Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42qw-9g84-jp2h

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42qv-x26x-fjv9

почти 4 года назад

Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which bypasses a sanity check that is only applied to a GET request.

EPSS: Низкий
github логотип

GHSA-42qr-q7pq-93c7

больше 3 лет назад

The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.

EPSS: Низкий
github логотип

GHSA-42qq-mh3v-978m

больше 3 лет назад

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42qq-mf68-hprg

около 3 лет назад

Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable Type Advanced 6.8.7 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42qp-w7cq-j4gj

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Templates – Elementor & Gutenberg templates allows Reflected XSS.This issue affects SKT Templates – Elementor & Gutenberg templates: from n/a through 6.14.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-42qm-c3cf-9wv2

почти 4 года назад

Code injection in dolibarr/dolibarr

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42qm-8v8m-m78c

больше 2 лет назад

PocketMine MP vulnerable to uncontrolled resource consumption via mismatched type of 'InventoryTransactionPacket'

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42qm-8j3v-68c9

11 месяцев назад

A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-42qm-2w7f-wp7g

около 3 лет назад

GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42qh-q4x8-48hc

почти 4 года назад

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality via unknown vectors related to Utility/Remote Execution Server (in.rexecd).

EPSS: Низкий
github логотип

GHSA-42qh-h645-hm57

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS. This issue affects Newsletters: from n/a through 4.9.9.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-42qg-gfqm-p7q6

больше 3 лет назад

A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42qg-766j-27mg

10 месяцев назад

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42qg-74gw-4v5q

9 месяцев назад

The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-42qf-mf9c-m62g

около 4 лет назад

Microsoft Cluster Port Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42qf-73xw-h6m8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

EPSS: Низкий
github логотип

GHSA-42qc-mrm5-rf8f

больше 3 лет назад

Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ?Kassa ??? WooCommerce plugin <= 2.3.0 at WordPress.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42qc-f87p-hg2h

больше 3 лет назад

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42q8-j57q-84vc

почти 4 года назад

SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42qw-9g84-jp2h

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-42qv-x26x-fjv9

Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which bypasses a sanity check that is only applied to a GET request.

2%
Низкий
почти 4 года назад
github логотип
GHSA-42qr-q7pq-93c7

The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-42qq-mh3v-978m

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-42qq-mf68-hprg

Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable Type Advanced 6.8.7 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-42qp-w7cq-j4gj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Templates – Elementor & Gutenberg templates allows Reflected XSS.This issue affects SKT Templates – Elementor & Gutenberg templates: from n/a through 6.14.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-42qm-c3cf-9wv2

Code injection in dolibarr/dolibarr

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-42qm-8v8m-m78c

PocketMine MP vulnerable to uncontrolled resource consumption via mismatched type of 'InventoryTransactionPacket'

CVSS3: 5.3
больше 2 лет назад
github логотип
GHSA-42qm-8j3v-68c9

A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 4.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-42qm-2w7f-wp7g

GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-42qh-q4x8-48hc

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality via unknown vectors related to Utility/Remote Execution Server (in.rexecd).

1%
Низкий
почти 4 года назад
github логотип
GHSA-42qh-h645-hm57

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS. This issue affects Newsletters: from n/a through 4.9.9.6.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-42qg-gfqm-p7q6

A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42qg-766j-27mg

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-42qg-74gw-4v5q

The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-42qf-mf9c-m62g

Microsoft Cluster Port Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-42qf-73xw-h6m8

Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42qc-mrm5-rf8f

Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ?Kassa ??? WooCommerce plugin <= 2.3.0 at WordPress.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42qc-f87p-hg2h

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-42q8-j57q-84vc

SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу