Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3wf5-983h-ccwq

больше 3 лет назад

An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29.

EPSS: Низкий
github логотип

GHSA-3wf4-68gx-mph8

около 1 года назад

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wf3-9vwr-cm6w

больше 1 года назад

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3wf3-3cc5-7887

больше 3 лет назад

An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wf3-2hqv-7qjg

почти 4 года назад

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

EPSS: Низкий
github логотип

GHSA-3wf2-vcwv-gqjp

больше 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-3wf2-8r42-5jxv

больше 3 лет назад

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wf2-2pq4-4rvc

больше 1 года назад

Woodpecker's custom environment variables allow to alter execution flow of plugins

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wcx-x5mh-phrw

около 1 года назад

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wcx-w5qh-8gcx

около 3 лет назад

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wcx-6cxr-rw7f

почти 4 года назад

Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-3wcx-33v7-xf78

больше 3 лет назад

Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the-middle attack. An attacker may trick Galaxy Apps into using an arbitrary hostname for which the attacker can provide a valid SSL certificate, and emulate the API of the app store to modify existing apps at installation time. The specific flaw involves an HTTP method to obtain the load-balanced hostname that enforces SSL only after obtaining a hostname from the load balancer, and a missing app signature validation in the application XML. An attacker can exploit this vulnerability to achieve Remote Code Execution on the device. The Samsung ID is SVE-2018-12071.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3wcw-m33p-8r99

больше 3 лет назад

Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3wcw-6j7r-p57r

5 месяцев назад

The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3wcv-7wxv-gvf8

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wcv-7r47-m45v

больше 3 лет назад

The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528.

EPSS: Низкий
github логотип

GHSA-3wcr-vccv-4fcx

больше 3 лет назад

The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wcr-p8pv-4w4w

больше 3 лет назад

Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wcq-x3mq-6r9p

больше 4 лет назад

Potential memory exposure in dns-packet

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3wcq-hf94-333f

больше 3 лет назад

In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wf5-983h-ccwq

An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf4-68gx-mph8

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wf3-9vwr-cm6w

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wf3-3cc5-7887

An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf3-2hqv-7qjg

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3wf2-vcwv-gqjp

Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

18%
Средний
больше 3 лет назад
github логотип
GHSA-3wf2-8r42-5jxv

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf2-2pq4-4rvc

Woodpecker's custom environment variables allow to alter execution flow of plugins

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wcx-x5mh-phrw

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wcx-w5qh-8gcx

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-3wcx-6cxr-rw7f

Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wcx-33v7-xf78

Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the-middle attack. An attacker may trick Galaxy Apps into using an arbitrary hostname for which the attacker can provide a valid SSL certificate, and emulate the API of the app store to modify existing apps at installation time. The specific flaw involves an HTTP method to obtain the load-balanced hostname that enforces SSL only after obtaining a hostname from the load balancer, and a missing app signature validation in the application XML. An attacker can exploit this vulnerability to achieve Remote Code Execution on the device. The Samsung ID is SVE-2018-12071.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wcw-m33p-8r99

Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wcw-6j7r-p57r

The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-3wcv-7wxv-gvf8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3wcv-7r47-m45v

The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3wcr-vccv-4fcx

The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wcr-p8pv-4w4w

Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wcq-x3mq-6r9p

Potential memory exposure in dns-packet

CVSS3: 7.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcq-hf94-333f

In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу