Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vx3-xf6q-r5xp

больше 3 лет назад

Exposure of Resource to Wrong Sphere in Apache Tomcat

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-3vx3-2qpf-jvhh

около 1 года назад

The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vx2-j5pv-6cq7

почти 2 года назад

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3vx2-9q2c-34r9

почти 4 года назад

Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3vwx-8478-gm7p

почти 4 года назад

The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12) 332, (13) 333, (14) 352, and (15) 367.

EPSS: Средний
github логотип

GHSA-3vwx-56vp-x7gr

больше 3 лет назад

Integer underflow in Uniscribe in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows remote attackers to execute arbitrary code via a crafted font, aka "Windows Integer Underflow Vulnerability."

EPSS: Средний
github логотип

GHSA-3vww-r7vf-jj85

11 месяцев назад

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3vww-prm4-rg7q

больше 3 лет назад

The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.

EPSS: Низкий
github логотип

GHSA-3vww-jrmm-9vff

почти 4 года назад

Liferay Portal and Liferay DXP allows arbitrary injection via the site name

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vww-c6r5-fh2r

4 месяца назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vwv-49mj-h47v

около 3 лет назад

A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3vwr-m2j6-695j

больше 3 лет назад

In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vwr-jj4f-h98x

больше 1 года назад

eZ Publish Remote code execution in file uploads

EPSS: Низкий
github логотип

GHSA-3vwp-294x-6v9c

около 3 лет назад

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3vwm-fc87-mq6h

около 3 лет назад

Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3vwh-qrr4-g3m5

больше 1 года назад

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vwh-824w-m2mm

больше 3 лет назад

The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.

EPSS: Низкий
github логотип

GHSA-3vwh-4gr8-m2f4

около 3 лет назад

CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vwg-x7c5-rg6m

12 месяцев назад

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vwg-x6p9-p27f

больше 3 лет назад

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vx3-xf6q-r5xp

Exposure of Resource to Wrong Sphere in Apache Tomcat

CVSS3: 9.1
19%
Средний
больше 3 лет назад
github логотип
GHSA-3vx3-2qpf-jvhh

The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3vx2-j5pv-6cq7

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

CVSS3: 5.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3vx2-9q2c-34r9

Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vwx-8478-gm7p

The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12) 332, (13) 333, (14) 352, and (15) 367.

16%
Средний
почти 4 года назад
github логотип
GHSA-3vwx-56vp-x7gr

Integer underflow in Uniscribe in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows remote attackers to execute arbitrary code via a crafted font, aka "Windows Integer Underflow Vulnerability."

30%
Средний
больше 3 лет назад
github логотип
GHSA-3vww-r7vf-jj85

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3vww-prm4-rg7q

The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vww-jrmm-9vff

Liferay Portal and Liferay DXP allows arbitrary injection via the site name

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3vww-c6r5-fh2r

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3vwv-49mj-h47v

A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vwr-m2j6-695j

In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vwr-jj4f-h98x

eZ Publish Remote code execution in file uploads

больше 1 года назад
github логотип
GHSA-3vwp-294x-6v9c

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVSS3: 7.8
55%
Средний
около 3 лет назад
github логотип
GHSA-3vwm-fc87-mq6h

Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vwh-qrr4-g3m5

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vwh-824w-m2mm

The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vwh-4gr8-m2f4

CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vwg-x7c5-rg6m

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3vwg-x6p9-p27f

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу