Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 436

Количество 289 436

github логотип

GHSA-2726-6rmv-hf9g

больше 1 года назад

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2726-63m5-f24q

больше 1 года назад

SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2723-63p7-cxpv

3 месяца назад

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-cp/menus of the component Menu Page. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2722-rx7q-f2w5

около 3 лет назад

MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.

EPSS: Низкий
github логотип

GHSA-2722-p93p-vrgm

7 месяцев назад

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: High. However, the attacker will need a (low privilege) account to gain access to the action.exe CGI binary and upload the crafted firmware file, or convince a user with such access to upload it. Impact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services. CVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and comp...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26xx-m4q2-xhq8

больше 3 лет назад

Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-26xx-jvvm-7pfr

больше 3 лет назад

SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-26xx-j6q3-j3rf

больше 3 лет назад

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."

EPSS: Низкий
github логотип

GHSA-26xv-73mx-mq4r

5 дней назад

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

EPSS: Низкий
github логотип

GHSA-26xv-5c8j-w237

больше 3 лет назад

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26xv-4xf9-c953

около 3 лет назад

In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26xq-m8xw-6373

5 месяцев назад

Froxlor has an HTML Injection Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26xq-4h5f-fhh8

около 3 лет назад

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26xp-wjvm-542h

около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26xp-w34p-3h6q

около 3 лет назад

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

EPSS: Низкий
github логотип

GHSA-26xp-84m3-w6wh

больше 3 лет назад

The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.

EPSS: Низкий
github логотип

GHSA-26xm-phwj-2pmp

около 3 лет назад

Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0610.

EPSS: Низкий
github логотип

GHSA-26xj-xw26-4hf7

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

EPSS: Низкий
github логотип

GHSA-26xj-r8r2-vvgx

2 месяца назад

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26xj-hxvp-rc79

почти 2 года назад

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2726-6rmv-hf9g

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2726-63m5-f24q

SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2723-63p7-cxpv

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-cp/menus of the component Menu Page. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2722-rx7q-f2w5

MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2722-p93p-vrgm

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: High. However, the attacker will need a (low privilege) account to gain access to the action.exe CGI binary and upload the crafted firmware file, or convince a user with such access to upload it. Impact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services. CVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and comp...

CVSS3: 8.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-26xx-m4q2-xhq8

Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness

CVSS3: 9.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xx-jvvm-7pfr

SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xx-j6q3-j3rf

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."

4%
Низкий
больше 3 лет назад
github логотип
GHSA-26xv-73mx-mq4r

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

0%
Низкий
5 дней назад
github логотип
GHSA-26xv-5c8j-w237

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xv-4xf9-c953

In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.

CVSS3: 9.8
8%
Низкий
около 3 лет назад
github логотип
GHSA-26xq-m8xw-6373

Froxlor has an HTML Injection Vulnerability

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-26xq-4h5f-fhh8

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-26xp-wjvm-542h

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-26xp-w34p-3h6q

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

1%
Низкий
около 3 лет назад
github логотип
GHSA-26xp-84m3-w6wh

The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xm-phwj-2pmp

Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0610.

7%
Низкий
около 3 лет назад
github логотип
GHSA-26xj-xw26-4hf7

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

0%
Низкий
около 3 лет назад
github логотип
GHSA-26xj-r8r2-vvgx

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-26xj-hxvp-rc79

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу