Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jqm-hvwr-82mr

почти 4 года назад

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

EPSS: Низкий
github логотип

GHSA-3jqm-6jfp-fcm9

почти 3 года назад

A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the function sliderPicSubmit of the file adminHome.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-223126 is the identifier assigned to this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jqm-4487-ppp7

почти 4 года назад

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

EPSS: Низкий
github логотип

GHSA-3jqj-jp4r-6xwm

около 1 месяца назад

The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or considering if the server is behind a trusted proxy. This makes it possible for unauthenticated attackers to bypass IP-based access restrictions by spoofing their IP address via the X-Forwarded-For header.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3jqj-38m2-pxp7

почти 4 года назад

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

EPSS: Низкий
github логотип

GHSA-3jqh-85c5-qcrg

12 месяцев назад

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations of other users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3jqf-v4mv-747g

17 дней назад

Moonraker affected by LDAP search filter injection

EPSS: Низкий
github логотип

GHSA-3jqc-q5pp-f8hm

больше 3 лет назад

There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

EPSS: Низкий
github логотип

GHSA-3jqc-mccc-r8m7

больше 3 лет назад

OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters.

EPSS: Низкий
github логотип

GHSA-3jqc-hm9w-f824

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3jqc-gqj7-6fcm

больше 3 лет назад

SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app.

EPSS: Низкий
github логотип

GHSA-3jq8-jg75-rqv6

около 7 лет назад

Cleartext Transmission of Sensitive Information in Apache nifi

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jq8-j7q6-f6m6

больше 3 лет назад

A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jq8-4x2x-fr2h

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users.

EPSS: Низкий
github логотип

GHSA-3jq7-wcv7-p4gw

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wobbie.Nl Doneren met Mollie allows Reflected XSS.This issue affects Doneren met Mollie: from n/a through 2.10.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jq7-m4v4-gfrf

больше 3 лет назад

In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645695

EPSS: Низкий
github логотип

GHSA-3jq7-j743-cxfp

больше 3 лет назад

plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex functions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDC certauth plugin code that is specific to Red Hat.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jq7-8ph8-63xm

больше 3 лет назад

Grafana information disclosure

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jq6-qm73-q65c

почти 4 года назад

Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unknown impact and attack vectors, as identified by Vuln# (1) APPS03 in (a) iProcurement; (2) APPS04 in (b) Oracle Application Object Library; (3) APPS06, (4) APPS07, and (5) APPS08 in (c) Oracle Applications Technology Stack; and (6) APPS11 in (d) Oracle Order Capture.

EPSS: Низкий
github логотип

GHSA-3jq6-fx9w-pjqj

почти 4 года назад

CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an authenticated FTP connection established earlier in the same browser session, as demonstrated using a DELE command, a variant or possibly a regression of CVE-2004-1166. NOTE: a trailing "//" can force Internet Explorer to try to reuse an existing authenticated connection.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jqm-hvwr-82mr

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jqm-6jfp-fcm9

A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the function sliderPicSubmit of the file adminHome.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-223126 is the identifier assigned to this vulnerability.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3jqm-4487-ppp7

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3jqj-jp4r-6xwm

The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or considering if the server is behind a trusted proxy. This makes it possible for unauthenticated attackers to bypass IP-based access restrictions by spoofing their IP address via the X-Forwarded-For header.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3jqj-38m2-pxp7

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jqh-85c5-qcrg

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations of other users.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3jqf-v4mv-747g

Moonraker affected by LDAP search filter injection

0%
Низкий
17 дней назад
github логотип
GHSA-3jqc-q5pp-f8hm

There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jqc-mccc-r8m7

OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jqc-hm9w-f824

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-3jqc-gqj7-6fcm

SecurityAgent in Apple OS X before 10.11.1 does not prevent synthetic clicks from reaching keychain windows, which allows attackers to bypass intended access restrictions via a crafted app.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq8-jg75-rqv6

Cleartext Transmission of Sensitive Information in Apache nifi

CVSS3: 7.5
0%
Низкий
около 7 лет назад
github логотип
GHSA-3jq8-j7q6-f6m6

A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq8-4x2x-fr2h

Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq7-wcv7-p4gw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wobbie.Nl Doneren met Mollie allows Reflected XSS.This issue affects Doneren met Mollie: from n/a through 2.10.2.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3jq7-m4v4-gfrf

In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645695

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq7-j743-cxfp

plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex functions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDC certauth plugin code that is specific to Red Hat.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq7-8ph8-63xm

Grafana information disclosure

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jq6-qm73-q65c

Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unknown impact and attack vectors, as identified by Vuln# (1) APPS03 in (a) iProcurement; (2) APPS04 in (b) Oracle Application Object Library; (3) APPS06, (4) APPS07, and (5) APPS08 in (c) Oracle Applications Technology Stack; and (6) APPS11 in (d) Oracle Order Capture.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3jq6-fx9w-pjqj

CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an authenticated FTP connection established earlier in the same browser session, as demonstrated using a DELE command, a variant or possibly a regression of CVE-2004-1166. NOTE: a trailing "//" can force Internet Explorer to try to reuse an existing authenticated connection.

23%
Средний
почти 4 года назад

Уязвимостей на страницу