Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3j7g-gwmc-fxrx

больше 3 лет назад

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3j7g-922g-j6r3

около 3 лет назад

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j7g-6hfp-ww62

больше 1 года назад

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3j7f-43fq-vpg9

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce allows Stored XSS. This issue affects EAN for WooCommerce: from n/a through 5.4.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3j7c-p7jw-q87h

больше 3 лет назад

cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j7c-gxhc-gfrg

почти 4 года назад

Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the vendor advisory addresses this issue. In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries.

EPSS: Низкий
github логотип

GHSA-3j7c-23m3-57jj

больше 2 лет назад

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j78-rxcg-xggm

больше 3 лет назад

Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-3j78-gc32-cr37

больше 3 лет назад

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j78-fv9c-9gh2

почти 4 года назад

ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.

EPSS: Низкий
github логотип

GHSA-3j78-7m59-r7gv

почти 6 лет назад

Private data exposure via REST API in BuddyPress

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3j77-7r45-wfxw

почти 4 года назад

Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Средний
github логотип

GHSA-3j77-72gm-5rj8

почти 2 года назад

BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3j75-rq9m-pxrv

почти 2 года назад

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3j75-qm7x-j2gc

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.

EPSS: Низкий
github логотип

GHSA-3j75-7jc2-vqcg

больше 3 лет назад

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.

EPSS: Низкий
github логотип

GHSA-3j75-6w2h-35v4

почти 3 года назад

A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/sales/manage_sale.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226979.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3j74-m6hf-wwh5

больше 3 лет назад

A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released a software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).

EPSS: Низкий
github логотип

GHSA-3j6x-wqc4-76mc

больше 3 лет назад

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified filesystem actions via a crafted application, aka "Windows Filesystem Elevation of Privilege Vulnerability."

EPSS: Низкий
github логотип

GHSA-3j6w-wcmf-ph6c

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Bulk Delete allows Reflected XSS.This issue affects WP Bulk Delete: from n/a through 1.3.1.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j7g-gwmc-fxrx

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
68%
Средний
больше 3 лет назад
github логотип
GHSA-3j7g-922g-j6r3

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3j7g-6hfp-ww62

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3j7f-43fq-vpg9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce allows Stored XSS. This issue affects EAN for WooCommerce: from n/a through 5.4.6.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3j7c-p7jw-q87h

cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j7c-gxhc-gfrg

Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the vendor advisory addresses this issue. In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3j7c-23m3-57jj

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3j78-rxcg-xggm

Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j78-gc32-cr37

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3j78-fv9c-9gh2

ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3j78-7m59-r7gv

Private data exposure via REST API in BuddyPress

CVSS3: 8
1%
Низкий
почти 6 лет назад
github логотип
GHSA-3j77-7r45-wfxw

Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

14%
Средний
почти 4 года назад
github логотип
GHSA-3j77-72gm-5rj8

BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3j75-rq9m-pxrv

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3j75-qm7x-j2gc

Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3j75-7jc2-vqcg

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j75-6w2h-35v4

A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/sales/manage_sale.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226979.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3j74-m6hf-wwh5

A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released a software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6x-wqc4-76mc

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified filesystem actions via a crafted application, aka "Windows Filesystem Elevation of Privilege Vulnerability."

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6w-wcmf-ph6c

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Bulk Delete allows Reflected XSS.This issue affects WP Bulk Delete: from n/a through 1.3.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу