Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xrjp-rhjh-9hxf

около 4 лет назад

The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State Update message.

EPSS: Низкий
github логотип

GHSA-xrjp-pjmj-2fh5

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Iván R. Delgado Martínez WP Custom Google Search allows Stored XSS.This issue affects WP Custom Google Search: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrjm-v355-frfj

больше 4 лет назад

ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.

EPSS: Низкий
github логотип

GHSA-xrjm-94r9-c987

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Predrag Supurović Stop Comment Spam allows Stored XSS.This issue affects Stop Comment Spam: from n/a through 0.5.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrjj-mj9h-534m

больше 3 лет назад

golang.org/x/net/http2 vulnerable to possible excessive memory growth

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrjj-hqhj-84h2

около 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect integrity, related to PIA Core Technology.

EPSS: Низкий
github логотип

GHSA-xrjh-j238-j8p7

около 4 лет назад

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime has an improperly selected default password for the administrator account, which makes it easier for remote attackers to obtain access via a brute-force approach involving many HTTP requests.

EPSS: Низкий
github логотип

GHSA-xrjh-cg36-q3cp

около 4 лет назад

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

EPSS: Низкий
github логотип

GHSA-xrjg-wm25-cxc7

около 4 лет назад

Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.

EPSS: Низкий
github логотип

GHSA-xrjg-w5fr-6ph9

почти 2 года назад

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrjg-w3rg-6hjx

11 месяцев назад

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.6. Running an hdiutil command may unexpectedly execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrjf-xqgq-8525

около 4 лет назад

There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly.

EPSS: Низкий
github логотип

GHSA-xrjf-q592-pcrw

около 4 лет назад

A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xrjf-phvv-r4vr

больше 4 лет назад

Command injection in strapi

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrjf-j24x-4gqj

больше 3 лет назад

A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 04b223813f0e336aab50bff140d0f5889c31dbec. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221503.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrj9-vwwj-2w2c

больше 4 лет назад

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

EPSS: Средний
github логотип

GHSA-xrj9-mw57-j34v

9 месяцев назад

AstrBot contains a directory traversal vulnerability

EPSS: Низкий
github логотип

GHSA-xrj9-h79q-8446

больше 4 лет назад

Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

EPSS: Низкий
github логотип

GHSA-xrj9-8xhq-9gjh

больше 4 лет назад

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xrj9-7qw9-gvw5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrjp-rhjh-9hxf

The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State Update message.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xrjp-pjmj-2fh5

Cross-Site Request Forgery (CSRF) vulnerability in Iván R. Delgado Martínez WP Custom Google Search allows Stored XSS.This issue affects WP Custom Google Search: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrjm-v355-frfj

ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xrjm-94r9-c987

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Predrag Supurović Stop Comment Spam allows Stored XSS.This issue affects Stop Comment Spam: from n/a through 0.5.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrjj-mj9h-534m

golang.org/x/net/http2 vulnerable to possible excessive memory growth

CVSS3: 5.3
6%
Низкий
больше 3 лет назад
github логотип
GHSA-xrjj-hqhj-84h2

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect integrity, related to PIA Core Technology.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrjh-j238-j8p7

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime has an improperly selected default password for the administrator account, which makes it easier for remote attackers to obtain access via a brute-force approach involving many HTTP requests.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrjh-cg36-q3cp

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrjg-wm25-cxc7

Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xrjg-w5fr-6ph9

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-xrjg-w3rg-6hjx

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.6. Running an hdiutil command may unexpectedly execute arbitrary code.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xrjf-xqgq-8525

There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrjf-q592-pcrw

A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused.

CVSS3: 4.9
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrjf-phvv-r4vr

Command injection in strapi

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrjf-j24x-4gqj

A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 04b223813f0e336aab50bff140d0f5889c31dbec. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221503.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrj9-vwwj-2w2c

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

68%
Средний
больше 4 лет назад
github логотип
GHSA-xrj9-mw57-j34v

AstrBot contains a directory traversal vulnerability

1%
Низкий
9 месяцев назад
github логотип
GHSA-xrj9-h79q-8446

Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xrj9-8xhq-9gjh

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

CVSS3: 9.8
36%
Средний
больше 4 лет назад
github логотип
GHSA-xrj9-7qw9-gvw5

Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

4%
Низкий
около 4 лет назад

Уязвимостей на страницу