Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 852

Количество 312 852

github логотип

GHSA-32pm-mq37-w9xm

больше 1 года назад

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-32pm-63j6-22qc

около 1 года назад

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-32pj-3qhw-8xrh

8 месяцев назад

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /script/academic/division-system of the component Division System Page. The manipulation of the argument Division leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-32ph-rfjm-xcxh

около 3 лет назад

An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32ph-p8jx-rv5r

больше 3 лет назад

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-32pg-9428-4x59

больше 3 лет назад

An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.

EPSS: Низкий
github логотип

GHSA-32pg-5795-jh5m

почти 4 года назад

Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.

EPSS: Низкий
github логотип

GHSA-32pf-q5pw-hg4f

больше 3 лет назад

radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.

EPSS: Низкий
github логотип

GHSA-32pf-5hm5-f9mf

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-32pc-xphx-q4f6

больше 7 лет назад

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32pc-g2wc-v836

около 2 лет назад

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-32p9-x7g8-8m43

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-32p9-vr87-6gx3

больше 2 лет назад

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, including the submitter's first name.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32p9-v6w3-v6fj

11 месяцев назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be executed by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32p9-9c2j-m88v

почти 4 года назад

PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.

EPSS: Низкий
github логотип

GHSA-32p9-664j-q6j6

больше 3 лет назад

libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32p8-xhh6-v239

почти 4 года назад

SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

EPSS: Низкий
github логотип

GHSA-32p8-qq6w-3v8c

больше 3 лет назад

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32p7-7q74-w9jv

почти 3 года назад

An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-32p5-w624-64gp

около 2 лет назад

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32pm-mq37-w9xm

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-32pm-63j6-22qc

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.

CVSS3: 9.8
58%
Средний
около 1 года назад
github логотип
GHSA-32pj-3qhw-8xrh

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /script/academic/division-system of the component Division System Page. The manipulation of the argument Division leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-32ph-rfjm-xcxh

An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-32ph-p8jx-rv5r

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32pg-9428-4x59

An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32pg-5795-jh5m

Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32pf-q5pw-hg4f

radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32pf-5hm5-f9mf

Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32pc-xphx-q4f6

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
github логотип
GHSA-32pc-g2wc-v836

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-32p9-x7g8-8m43

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-32p9-vr87-6gx3

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, including the submitter's first name.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32p9-v6w3-v6fj

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be executed by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-32p9-9c2j-m88v

PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-32p9-664j-q6j6

libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32p8-xhh6-v239

SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32p8-qq6w-3v8c

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32p7-7q74-w9jv

An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.

CVSS3: 9.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-32p5-w624-64gp

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
около 2 лет назад

Уязвимостей на страницу