Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33q9-fp3q-fw2p

10 месяцев назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-33q9-8xm4-j4g6

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer Easy Elements Hider allows Stored XSS. This issue affects Easy Elements Hider: from n/a through 2.0.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-33q9-6qmp-35mw

больше 1 года назад

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33q8-pg9c-rw7v

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7844.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33q8-hj9q-xc35

больше 3 лет назад

Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0065.

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-33q7-w2pp-4v3v

больше 3 лет назад

Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."

EPSS: Низкий
github логотип

GHSA-33q7-797m-mc98

почти 4 года назад

Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

EPSS: Низкий
github логотип

GHSA-33q6-4f6h-v2vh

больше 1 года назад

Origin Validation Error in GitHub repository stitionai/devika prior to -.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-33q5-mhvx-53mf

больше 3 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-33q4-669f-3r2r

больше 3 лет назад

The booking-sms plugin before 1.1.0 for WordPress has XSS.

EPSS: Низкий
github логотип

GHSA-33q3-w4gf-476f

6 месяцев назад

Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio allows Object Injection. This issue affects Exertio: from n/a through 1.3.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33q3-rggw-hh5x

5 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack allows Retrieve Embedded Sensitive Data. This issue affects All In One SEO Pack: from n/a through 4.8.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33q3-mv77-cgr2

4 месяца назад

A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33q3-54qh-6h84

больше 3 лет назад

Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33q2-wm99-m8f7

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33q2-cxrh-v3f9

около 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeMShop 워드프레스 결제 심플페이 allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33px-qmc3-m5x2

почти 2 года назад

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-33px-mv83-cg73

11 месяцев назад

The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the wpcb_all_bookings(), wpcb_update_booking_post(), and wpcb_delete_posts() functions in all versions up to, and including, 4.0.3. This makes it possible for unauthenticated attackers to extract data, create or update bookings, or delete arbitrary posts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33px-jmpm-x3q5

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of FreeText annotations. By manipulating a document's elements, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6213.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33pw-r3fr-fc28

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33q9-fp3q-fw2p

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS3: 3.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-33q9-8xm4-j4g6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer Easy Elements Hider allows Stored XSS. This issue affects Easy Elements Hider: from n/a through 2.0.

CVSS3: 5.9
0%
Низкий
7 месяцев назад
github логотип
GHSA-33q9-6qmp-35mw

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-33q8-pg9c-rw7v

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7844.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33q8-hj9q-xc35

Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0065.

CVSS3: 4.3
23%
Средний
больше 3 лет назад
github логотип
GHSA-33q7-w2pp-4v3v

Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-33q7-797m-mc98

Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33q6-4f6h-v2vh

Origin Validation Error in GitHub repository stitionai/devika prior to -.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-33q5-mhvx-53mf

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
13%
Средний
больше 3 лет назад
github логотип
GHSA-33q4-669f-3r2r

The booking-sms plugin before 1.1.0 for WordPress has XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33q3-w4gf-476f

Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio allows Object Injection. This issue affects Exertio: from n/a through 1.3.2.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-33q3-rggw-hh5x

Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack allows Retrieve Embedded Sensitive Data. This issue affects All In One SEO Pack: from n/a through 4.8.7.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-33q3-mv77-cgr2

A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-33q3-54qh-6h84

Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-33q2-wm99-m8f7

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-33q2-cxrh-v3f9

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeMShop 워드프레스 결제 심플페이 allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.0.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-33px-qmc3-m5x2

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-33px-mv83-cg73

The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the wpcb_all_bookings(), wpcb_update_booking_post(), and wpcb_delete_posts() functions in all versions up to, and including, 4.0.3. This makes it possible for unauthenticated attackers to extract data, create or update bookings, or delete arbitrary posts.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-33px-jmpm-x3q5

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of FreeText annotations. By manipulating a document's elements, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6213.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33pw-r3fr-fc28

Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.

2%
Низкий
почти 4 года назад

Уязвимостей на страницу