Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32qj-4pcr-vqhp

больше 3 лет назад

By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

EPSS: Низкий
github логотип

GHSA-32qh-ffxc-wq2g

около 2 лет назад

In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32qh-8vg6-9g43

около 3 лет назад

Cloud Foundry Archiver vulnerable to path traversal

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-32qh-67mm-vmwj

больше 3 лет назад

The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.

EPSS: Низкий
github логотип

GHSA-32qf-g28m-p524

больше 2 лет назад

The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32qf-68xj-9wqj

больше 3 лет назад

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via the web management interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-32qf-5pwg-7x24

почти 2 года назад

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in all versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-32qc-3hm3-7969

больше 3 лет назад

'Hulu / ????' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32q9-fj3c-ggpm

8 месяцев назад

A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-32q7-x7q9-wcf9

больше 3 лет назад

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-32q7-wm3c-r52g

больше 3 лет назад

Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.

EPSS: Средний
github логотип

GHSA-32q7-jcv7-p935

больше 3 лет назад

The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different vulnerability than CVE-2012-4248.

EPSS: Низкий
github логотип

GHSA-32q7-gv7f-4cg5

почти 2 года назад

Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32q6-rr98-cjqv

около 1 года назад

OpenFGA Authorization Bypass

EPSS: Низкий
github логотип

GHSA-32q5-2wwg-3v4v

больше 1 года назад

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-32q4-86g8-6637

около 2 лет назад

Stored Cross Site Scripting in beetl-bbs

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-32q4-6g3f-wq36

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-32q2-gv5x-j2pp

больше 3 лет назад

Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).

EPSS: Низкий
github логотип

GHSA-32px-xrqr-6c5g

5 месяцев назад

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate a limited number of specific plugins. The News Kit Elementor Addons plugin and a BlazeThemes theme must be installed and activated in order to exploit the vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32px-gjp5-9f34

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin 2.8.26 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit_time parameter in the CF7DBPluginSubmissions page to wp-admin/admin.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32qj-4pcr-vqhp

By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-32qh-ffxc-wq2g

In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-32qh-8vg6-9g43

Cloud Foundry Archiver vulnerable to path traversal

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-32qh-67mm-vmwj

The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32qf-g28m-p524

The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-32qf-68xj-9wqj

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via the web management interface.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-32qf-5pwg-7x24

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in all versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-32qc-3hm3-7969

'Hulu / ????' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32q9-fj3c-ggpm

A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-32q7-x7q9-wcf9

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.

CVSS3: 9.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-32q7-wm3c-r52g

Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.

39%
Средний
больше 3 лет назад
github логотип
GHSA-32q7-jcv7-p935

The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different vulnerability than CVE-2012-4248.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-32q7-gv7f-4cg5

Duplicate Advisory: Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability

CVSS3: 7.5
почти 2 года назад
github логотип
GHSA-32q6-rr98-cjqv

OpenFGA Authorization Bypass

0%
Низкий
около 1 года назад
github логотип
GHSA-32q5-2wwg-3v4v

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-32q4-86g8-6637

Stored Cross Site Scripting in beetl-bbs

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-32q4-6g3f-wq36

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-32q2-gv5x-j2pp

Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).

2%
Низкий
больше 3 лет назад
github логотип
GHSA-32px-xrqr-6c5g

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate a limited number of specific plugins. The News Kit Elementor Addons plugin and a BlazeThemes theme must be installed and activated in order to exploit the vulnerability.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-32px-gjp5-9f34

Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin 2.8.26 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit_time parameter in the CF7DBPluginSubmissions page to wp-admin/admin.php.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу