Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2wgp-4wpc-33f4

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Contact Form With Shortcode allows Reflected XSS. This issue affects Contact Form With Shortcode: from n/a through 4.2.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2wgm-mwg3-j9q5

почти 2 года назад

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_class' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2wgm-5xw3-53m2

почти 4 года назад

nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.

EPSS: Низкий
github логотип

GHSA-2wgm-3pxj-gmrx

почти 4 года назад

graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function.

EPSS: Низкий
github логотип

GHSA-2wgj-4jrq-2g66

около 1 года назад

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the parameter password at the change admin password page at the router web interface.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-2wgh-rqx2-f94c

больше 3 лет назад

Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

EPSS: Низкий
github логотип

GHSA-2wgh-cg2p-67mv

больше 3 лет назад

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a large number of elements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wgh-9jrp-f6jq

почти 4 года назад

Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a crafted packet to TCP port 4002.

EPSS: Средний
github логотип

GHSA-2wgg-qhc4-8436

почти 4 года назад

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wgg-mrqh-cxvr

больше 3 лет назад

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

EPSS: Низкий
github логотип

GHSA-2wgg-c8xc-7gg3

почти 4 года назад

TYPO3 Backend Discloses Encryption Key

EPSS: Низкий
github логотип

GHSA-2wgg-6f6v-vvvx

8 месяцев назад

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2wgf-8c9h-xvxv

больше 3 лет назад

Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2wgf-345r-c46f

больше 2 лет назад

IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2wgc-48g2-cj5w

около 2 лет назад

vantage6 has insecure SSH configuration for node and server containers

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wgc-2cv4-ww9r

почти 4 года назад

A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.

EPSS: Средний
github логотип

GHSA-2wg8-j75p-4mrm

больше 3 лет назад

MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access vulnerabilities, leading to sensitive information leakage.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wg8-fhxh-9xhr

больше 3 лет назад

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2wg8-2p2f-8ccc

больше 3 лет назад

Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.

EPSS: Низкий
github логотип

GHSA-2wg8-2hgh-5f85

больше 2 лет назад

Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wgp-4wpc-33f4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Contact Form With Shortcode allows Reflected XSS. This issue affects Contact Form With Shortcode: from n/a through 4.2.5.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-2wgm-mwg3-j9q5

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_class' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2wgm-5xw3-53m2

nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wgm-3pxj-gmrx

graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2wgj-4jrq-2g66

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the parameter password at the change admin password page at the router web interface.

CVSS3: 7.5
75%
Высокий
около 1 года назад
github логотип
GHSA-2wgh-rqx2-f94c

Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wgh-cg2p-67mv

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a large number of elements.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wgh-9jrp-f6jq

Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a crafted packet to TCP port 4002.

39%
Средний
почти 4 года назад
github логотип
GHSA-2wgg-qhc4-8436

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2wgg-mrqh-cxvr

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2wgg-c8xc-7gg3

TYPO3 Backend Discloses Encryption Key

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wgg-6f6v-vvvx

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.

CVSS3: 4.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2wgf-8c9h-xvxv

Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wgf-345r-c46f

IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wgc-48g2-cj5w

vantage6 has insecure SSH configuration for node and server containers

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wgc-2cv4-ww9r

A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.

11%
Средний
почти 4 года назад
github логотип
GHSA-2wg8-j75p-4mrm

MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access vulnerabilities, leading to sensitive information leakage.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wg8-fhxh-9xhr

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wg8-2p2f-8ccc

Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wg8-2hgh-5f85

Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу