Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-2qrx-vr2m-vjfp

больше 3 лет назад

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input validation of CLI command user input. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a CLI command with crafted user input. A successful exploit could allow the attacker to execute arbitrary commands on the affected system that should be restricted. The attacker would need to have valid user credentials for the device. Cisco Bug IDs: CSCvf49844.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2qrx-mpvp-j33p

почти 3 года назад

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qrx-m2qx-4wr4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2qrw-655g-f524

около 2 лет назад

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qrv-v95f-h2jw

больше 3 лет назад

ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

EPSS: Низкий
github логотип

GHSA-2qrr-vmr2-jmmh

больше 3 лет назад

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Низкий
github логотип

GHSA-2qrr-rf5c-q7q9

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) allows Stored XSS.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through 0.5.8.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qrr-mpjx-3hvh

2 месяца назад

The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2qrr-fxgw-wwcx

около 1 года назад

Missing Authorization vulnerability in dusthazard Popup Surveys & Polls for WordPress (Mare.io) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through 1.36.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2qrr-c2gh-pr35

больше 3 лет назад

Wikimedia information leak vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qrq-v847-3jwg

больше 1 года назад

Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2qrq-mpmg-w3v6

около 2 лет назад

Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2qrq-m5fx-379q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2qrq-4qxf-6cfm

около 4 лет назад

There is an Exception log vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause address information leakage.

EPSS: Низкий
github логотип

GHSA-2qrp-v3mf-g36h

больше 3 лет назад

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.

EPSS: Средний
github логотип

GHSA-2qrm-xmpc-h7fp

почти 4 года назад

FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.

EPSS: Низкий
github логотип

GHSA-2qrm-vwv9-87jm

больше 3 лет назад

An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.

EPSS: Низкий
github логотип

GHSA-2qrm-3wph-84mx

почти 4 года назад

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qrm-36rr-ffj3

10 месяцев назад

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2qrj-g9hq-chph

9 месяцев назад

Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qrx-vr2m-vjfp

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input validation of CLI command user input. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a CLI command with crafted user input. A successful exploit could allow the attacker to execute arbitrary commands on the affected system that should be restricted. The attacker would need to have valid user credentials for the device. Cisco Bug IDs: CSCvf49844.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrx-mpvp-j33p

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2qrx-m2qx-4wr4

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrw-655g-f524

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2qrv-v95f-h2jw

ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrr-vmr2-jmmh

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrr-rf5c-q7q9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) allows Stored XSS.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through 0.5.8.1.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2qrr-mpjx-3hvh

The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
2 месяца назад
github логотип
GHSA-2qrr-fxgw-wwcx

Missing Authorization vulnerability in dusthazard Popup Surveys & Polls for WordPress (Mare.io) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through 1.36.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2qrr-c2gh-pr35

Wikimedia information leak vulnerability

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrq-v847-3jwg

Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qrq-mpmg-w3v6

Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

CVSS3: 6.1
34%
Средний
около 2 лет назад
github логотип
GHSA-2qrq-m5fx-379q

Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrq-4qxf-6cfm

There is an Exception log vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause address information leakage.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2qrp-v3mf-g36h

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.

14%
Средний
больше 3 лет назад
github логотип
GHSA-2qrm-xmpc-h7fp

FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2qrm-vwv9-87jm

An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrm-3wph-84mx

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2qrm-36rr-ffj3

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2qrj-g9hq-chph

Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow

0%
Низкий
9 месяцев назад

Уязвимостей на страницу