Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2pqr-5864-6fgw

5 месяцев назад

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pqq-4jjp-fmr3

10 месяцев назад

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2pqp-x768-f3m2

больше 3 лет назад

An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

EPSS: Низкий
github логотип

GHSA-2pqp-qqmg-62w8

больше 3 лет назад

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pqm-v28p-x679

больше 3 лет назад

eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

EPSS: Низкий
github логотип

GHSA-2pqm-qhp5-fh45

почти 2 года назад

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pqm-q853-jfvf

больше 3 лет назад

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2pqj-vff5-fgh2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2pqj-h3vj-pqgw

больше 5 лет назад

Cross-Site Scripting in jquery

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pqg-9xqc-m3rw

почти 4 года назад

D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the wireless link.

EPSS: Низкий
github логотип

GHSA-2pqf-pg56-pwcv

больше 3 лет назад

The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

EPSS: Низкий
github логотип

GHSA-2pqf-jwpx-hmhw

больше 3 лет назад

The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-2pqf-f6j5-7m26

почти 4 года назад

Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.

EPSS: Низкий
github логотип

GHSA-2pqf-865h-wqmh

больше 3 лет назад

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-2pqc-gv8q-pvqv

больше 3 лет назад

django-cms CSRF Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pq9-cj9c-6vgr

почти 3 года назад

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pq9-746g-vp4h

4 месяца назад

A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2pq9-46mh-w84j

12 месяцев назад

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pq8-vhfp-3f4x

почти 4 года назад

Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2pq8-4rf3-3vh9

10 месяцев назад

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pqr-5864-6fgw

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2pqq-4jjp-fmr3

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2pqp-x768-f3m2

An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqp-qqmg-62w8

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqm-v28p-x679

eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqm-qhp5-fh45

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2pqm-q853-jfvf

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 6.8
10%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqj-vff5-fgh2

Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqj-h3vj-pqgw

Cross-Site Scripting in jquery

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-2pqg-9xqc-m3rw

D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the wireless link.

9%
Низкий
почти 4 года назад
github логотип
GHSA-2pqf-pg56-pwcv

The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqf-jwpx-hmhw

The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.

CVSS3: 8.1
78%
Высокий
больше 3 лет назад
github логотип
GHSA-2pqf-f6j5-7m26

Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2pqf-865h-wqmh

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqc-gv8q-pvqv

django-cms CSRF Vulnerability

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pq9-cj9c-6vgr

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2pq9-746g-vp4h

A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2pq9-46mh-w84j

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-2pq8-vhfp-3f4x

Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2pq8-4rf3-3vh9

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

CVSS3: 7.2
0%
Низкий
10 месяцев назад

Уязвимостей на страницу