Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2jv5-xv66-fhx8

почти 2 года назад

A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2jv5-wvvg-c9hj

больше 3 лет назад

Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2jv5-mm7g-6r3r

больше 3 лет назад

SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jv5-h643-m9jp

больше 3 лет назад

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.

EPSS: Низкий
github логотип

GHSA-2jv5-9r88-3w3p

почти 2 года назад

python-multipart vulnerable to Content-Type Header ReDoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jv5-59rp-vmgj

больше 1 года назад

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2jv4-vc4g-7mp7

больше 3 лет назад

Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.

EPSS: Низкий
github логотип

GHSA-2jv4-g2j5-gcgx

8 месяцев назад

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2jv4-86qg-m23h

около 1 года назад

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2jv4-596w-g9hj

2 месяца назад

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jv4-4qp4-gcjc

больше 3 лет назад

Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2jv3-v37p-65w3

больше 3 лет назад

CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-2jv3-mh5v-j4w2

почти 4 года назад

Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.

EPSS: Низкий
github логотип

GHSA-2jv3-8jp8-xgcm

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2jv2-97wr-gpc9

больше 3 лет назад

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

EPSS: Низкий
github логотип

GHSA-2jrx-vp4g-6wgj

8 месяцев назад

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jrx-hm6v-q9c6

почти 4 года назад

SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.

EPSS: Низкий
github логотип

GHSA-2jrx-fmqr-7h3v

около 1 года назад

Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2jrw-7rm5-qgh5

больше 3 лет назад

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001eca0."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jrw-3wxv-fr6m

больше 3 лет назад

Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jv5-xv66-fhx8

A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.

CVSS3: 4.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jv5-wvvg-c9hj

Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jv5-mm7g-6r3r

SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jv5-h643-m9jp

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jv5-9r88-3w3p

python-multipart vulnerable to Content-Type Header ReDoS

CVSS3: 7.5
2%
Низкий
почти 2 года назад
github логотип
GHSA-2jv5-59rp-vmgj

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jv4-vc4g-7mp7

Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jv4-g2j5-gcgx

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS3: 6.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jv4-86qg-m23h

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 2.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2jv4-596w-g9hj

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2jv4-4qp4-gcjc

Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-2jv3-v37p-65w3

CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources

CVSS3: 7.2
15%
Средний
больше 3 лет назад
github логотип
GHSA-2jv3-mh5v-j4w2

Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jv3-8jp8-xgcm

Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2jv2-97wr-gpc9

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrx-vp4g-6wgj

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jrx-hm6v-q9c6

SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2jrx-fmqr-7h3v

Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2jrw-7rm5-qgh5

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001eca0."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrw-3wxv-fr6m

Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу