Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2fh4-45ph-7q27

около 2 лет назад

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fh3-xg72-f7vx

больше 3 лет назад

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.

EPSS: Критический
github логотип

GHSA-2fh3-rm73-hjxf

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fh2-r4pq-hx4f

больше 1 года назад

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2fgx-cg4f-9pgq

больше 3 лет назад

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fgw-qh65-pxv5

9 месяцев назад

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fgw-hpx5-xjx3

почти 2 года назад

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2fgw-ch33-hpgq

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fgw-2v2m-w7mc

почти 4 года назад

useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.

EPSS: Низкий
github логотип

GHSA-2fgv-c9q9-5wwh

почти 4 года назад

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

EPSS: Средний
github логотип

GHSA-2fgr-v6mx-rmch

5 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection. This issue affects Perfect Brands for WooCommerce: from n/a through 3.6.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2fgq-wq42-4xxq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2.

EPSS: Низкий
github логотип

GHSA-2fgq-8829-2c9j

больше 2 лет назад

Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fgp-4w27-wc8x

11 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fgj-xr9x-3qq6

почти 4 года назад

Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2fgj-q22q-g9pg

почти 3 года назад

Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fgh-m45q-cgrh

почти 4 года назад

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

EPSS: Низкий
github логотип

GHSA-2fgh-jwqp-hr3r

почти 4 года назад

zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

EPSS: Низкий
github логотип

GHSA-2fgh-jjh6-cvr4

около 1 года назад

Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fgh-78wf-f9v9

6 месяцев назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass.This issue affects Post SMTP: from n/a through 3.2.0.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fh4-45ph-7q27

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fh3-xg72-f7vx

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.

93%
Критический
больше 3 лет назад
github логотип
GHSA-2fh3-rm73-hjxf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2fh2-r4pq-hx4f

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fgx-cg4f-9pgq

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fgw-qh65-pxv5

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2fgw-hpx5-xjx3

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fgw-ch33-hpgq

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fgw-2v2m-w7mc

useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fgv-c9q9-5wwh

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

24%
Средний
почти 4 года назад
github логотип
GHSA-2fgr-v6mx-rmch

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection. This issue affects Perfect Brands for WooCommerce: from n/a through 3.6.0.

CVSS3: 8.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2fgq-wq42-4xxq

Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fgq-8829-2c9j

Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fgp-4w27-wc8x

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2fgj-xr9x-3qq6

Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2fgj-q22q-g9pg

Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2fgh-m45q-cgrh

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fgh-jwqp-hr3r

zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2fgh-jjh6-cvr4

Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2fgh-78wf-f9v9

Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass.This issue affects Post SMTP: from n/a through 3.2.0.

CVSS3: 8.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу