Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2983-hvjm-2229

6 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) allows SQL Injection. This issue affects WooCommerce Point Of Sale (POS): from n/a through 1.4.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2982-34wj-7m53

10 месяцев назад

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce validation on the dismiss() function. This makes it possible for unauthenticated attackers to set arbitrary user meta values to `1` which can be leveraged to lock and administrator out of their site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2982-268x-jwcx

больше 3 лет назад

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.

EPSS: Низкий
github логотип

GHSA-297x-j9pm-xjgg

почти 2 года назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-297x-8xj4-vcxv

больше 3 лет назад

Improper Control of Generation of Code in doT

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-297x-2qf3-jrj3

около 2 лет назад

Unsafe yaml deserialization in llama-hub

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-297w-r8j3-c69q

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-297w-mgxc-v84x

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-297w-79rr-rq4p

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooCommerce.This issue affects Product Stock Manager & Notifier for WooCommerce: from n/a through 2.0.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-297v-qp46-84h5

больше 3 лет назад

NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound's delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-297v-jphp-x99g

почти 4 года назад

Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.

EPSS: Низкий
github логотип

GHSA-297r-x2mr-8f9w

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.

EPSS: Низкий
github логотип

GHSA-297r-jg48-c6q4

5 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-297q-7r2m-g586

больше 3 лет назад

In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-297p-pfx7-4599

больше 3 лет назад

Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.

EPSS: Низкий
github логотип

GHSA-297m-8m2m-8grg

больше 3 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.

EPSS: Средний
github логотип

GHSA-297j-p28c-w597

11 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EPC Massive Dynamic. This issue affects Massive Dynamic: from n/a through 8.2.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-297j-25fr-6hh8

больше 3 лет назад

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

EPSS: Низкий
github логотип

GHSA-297g-xg4h-7w4c

больше 1 года назад

Laravel Cross-site Scripting vulnerability in blade templating

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-297g-gfvh-fg6g

около 2 месяцев назад

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2983-hvjm-2229

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) allows SQL Injection. This issue affects WooCommerce Point Of Sale (POS): from n/a through 1.4.

CVSS3: 8.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2982-34wj-7m53

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce validation on the dismiss() function. This makes it possible for unauthenticated attackers to set arbitrary user meta values to `1` which can be leveraged to lock and administrator out of their site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2982-268x-jwcx

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-297x-j9pm-xjgg

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
94%
Критический
почти 2 года назад
github логотип
GHSA-297x-8xj4-vcxv

Improper Control of Generation of Code in doT

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-297x-2qf3-jrj3

Unsafe yaml deserialization in llama-hub

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-297w-r8j3-c69q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-297w-mgxc-v84x

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-297w-79rr-rq4p

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooCommerce.This issue affects Product Stock Manager & Notifier for WooCommerce: from n/a through 2.0.1.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-297v-qp46-84h5

NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound's delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-297v-jphp-x99g

Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.

1%
Низкий
почти 4 года назад
github логотип
GHSA-297r-x2mr-8f9w

Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.

1%
Низкий
почти 4 года назад
github логотип
GHSA-297r-jg48-c6q4

Rejected reason: Not used

5 месяцев назад
github логотип
GHSA-297q-7r2m-g586

In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-297p-pfx7-4599

Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-297m-8m2m-8grg

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.

24%
Средний
больше 3 лет назад
github логотип
GHSA-297j-p28c-w597

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EPC Massive Dynamic. This issue affects Massive Dynamic: from n/a through 8.2.

CVSS3: 9
0%
Низкий
11 месяцев назад
github логотип
GHSA-297j-25fr-6hh8

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-297g-xg4h-7w4c

Laravel Cross-site Scripting vulnerability in blade templating

CVSS3: 4.7
больше 1 года назад
github логотип
GHSA-297g-gfvh-fg6g

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.

CVSS3: 4.7
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу