Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xr96-c25j-m65g

около 4 лет назад

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr96-7ccp-pg5c

больше 4 лет назад

DotNetNuke Vulnerable to XSS in Pass-Through Values

EPSS: Низкий
github логотип

GHSA-xr96-49c7-2pfc

7 месяцев назад

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories & Taxonomies: from n/a through 1.0.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xr95-5hhj-crp6

около 4 лет назад

A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xr94-m5ww-76cc

больше 4 лет назад

FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.

EPSS: Средний
github логотип

GHSA-xr94-h88h-jc73

больше 1 года назад

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xr94-cv8c-7r6v

больше 2 лет назад

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr94-3hc5-534p

больше 2 лет назад

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22800.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr94-28q3-25f3

около 4 лет назад

The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr93-pcq3-pxf8

4 месяца назад

Zebra: addr/addrv2 Deserialization Resource Exhaustion

EPSS: Низкий
github логотип

GHSA-xr92-rw38-fmg9

около 4 лет назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

EPSS: Низкий
github логотип

GHSA-xr92-q26v-hcvr

около 4 лет назад

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

EPSS: Низкий
github логотип

GHSA-xr8x-pxm6-prjg

больше 3 лет назад

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xr8x-f92g-w7rv

около 2 лет назад

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr8x-5cxm-p785

больше 4 лет назад

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

EPSS: Низкий
github логотип

GHSA-xr8x-4mg2-g4gr

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr8x-4f65-m34g

больше 2 лет назад

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr8x-2h22-4fr9

около 4 лет назад

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <iframe> sandbox via a crafted HTML page.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xr8w-5325-33v3

около 1 года назад

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xr8v-mf39-c8v7

больше 4 лет назад

PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr96-c25j-m65g

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xr96-7ccp-pg5c

DotNetNuke Vulnerable to XSS in Pass-Through Values

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr96-49c7-2pfc

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories &amp; Taxonomies: from n/a through 1.0.3.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xr95-5hhj-crp6

A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr94-m5ww-76cc

FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.

17%
Средний
больше 4 лет назад
github логотип
GHSA-xr94-h88h-jc73

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 5.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-xr94-cv8c-7r6v

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr94-3hc5-534p

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22800.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr94-28q3-25f3

The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr93-pcq3-pxf8

Zebra: addr/addrv2 Deserialization Resource Exhaustion

0%
Низкий
4 месяца назад
github логотип
GHSA-xr92-rw38-fmg9

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr92-q26v-hcvr

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xr8x-pxm6-prjg

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CVSS3: 9.1
больше 3 лет назад
github логотип
GHSA-xr8x-f92g-w7rv

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr8x-5cxm-p785

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8x-4mg2-g4gr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-xr8x-4f65-m34g

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr8x-2h22-4fr9

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <iframe> sandbox via a crafted HTML page.

CVSS3: 9.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr8w-5325-33v3

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xr8v-mf39-c8v7

PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу