Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 827

Количество 326 827

github логотип

GHSA-2hw5-388c-g7xj

почти 4 года назад

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw3-wmq2-hxf7

почти 4 года назад

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hw3-rfjc-q8m6

6 месяцев назад

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-2hw3-h8qx-hqqp

10 месяцев назад

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw3-28v7-q78p

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

EPSS: Средний
github логотип

GHSA-2hw2-hc6g-cv7v

6 месяцев назад

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hw2-h3mf-c2j9

почти 4 года назад

Moodle open redirect vulnerability

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2hw2-7jq8-w9vp

больше 4 лет назад

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

EPSS: Высокий
github логотип

GHSA-2hw2-62cp-p9p7

почти 7 лет назад

Access control bypass in Apache ZooKeeper

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hvx-m86j-h9m3

почти 4 года назад

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

EPSS: Средний
github логотип

GHSA-2hvx-9r8j-qvph

почти 3 года назад

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hvx-93c2-p928

больше 2 лет назад

** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2hvw-r4rp-mjpp

больше 2 лет назад

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hvv-h4pw-wcm2

почти 4 года назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

EPSS: Низкий
github логотип

GHSA-2hvr-h6gw-qrxp

больше 3 лет назад

Cargo extracting malicious crates can fill the file system

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2hvr-43xf-39rx

около 3 лет назад

Not used in 2022

EPSS: Низкий
github логотип

GHSA-2hvq-vmfm-c497

больше 3 лет назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2hvm-7cm7-f4p9

почти 4 года назад

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hvj-wgq7-vx3c

почти 4 года назад

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

EPSS: Низкий
github логотип

GHSA-2hvj-p59v-p559

около 1 года назад

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hw5-388c-g7xj

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2hw3-wmq2-hxf7

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2hw3-rfjc-q8m6

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

CVSS3: 9
0%
Низкий
6 месяцев назад
github логотип
GHSA-2hw3-h8qx-hqqp

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2hw3-28v7-q78p

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

48%
Средний
почти 4 года назад
github логотип
GHSA-2hw2-hc6g-cv7v

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2hw2-h3mf-c2j9

Moodle open redirect vulnerability

CVSS3: 7.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2hw2-7jq8-w9vp

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

75%
Высокий
больше 4 лет назад
github логотип
GHSA-2hw2-62cp-p9p7

Access control bypass in Apache ZooKeeper

CVSS3: 5.9
0%
Низкий
почти 7 лет назад
github логотип
GHSA-2hvx-m86j-h9m3

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

23%
Средний
почти 4 года назад
github логотип
GHSA-2hvx-9r8j-qvph

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2hvx-93c2-p928

** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hvw-r4rp-mjpp

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVSS3: 5.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2hvv-h4pw-wcm2

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hvr-h6gw-qrxp

Cargo extracting malicious crates can fill the file system

CVSS3: 4.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvr-43xf-39rx

Not used in 2022

около 3 лет назад
github логотип
GHSA-2hvq-vmfm-c497

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvm-7cm7-f4p9

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2hvj-wgq7-vx3c

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hvj-p59v-p559

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу