Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-2gj8-24rx-v734

почти 4 года назад

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gj7-v6cw-hpq6

почти 4 года назад

Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.

EPSS: Низкий
github логотип

GHSA-2gj6-qx93-qj58

почти 4 года назад

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

EPSS: Высокий
github логотип

GHSA-2gj6-9mmj-r597

24 дня назад

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gj6-9934-w9r6

больше 1 года назад

Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service. This vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gj6-8x44-7f5c

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2gj6-558v-rq2w

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gj6-4m7m-3c82

почти 4 года назад

Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which may allow an attacker to execute a malicious macro by having a user to download, import, and open a specially crafted file in the local environment.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gj6-3jhw-wm56

почти 4 года назад

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:21:23.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gj5-wp37-4727

почти 4 года назад

The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2gj5-g2gq-97mp

8 месяцев назад

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

EPSS: Средний
github логотип

GHSA-2gj5-2jfx-vcmc

почти 4 года назад

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

EPSS: Низкий
github логотип

GHSA-2gj3-xrpr-w23r

почти 4 года назад

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

EPSS: Низкий
github логотип

GHSA-2gj2-vj98-j2qq

больше 3 лет назад

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2gj2-5v4g-j7xv

почти 4 года назад

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2ghx-mx8m-8w49

9 месяцев назад

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2ghv-58hc-7529

почти 4 года назад

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ghr-522h-prhx

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2ghq-fx5m-357p

около 1 года назад

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ghq-f5hx-5jwp

почти 4 года назад

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gj8-24rx-v734

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gj7-v6cw-hpq6

Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2gj6-qx93-qj58

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

77%
Высокий
почти 4 года назад
github логотип
GHSA-2gj6-9mmj-r597

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
24 дня назад
github логотип
GHSA-2gj6-9934-w9r6

Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service. This vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gj6-8x44-7f5c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2gj6-558v-rq2w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gj6-4m7m-3c82

Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which may allow an attacker to execute a malicious macro by having a user to download, import, and open a specially crafted file in the local environment.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gj6-3jhw-wm56

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:21:23.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gj5-wp37-4727

The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2gj5-g2gq-97mp

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

48%
Средний
8 месяцев назад
github логотип
GHSA-2gj5-2jfx-vcmc

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gj3-xrpr-w23r

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gj2-vj98-j2qq

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gj2-5v4g-j7xv

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVSS3: 6.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2ghx-mx8m-8w49

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2ghv-58hc-7529

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2ghr-522h-prhx

Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2ghq-fx5m-357p

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2ghq-f5hx-5jwp

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVSS3: 7.2
3%
Низкий
почти 4 года назад

Уязвимостей на страницу