Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c8v-3247-5w53

больше 3 лет назад

Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adversary with WMS group admin access could potentially exploit this vulnerability, leading to temporary denial-of-service.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2c8r-x33h-7828

почти 4 года назад

Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.

EPSS: Низкий
github логотип

GHSA-2c8r-m99r-h2pj

почти 4 года назад

SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2c8q-6p99-6rj3

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2c8q-6gj7-g33w

почти 3 года назад

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2c8q-5cp4-4jf7

почти 4 года назад

Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c8p-fcx5-8r73

больше 3 лет назад

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2c8p-cf3h-g92r

почти 4 года назад

Untrusted search path vulnerability in MunSoft Easy Office Recovery 1.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .doc, .xls, or .ppt file. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2c8p-8v35-g4g6

почти 4 года назад

In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2c8m-gphg-q96w

почти 4 года назад

CuteFTP uses weak encryption to store password information in its tree.dat file.

EPSS: Низкий
github логотип

GHSA-2c8h-r8fq-rgch

почти 2 года назад

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c8h-6hfp-gpv6

больше 2 лет назад

Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 2 or more.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c8h-4v5j-p9cq

8 месяцев назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue affects myCred: from n/a through 2.9.4.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c8f-m29p-3q3j

почти 4 года назад

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2c8c-xhwv-r7h7

больше 3 лет назад

Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c8c-h5pf-cx5h

около 2 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4. An app from a standard user account may be able to escalate privilege after admin user login.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2c8c-84w2-j38j

около 5 лет назад

Improper Restriction of XML External Entity Reference in Plone

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c8c-2rmr-9rrp

почти 4 года назад

A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2c89-h2r9-m4fw

почти 4 года назад

The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2c89-6hf9-mggj

почти 4 года назад

Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c8v-3247-5w53

Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adversary with WMS group admin access could potentially exploit this vulnerability, leading to temporary denial-of-service.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c8r-x33h-7828

Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2c8r-m99r-h2pj

SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c8q-6p99-6rj3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c8q-6gj7-g33w

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2c8q-5cp4-4jf7

Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c8p-fcx5-8r73

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c8p-cf3h-g92r

Untrusted search path vulnerability in MunSoft Easy Office Recovery 1.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .doc, .xls, or .ppt file. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c8p-8v35-g4g6

In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.

CVSS3: 2.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c8m-gphg-q96w

CuteFTP uses weak encryption to store password information in its tree.dat file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c8h-r8fq-rgch

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.

CVSS3: 8.8
почти 2 года назад
github логотип
GHSA-2c8h-6hfp-gpv6

Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 2 or more.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c8h-4v5j-p9cq

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue affects myCred: from n/a through 2.9.4.3.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2c8f-m29p-3q3j

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c8c-xhwv-r7h7

Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c8c-h5pf-cx5h

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4. An app from a standard user account may be able to escalate privilege after admin user login.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c8c-84w2-j38j

Improper Restriction of XML External Entity Reference in Plone

CVSS3: 8.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-2c8c-2rmr-9rrp

A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c89-h2r9-m4fw

The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2c89-6hf9-mggj

Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method.

11%
Средний
почти 4 года назад

Уязвимостей на страницу