Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-26r4-vjwg-4pqh

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.

EPSS: Низкий
github логотип

GHSA-26r4-j8xv-5q4j

почти 4 года назад

Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.

EPSS: Средний
github логотип

GHSA-26r4-gcg8-rjjp

11 месяцев назад

A vulnerability, which was classified as critical, has been found in Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26r4-c2j9-3fcx

почти 4 года назад

SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.

EPSS: Низкий
github логотип

GHSA-26r4-3m3w-c772

почти 4 года назад

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

EPSS: Низкий
github логотип

GHSA-26r3-pw5g-9v53

почти 4 года назад

The mintToken function of a smart contract implementation for Trabet_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26r2-pm58-r4jr

больше 1 года назад

Windows MSHTML Platform Spoofing Vulnerability

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-26r2-c5w2-92vj

почти 4 года назад

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26r2-6q54-995j

почти 4 года назад

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26qx-fmxx-pg6h

почти 4 года назад

Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26qx-4m49-6cfr

больше 2 лет назад

wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26qv-p8cr-jxp5

10 месяцев назад

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-26qv-cc62-952x

5 месяцев назад

Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26qv-3573-wxg2

больше 1 года назад

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26qr-qf74-v2w4

почти 4 года назад

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

EPSS: Низкий
github логотип

GHSA-26qr-hrpr-gcj8

2 месяца назад

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26qr-5f59-55qh

почти 4 года назад

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26qr-26wf-xv6x

14 дней назад

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

EPSS: Низкий
github логотип

GHSA-26qq-h2w9-r3wv

почти 4 года назад

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-26qq-9jw6-r5h4

почти 4 года назад

Intesync Solismed 3.3sp has Incorrect Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26r4-vjwg-4pqh

Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26r4-j8xv-5q4j

Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.

19%
Средний
почти 4 года назад
github логотип
GHSA-26r4-gcg8-rjjp

A vulnerability, which was classified as critical, has been found in Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-26r4-c2j9-3fcx

SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26r4-3m3w-c772

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-26r3-pw5g-9v53

The mintToken function of a smart contract implementation for Trabet_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-26r2-pm58-r4jr

Windows MSHTML Platform Spoofing Vulnerability

CVSS3: 6.5
18%
Средний
больше 1 года назад
github логотип
GHSA-26r2-c5w2-92vj

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-26r2-6q54-995j

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qx-fmxx-pg6h

Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qx-4m49-6cfr

wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26qv-p8cr-jxp5

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
52%
Средний
10 месяцев назад
github логотип
GHSA-26qv-cc62-952x

Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-26qv-3573-wxg2

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-26qr-qf74-v2w4

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26qr-hrpr-gcj8

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
1%
Низкий
2 месяца назад
github логотип
GHSA-26qr-5f59-55qh

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qr-26wf-xv6x

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

0%
Низкий
14 дней назад
github логотип
GHSA-26qq-h2w9-r3wv

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS3: 7
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qq-9jw6-r5h4

Intesync Solismed 3.3sp has Incorrect Access Control.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу