Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-xxj3-2v78-2rpq

3 месяца назад

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxj2-p55v-46x5

почти 4 года назад

Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.

EPSS: Низкий
github логотип

GHSA-xxj2-mx8m-c7xg

около 1 года назад

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxj2-44jh-42qg

больше 3 лет назад

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxhx-8hf5-qg7v

больше 3 лет назад

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxhx-7292-7rv8

22 дня назад

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxhx-5qm4-836m

больше 3 лет назад

The RADIOS DEL ECUADOR (aka com.nobexinc.wls_87612622.rc) application 3.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xxhw-w5qp-5pvr

почти 4 года назад

Reflected XSS in wordpress plugin heat-trackr v1.0

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxhw-v6w9-gq64

7 месяцев назад

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxhw-935w-672r

больше 2 лет назад

A vulnerability, which was classified as problematic, was found in Gravity Forms DPS PxPay Plugin up to 1.4.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 5966a5e6343e3d5610bdfa126a5cfbae95e629b6. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230664.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xxhw-3mwj-8m78

почти 4 года назад

Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

EPSS: Средний
github логотип

GHSA-xxhr-wjq6-3g79

больше 3 лет назад

ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.

EPSS: Низкий
github логотип

GHSA-xxhr-8f54-6m66

почти 4 года назад

Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxhr-3f3g-r47h

больше 1 года назад

In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxhm-2g3m-gv88

больше 3 лет назад

main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxhj-whx7-2xjg

больше 2 лет назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxhh-59gh-6ffx

почти 3 года назад

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxhg-xvhq-pmx2

больше 3 лет назад

Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xxhg-c875-v6qf

почти 4 года назад

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

EPSS: Низкий
github логотип

GHSA-xxhf-xq6v-c8mj

больше 3 лет назад

Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxj3-2v78-2rpq

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xxj2-p55v-46x5

Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxj2-mx8m-c7xg

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
3%
Низкий
около 1 года назад
github логотип
GHSA-xxj2-44jh-42qg

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhx-8hf5-qg7v

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhx-7292-7rv8

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.

CVSS3: 5.4
0%
Низкий
22 дня назад
github логотип
GHSA-xxhx-5qm4-836m

The RADIOS DEL ECUADOR (aka com.nobexinc.wls_87612622.rc) application 3.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhw-w5qp-5pvr

Reflected XSS in wordpress plugin heat-trackr v1.0

CVSS3: 6.1
7%
Низкий
почти 4 года назад
github логотип
GHSA-xxhw-v6w9-gq64

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xxhw-935w-672r

A vulnerability, which was classified as problematic, was found in Gravity Forms DPS PxPay Plugin up to 1.4.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 5966a5e6343e3d5610bdfa126a5cfbae95e629b6. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230664.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxhw-3mwj-8m78

Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

46%
Средний
почти 4 года назад
github логотип
GHSA-xxhr-wjq6-3g79

ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhr-8f54-6m66

Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxhr-3f3g-r47h

In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxhm-2g3m-gv88

main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhj-whx7-2xjg

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxhh-59gh-6ffx

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.

CVSS3: 8.8
3%
Низкий
почти 3 года назад
github логотип
GHSA-xxhg-xvhq-pmx2

Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhg-c875-v6qf

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

6%
Низкий
почти 4 года назад
github логотип
GHSA-xxhf-xq6v-c8mj

Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement

CVSS3: 5.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу