Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 378 275

Количество 378 275

github логотип

GHSA-53c2-v8m6-cxf3

больше 4 лет назад

"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

EPSS: Низкий
github логотип

GHSA-53c2-8q6v-xx43

около 2 лет назад

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-53c2-2qjx-38qh

больше 4 лет назад

IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.

EPSS: Низкий
github логотип

GHSA-539x-x6m2-jhf2

больше 4 лет назад

content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigates away.

EPSS: Низкий
github логотип

GHSA-539v-w87w-w62c

больше 1 года назад

Magento Improper Access Control vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-539q-fqrf-rmxr

больше 4 лет назад

A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-539q-2529-45wv

больше 4 лет назад

Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-539q-24vg-qfm4

больше 4 лет назад

** DISPUTED ** In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crated file. NOTE: multiple third parties dispute the significance of this finding.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-539p-58qq-4359

больше 4 лет назад

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-539m-9xh6-q6rr

около 2 месяцев назад

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-539m-5qhp-7m96

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-539j-9cqc-ppx4

около 2 месяцев назад

A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. Performing a manipulation of the argument filePath results in path traversal. The attack is only possible with local access. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-539h-7w76-4wrc

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights Access Manager: from n/a through 1.1.2.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-539g-ppw2-7c4r

больше 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-539g-jjhg-mch4

8 месяцев назад

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3..4.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-539f-5h6r-p5pf

больше 3 лет назад

Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-539c-wv27-33m6

больше 4 лет назад

An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R2-S8, 18.4R3-S7; 19.1 versions prior to 19.1R2-S3, 19.1R3-S5; 19.2 versions prior to 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S2; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R2-S3, 20.2R3; 20.3 versions prior to 20.3R3; 20.4 versions prior to 20.4R1-S1, 20.4R2.

EPSS: Низкий
github логотип

GHSA-539c-rp35-q667

больше 4 лет назад

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-539c-mj4x-m9hp

27 дней назад

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-539c-2w6v-9rwx

больше 4 лет назад

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-53c2-v8m6-cxf3

"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-53c2-8q6v-xx43

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
около 2 лет назад
github логотип
GHSA-53c2-2qjx-38qh

IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-539x-x6m2-jhf2

content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigates away.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-539v-w87w-w62c

Magento Improper Access Control vulnerability

CVSS3: 6.5
больше 1 года назад
github логотип
GHSA-539q-fqrf-rmxr

A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-539q-2529-45wv

Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-539q-24vg-qfm4

** DISPUTED ** In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crated file. NOTE: multiple third parties dispute the significance of this finding.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-539p-58qq-4359

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-539m-9xh6-q6rr

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

CVSS3: 6.5
около 2 месяцев назад
github логотип
GHSA-539m-5qhp-7m96

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-539j-9cqc-ppx4

A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. Performing a manipulation of the argument filePath results in path traversal. The attack is only possible with local access. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
около 2 месяцев назад
github логотип
GHSA-539h-7w76-4wrc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights Access Manager: from n/a through 1.1.2.

CVSS3: 5.8
больше 2 лет назад
github логотип
GHSA-539g-ppw2-7c4r

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-539g-jjhg-mch4

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3..4.

CVSS3: 7.6
8 месяцев назад
github логотип
GHSA-539f-5h6r-p5pf

Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-539c-wv27-33m6

An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated attacker to cause routing process daemon (RPD) to crash and restart, causing a Denial of Service (DoS). Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R2-S8, 18.4R3-S7; 19.1 versions prior to 19.1R2-S3, 19.1R3-S5; 19.2 versions prior to 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S2; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R2-S3, 20.2R3; 20.3 versions prior to 20.3R3; 20.4 versions prior to 20.4R1-S1, 20.4R2.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-539c-rp35-q667

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-539c-mj4x-m9hp

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.

CVSS3: 8.1
27 дней назад
github логотип
GHSA-539c-2w6v-9rwx

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CVSS3: 9.8
87%
Высокий
больше 4 лет назад

Уязвимостей на страницу