Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52x5-j3x8-48hp

около 3 лет назад

Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-52x5-63xf-5w3p

больше 4 лет назад

A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).

EPSS: Низкий
github логотип

GHSA-52x4-qwpg-c64f

почти 4 года назад

A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is 974f21aa1b2527ef39c8afe1a5060548217deca8. It is recommended to apply a patch to fix this issue. VDB-216498 is the identifier assigned to this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-52x4-pcpg-9vp8

почти 4 года назад

The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52x4-mg6c-cvc8

больше 3 лет назад

Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox cloud and device if the MAC address of a device if known.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52x4-hjxq-qrcm

больше 3 лет назад

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-52x3-hfmq-fxmq

больше 3 лет назад

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223111.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-52x3-94cg-xpgf

больше 4 лет назад

A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.html.

EPSS: Низкий
github логотип

GHSA-52x3-4q77-2jhw

больше 4 лет назад

minidlna has SQL Injection that may allow retrieval of arbitrary files

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52x2-jm85-hhjv

больше 4 лет назад

SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

EPSS: Низкий
github логотип

GHSA-52wx-ppx5-cwp9

больше 4 лет назад

Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.

EPSS: Средний
github логотип

GHSA-52wx-6vvh-8hww

больше 4 лет назад

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.

EPSS: Низкий
github логотип

GHSA-52wv-9457-3g76

больше 4 лет назад

The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files.

EPSS: Низкий
github логотип

GHSA-52wv-2qwp-5w9x

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

EPSS: Низкий
github логотип

GHSA-52wr-wgrx-pgjh

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Advanced Product Information for WooCommerce allows Stored XSS.This issue affects Advanced Product Information for WooCommerce: from n/a through 1.1.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52wr-qfvp-rcxr

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-52wr-g3vp-7h6v

18 дней назад

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-52wr-3vww-rmpq

больше 4 лет назад

SOAPpy vulnerable to XML External Entity attacks

EPSS: Низкий
github логотип

GHSA-52wr-2fpp-5m5m

больше 2 лет назад

A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registrar/. The manipulation of the argument search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-265202 is the identifier assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-52wq-q527-xcxw

больше 4 лет назад

The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted VPx video data.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52x5-j3x8-48hp

Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

CVSS3: 8
0%
Низкий
около 3 лет назад
github логотип
GHSA-52x5-63xf-5w3p

A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52x4-qwpg-c64f

A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is 974f21aa1b2527ef39c8afe1a5060548217deca8. It is recommended to apply a patch to fix this issue. VDB-216498 is the identifier assigned to this vulnerability.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-52x4-pcpg-9vp8

The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-52x4-mg6c-cvc8

Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox cloud and device if the MAC address of a device if known.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-52x4-hjxq-qrcm

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-52x3-hfmq-fxmq

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223111.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-52x3-94cg-xpgf

A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.html.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52x3-4q77-2jhw

minidlna has SQL Injection that may allow retrieval of arbitrary files

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52x2-jm85-hhjv

SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52wx-ppx5-cwp9

Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.

12%
Средний
больше 4 лет назад
github логотип
GHSA-52wx-6vvh-8hww

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-52wv-9457-3g76

The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-52wv-2qwp-5w9x

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52wr-wgrx-pgjh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Advanced Product Information for WooCommerce allows Stored XSS.This issue affects Advanced Product Information for WooCommerce: from n/a through 1.1.4.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-52wr-qfvp-rcxr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-52wr-g3vp-7h6v

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

CVSS3: 7.7
0%
Низкий
18 дней назад
github логотип
GHSA-52wr-3vww-rmpq

SOAPpy vulnerable to XML External Entity attacks

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52wr-2fpp-5m5m

A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registrar/. The manipulation of the argument search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-265202 is the identifier assigned to this vulnerability.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-52wq-q527-xcxw

The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted VPx video data.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу