Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52rg-37rg-rfhm

больше 4 лет назад

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-52rf-xp84-3xvf

около 1 года назад

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /admin/slide.php. The manipulation of the argument idSlide leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-52rf-pfj9-676q

больше 4 лет назад

The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

EPSS: Низкий
github логотип

GHSA-52rf-25hq-5m33

больше 1 года назад

GeoNetwork search end-point information disclosure in response headers

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-52r9-g5g6-2hjp

около 8 лет назад

Path Traversal in node-srv

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52r8-qcqv-p7v2

больше 4 лет назад

The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-52r8-phxr-cfq6

около 2 лет назад

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "from" to be affected. But it must be assumed that parameter "to" is affected as well.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-52r7-gmhc-j7x9

больше 4 лет назад

Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.

EPSS: Средний
github логотип

GHSA-52r7-5244-6rfw

больше 4 лет назад

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52r7-445m-rwcg

больше 4 лет назад

Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52r6-x37j-435c

около 3 лет назад

A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-52r6-v45h-gh94

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search allows Stored XSS. This issue affects Lava Ajax Search: from n/a through 1.1.9.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-52r6-m74f-9g7w

почти 4 года назад

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52r6-fgpp-m7pq

больше 4 лет назад

The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-52r6-cp5p-c6x5

около 3 лет назад

SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-52r6-233g-595f

больше 4 лет назад

CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.

EPSS: Низкий
github логотип

GHSA-52r5-vp3g-vg7r

почти 3 года назад

DHCP Server Service Information Disclosure Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-52r5-crc5-6473

7 месяцев назад

An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52r5-7r4h-6hpf

больше 4 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework.

EPSS: Низкий
github логотип

GHSA-52r5-4x5p-ff7w

больше 4 лет назад

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect ID 00302077.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52rg-37rg-rfhm

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52rf-xp84-3xvf

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /admin/slide.php. The manipulation of the argument idSlide leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-52rf-pfj9-676q

The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-52rf-25hq-5m33

GeoNetwork search end-point information disclosure in response headers

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-52r9-g5g6-2hjp

Path Traversal in node-srv

CVSS3: 6.5
9%
Низкий
около 8 лет назад
github логотип
GHSA-52r8-qcqv-p7v2

The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52r8-phxr-cfq6

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "from" to be affected. But it must be assumed that parameter "to" is affected as well.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-52r7-gmhc-j7x9

Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.

22%
Средний
больше 4 лет назад
github логотип
GHSA-52r7-5244-6rfw

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52r7-445m-rwcg

Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52r6-x37j-435c

A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-52r6-v45h-gh94

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search allows Stored XSS. This issue affects Lava Ajax Search: from n/a through 1.1.9.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-52r6-m74f-9g7w

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-52r6-fgpp-m7pq

The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52r6-cp5p-c6x5

SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-52r6-233g-595f

CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52r5-vp3g-vg7r

DHCP Server Service Information Disclosure Vulnerability

CVSS3: 5.3
2%
Низкий
почти 3 года назад
github логотип
GHSA-52r5-crc5-6473

An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-52r5-7r4h-6hpf

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52r5-4x5p-ff7w

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect ID 00302077.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу