Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4wrr-4v2p-hg4v

8 месяцев назад

The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple settings fields in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4wrq-hgcp-rfc5

больше 4 лет назад

PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The bottom.php parameter is already covered by CVE-2006-4826.

EPSS: Низкий
github логотип

GHSA-4wrq-727c-gxwh

больше 4 лет назад

The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.

EPSS: Низкий
github логотип

GHSA-4wrp-m389-3rjm

больше 4 лет назад

Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4wrp-79m8-9m9p

5 месяцев назад

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4wrp-2fvc-9x8r

5 дней назад

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4wrm-qmq2-5fjx

почти 3 года назад

Directory Traversal in evershop

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4wrm-6rc2-jx27

11 месяцев назад

Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4wrm-25vr-9gjf

больше 4 лет назад

js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

EPSS: Низкий
github логотип

GHSA-4wrj-qhhf-3c55

около 2 лет назад

An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wrj-7475-35c2

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alberuni Azad Faltu Testimonial Rotator allows DOM-Based XSS.This issue affects Faltu Testimonial Rotator: from n/a through 1.0.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wrj-5x53-grvr

больше 4 лет назад

Untrusted search path vulnerability in the installer of LHMelting (LHMelting for Win32 Ver 1.65.3.6 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wrh-wg8j-2jv3

больше 3 лет назад

A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/?page=reminders/view_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226275.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4wrh-8j8q-8frq

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-4wrh-7cfv-pf4r

около 1 месяца назад

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wrg-fcqh-8cg6

больше 4 лет назад

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wrg-8wpc-h923

5 месяцев назад

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wrf-49x3-48xx

больше 4 лет назад

claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.

EPSS: Низкий
github логотип

GHSA-4wrf-2w9m-mh9f

больше 4 лет назад

Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current administrator password a second time via the GUI or GUI terminal commands.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4wrc-rw64-f2jp

больше 4 лет назад

The Absolute Lending Solutions (aka com.soln.S008F6C05EC0B63264B429F6D76286562) application 1.0073.b0073 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4wrr-4v2p-hg4v

The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple settings fields in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-4wrq-hgcp-rfc5

PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The bottom.php parameter is already covered by CVE-2006-4826.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrq-727c-gxwh

The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrp-m389-3rjm

Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrp-79m8-9m9p

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-4wrp-2fvc-9x8r

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

CVSS3: 5.9
0%
Низкий
5 дней назад
github логотип
GHSA-4wrm-qmq2-5fjx

Directory Traversal in evershop

CVSS3: 5.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-4wrm-6rc2-jx27

Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

CVSS3: 7
0%
Низкий
11 месяцев назад
github логотип
GHSA-4wrm-25vr-9gjf

js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrj-qhhf-3c55

An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4wrj-7475-35c2

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alberuni Azad Faltu Testimonial Rotator allows DOM-Based XSS.This issue affects Faltu Testimonial Rotator: from n/a through 1.0.0.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4wrj-5x53-grvr

Untrusted search path vulnerability in the installer of LHMelting (LHMelting for Win32 Ver 1.65.3.6 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrh-wg8j-2jv3

A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/?page=reminders/view_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226275.

CVSS3: 4.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4wrh-8j8q-8frq

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.

CVSS3: 9.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wrh-7cfv-pf4r

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4wrg-fcqh-8cg6

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrg-8wpc-h923

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4wrf-49x3-48xx

claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrf-2w9m-mh9f

Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current administrator password a second time via the GUI or GUI terminal commands.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrc-rw64-f2jp

The Absolute Lending Solutions (aka com.soln.S008F6C05EC0B63264B429F6D76286562) application 1.0073.b0073 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу