Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 083

Количество 323 083

github логотип

GHSA-2444-5vx9-4q2f

около 1 месяца назад

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted payloads through the ignoreLogACL parameter. Attackers can send POST requests to the proxy endpoint with JavaScript code in the ignoreLogACL parameter to execute arbitrary scripts in users' browsers.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2443-wh6v-5rjf

почти 4 года назад

Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.

EPSS: Низкий
github логотип

GHSA-2443-pfqf-c4ch

около 1 года назад

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2443-9w48-793g

больше 1 года назад

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2442-f237-7ghc

около 1 года назад

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2442-7w3j-mf4f

почти 4 года назад

An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2442-7hjc-vgc3

почти 4 года назад

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-243x-jj6v-4fj8

почти 4 года назад

IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186024.

EPSS: Низкий
github логотип

GHSA-243x-9r8g-wr3g

12 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Food ordering and Restaurant Menu allows PHP Local File Inclusion. This issue affects WP Food ordering and Restaurant Menu: from n/a through 1.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-243x-8mmp-f9jr

11 месяцев назад

The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-243w-cr2g-7p8m

почти 4 года назад

The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.

EPSS: Низкий
github логотип

GHSA-243v-xr6m-2w5j

почти 3 года назад

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-243v-fw8h-4xp3

почти 4 года назад

Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Replication.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-243v-98vx-264h

около 1 месяца назад

Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

EPSS: Низкий
github логотип

GHSA-243v-5pff-qqfj

больше 3 лет назад

Moodle Open redirect risk in mobile auto-login feature

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-243r-xrw9-vfhw

больше 2 лет назад

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-243r-v7fg-m2ff

почти 4 года назад

SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Низкий
github логотип

GHSA-243r-m3w5-w83p

больше 2 лет назад

The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-243r-cwrc-8j8h

около 3 лет назад

A vulnerability was found in 2071174A vinylmap. It has been classified as critical. Affected is the function contact of the file recordstoreapp/views.py. The manipulation leads to sql injection. The name of the patch is b07b79a1e92cc62574ba0492cce000ef4a7bd25f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218400.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-243r-85mw-fmg2

почти 4 года назад

Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2444-5vx9-4q2f

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted payloads through the ignoreLogACL parameter. Attackers can send POST requests to the proxy endpoint with JavaScript code in the ignoreLogACL parameter to execute arbitrary scripts in users' browsers.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2443-wh6v-5rjf

Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2443-pfqf-c4ch

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2443-9w48-793g

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2442-f237-7ghc

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2442-7w3j-mf4f

An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2442-7hjc-vgc3

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-243x-jj6v-4fj8

IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186024.

0%
Низкий
почти 4 года назад
github логотип
GHSA-243x-9r8g-wr3g

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Food ordering and Restaurant Menu allows PHP Local File Inclusion. This issue affects WP Food ordering and Restaurant Menu: from n/a through 1.1.

CVSS3: 8.1
1%
Низкий
12 месяцев назад
github логотип
GHSA-243x-8mmp-f9jr

The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-243w-cr2g-7p8m

The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.

0%
Низкий
почти 4 года назад
github логотип
GHSA-243v-xr6m-2w5j

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-243v-fw8h-4xp3

Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Replication.

CVSS3: 4.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-243v-98vx-264h

Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

0%
Низкий
около 1 месяца назад
github логотип
GHSA-243v-5pff-qqfj

Moodle Open redirect risk in mobile auto-login feature

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-243r-xrw9-vfhw

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-243r-v7fg-m2ff

SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-243r-m3w5-w83p

The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-243r-cwrc-8j8h

A vulnerability was found in 2071174A vinylmap. It has been classified as critical. Affected is the function contact of the file recordstoreapp/views.py. The manipulation leads to sql injection. The name of the patch is b07b79a1e92cc62574ba0492cce000ef4a7bd25f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218400.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-243r-85mw-fmg2

Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.

CVSS3: 8.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу