Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4vrf-42cm-7xfw

11 месяцев назад

TastyIgniter vulnerable to Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-4vrc-q7m6-vq7w

почти 4 года назад

Lin CMS vulnerable to Improper Authentication

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-4vrc-p2pf-p4qj

21 день назад

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4vrc-m9ch-6m3r

4 месяца назад

Open WebUI has stored XSS via the HTML renedering view

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4vrc-j85c-598c

5 месяцев назад

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vr9-m32x-692g

больше 4 лет назад

Lack of check on out of range for channels When processing channel list set command will lead to buffer flow in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4vr9-8jj4-gfwv

6 месяцев назад

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations, including internal services, via the Gopher protocol and other dangerous protocols. This can be exploited to achieve Remote Code Execution by chaining with services like Redis.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4vr9-8cjf-vf9c

почти 5 лет назад

Async-h1 request smuggling possible with long unread bodies

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4vr9-3763-mphq

больше 4 лет назад

A vulnerability in the Cisco application-hosting framework (CAF) of Cisco IOx could allow an authenticated, remote attacker to read arbitrary files on a targeted system. Affected Products: This vulnerability affects specific releases of the Cisco IOx subsystem of Cisco IOS and IOS XE Software. More Information: CSCvb23331. Known Affected Releases: 15.2(6.0.57i)E CAF-1.1.0.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vr9-33fv-mg6r

около 4 лет назад

Cross site scripting in ameos_tarteaucitron

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4vr8-r7qr-fpvq

больше 4 лет назад

Plone Privilege escalation through exposed underlying API

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4vr7-m8p8-434h

больше 4 лет назад

MediaWiki Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vr7-hw2p-5fvc

больше 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands on an affected device. The vulnerabilities exist because the web-based management interface does not properly validate user-supplied input to scripts. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending malicious requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

EPSS: Низкий
github логотип

GHSA-4vr7-g93g-cf6m

около 1 года назад

Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check

EPSS: Низкий
github логотип

GHSA-4vr7-cqg2-r964

больше 4 лет назад

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.

EPSS: Низкий
github логотип

GHSA-4vr7-2w2q-jv5q

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4vr6-qr4v-xmvq

около 2 лет назад

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4vr6-gq8x-m5fh

5 месяцев назад

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

EPSS: Низкий
github логотип

GHSA-4vr5-p2gc-h23p

около 2 месяцев назад

rclone archive extract allows S3 destination prefix escape via crafted archive paths

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-4vr4-w499-9g67

почти 4 года назад

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vrf-42cm-7xfw

TastyIgniter vulnerable to Cross-Site Scripting

1%
Низкий
11 месяцев назад
github логотип
GHSA-4vrc-q7m6-vq7w

Lin CMS vulnerable to Improper Authentication

CVSS3: 6.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-4vrc-p2pf-p4qj

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.

CVSS3: 4.9
0%
Низкий
21 день назад
github логотип
GHSA-4vrc-m9ch-6m3r

Open WebUI has stored XSS via the HTML renedering view

CVSS3: 7.7
0%
Низкий
4 месяца назад
github логотип
GHSA-4vrc-j85c-598c

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4vr9-m32x-692g

Lack of check on out of range for channels When processing channel list set command will lead to buffer flow in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vr9-8jj4-gfwv

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations, including internal services, via the Gopher protocol and other dangerous protocols. This can be exploited to achieve Remote Code Execution by chaining with services like Redis.

CVSS3: 7.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-4vr9-8cjf-vf9c

Async-h1 request smuggling possible with long unread bodies

CVSS3: 6.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4vr9-3763-mphq

A vulnerability in the Cisco application-hosting framework (CAF) of Cisco IOx could allow an authenticated, remote attacker to read arbitrary files on a targeted system. Affected Products: This vulnerability affects specific releases of the Cisco IOx subsystem of Cisco IOS and IOS XE Software. More Information: CSCvb23331. Known Affected Releases: 15.2(6.0.57i)E CAF-1.1.0.0.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vr9-33fv-mg6r

Cross site scripting in ameos_tarteaucitron

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-4vr8-r7qr-fpvq

Plone Privilege escalation through exposed underlying API

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vr7-m8p8-434h

MediaWiki Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vr7-hw2p-5fvc

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands on an affected device. The vulnerabilities exist because the web-based management interface does not properly validate user-supplied input to scripts. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending malicious requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4vr7-g93g-cf6m

Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check

около 1 года назад
github логотип
GHSA-4vr7-cqg2-r964

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perform taint checking for CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive image data by leveraging a redirect to a data:image resource.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4vr7-2w2q-jv5q

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-4vr6-qr4v-xmvq

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.

CVSS3: 6.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4vr6-gq8x-m5fh

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

5 месяцев назад
github логотип
GHSA-4vr5-p2gc-h23p

rclone archive extract allows S3 destination prefix escape via crafted archive paths

CVSS3: 5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4vr4-w499-9g67

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу