Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4vqm-wcg3-r4cm

больше 2 лет назад

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vqm-j4g4-5vv7

больше 4 лет назад

The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4vqm-49vv-x7x2

около 1 года назад

A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file quantity_upd.php. The manipulation of the argument med_name/med_cat/ex_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4vqj-mgvj-g5h9

больше 4 лет назад

The Advan i6A Android device with a build fingerprint of ADVAN/i6A/i6A:8.1.0/O11019/1523602705:userdebug/test-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

EPSS: Низкий
github логотип

GHSA-4vqj-9m7j-xf46

больше 4 лет назад

The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted packet that is sent during tunnel creation, aka Bug ID CSCum96401.

EPSS: Низкий
github логотип

GHSA-4vqg-xgxp-xqgh

3 месяца назад

The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete the site's security.txt file from the server filesystem or create the .well-known directory by directly invoking the delete_securitytxt or create_wellknown_folder AJAX actions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4vqg-hq2v-8672

почти 2 года назад

Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4vqf-pwq6-3wh3

больше 1 года назад

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords, and other critical data. Unauthorized access to critical server files, such as configuration files, user credentials (/etc/passwd), and private keys, can lead to a complete compromise of the system's security. Attackers could leverage the exposed information to further penetrate the network, exfiltrate data, or escalate privileges within the environment.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4vqc-wpwg-vh7j

4 месяца назад

kas's late signature validation may allow unnoticed repository manipulations

EPSS: Низкий
github логотип

GHSA-4vqc-4jrp-pwj7

около 4 лет назад

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vq9-rwg9-vq6x

больше 1 года назад

Insertion of Sensitive Information Into Sent Data vulnerability in AppExperts AppExperts – WordPress to Mobile App – WooCommerce to iOs and Android Apps allows Retrieve Embedded Sensitive Data. This issue affects AppExperts – WordPress to Mobile App – WooCommerce to iOs and Android Apps: from n/a through 1.4.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4vq9-fqw4-6r9r

больше 4 лет назад

Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.

EPSS: Низкий
github логотип

GHSA-4vq9-9g4j-pgg4

больше 4 лет назад

The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

EPSS: Низкий
github логотип

GHSA-4vq9-542f-qfqx

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce allows Cross Site Request Forgery. This issue affects Official CleverReach Plugin for WooCommerce: from n/a through 3.4.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vq9-4m7p-f69x

26 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-4vq8-hcpj-2v9j

больше 4 лет назад

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vq8-7jfc-9cvp

около 1 года назад

Moby firewalld reload removes bridge network isolation

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4vq8-4jhj-wj97

больше 4 лет назад

SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter.

EPSS: Низкий
github логотип

GHSA-4vq7-xgx9-437g

больше 4 лет назад

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

EPSS: Низкий
github логотип

GHSA-4vq7-882g-wcg4

больше 3 лет назад

Vega Expression Language `scale` expression function Cross Site Scripting

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vqm-wcg3-r4cm

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vqm-j4g4-5vv7

The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vqm-49vv-x7x2

A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file quantity_upd.php. The manipulation of the argument med_name/med_cat/ex_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4vqj-mgvj-g5h9

The Advan i6A Android device with a build fingerprint of ADVAN/i6A/i6A:8.1.0/O11019/1523602705:userdebug/test-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vqj-9m7j-xf46

The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted packet that is sent during tunnel creation, aka Bug ID CSCum96401.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vqg-xgxp-xqgh

The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete the site's security.txt file from the server filesystem or create the .well-known directory by directly invoking the delete_securitytxt or create_wellknown_folder AJAX actions.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4vqg-hq2v-8672

Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.

CVSS3: 5.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-4vqf-pwq6-3wh3

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords, and other critical data. Unauthorized access to critical server files, such as configuration files, user credentials (/etc/passwd), and private keys, can lead to a complete compromise of the system's security. Attackers could leverage the exposed information to further penetrate the network, exfiltrate data, or escalate privileges within the environment.

CVSS3: 6.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-4vqc-wpwg-vh7j

kas's late signature validation may allow unnoticed repository manipulations

0%
Низкий
4 месяца назад
github логотип
GHSA-4vqc-4jrp-pwj7

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-4vq9-rwg9-vq6x

Insertion of Sensitive Information Into Sent Data vulnerability in AppExperts AppExperts – WordPress to Mobile App – WooCommerce to iOs and Android Apps allows Retrieve Embedded Sensitive Data. This issue affects AppExperts – WordPress to Mobile App – WooCommerce to iOs and Android Apps: from n/a through 1.4.3.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vq9-fqw4-6r9r

Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vq9-9g4j-pgg4

The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4vq9-542f-qfqx

Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce allows Cross Site Request Forgery. This issue affects Official CleverReach Plugin for WooCommerce: from n/a through 3.4.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vq9-4m7p-f69x

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

26 дней назад
github логотип
GHSA-4vq8-hcpj-2v9j

GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vq8-7jfc-9cvp

Moby firewalld reload removes bridge network isolation

CVSS3: 3.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4vq8-4jhj-wj97

SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vq7-xgx9-437g

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vq7-882g-wcg4

Vega Expression Language `scale` expression function Cross Site Scripting

CVSS3: 6.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу