Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v65-5rwc-6vwm

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ThemeIsle Hestia allows Cross Site Request Forgery.This issue affects Hestia: from n/a through 3.1.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v65-2p65-mvwf

больше 4 лет назад

ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-4v64-w7v7-ch7f

около 3 лет назад

An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4v64-pj7p-h4rr

больше 4 лет назад

Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.

EPSS: Низкий
github логотип

GHSA-4v64-3g6p-jfw6

больше 4 лет назад

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v63-pgpj-7w24

больше 4 лет назад

Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

EPSS: Низкий
github логотип

GHSA-4v63-9rgj-4j4x

больше 1 года назад

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v62-8fqp-chch

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

EPSS: Низкий
github логотип

GHSA-4v5x-9m47-cqr2

почти 2 года назад

Duplicate Advisory: WildFly Elytron OpenID Connect Client Extension authorization code injection attack

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-4v5x-6vf6-8x7f

больше 4 лет назад

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8477, CVE-2018-8622.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v5x-46v5-4rgc

больше 4 лет назад

The Rastreador de Celulares (aka com.mobincube.android.sc_9KTH8) application 5.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4v5x-38hq-2rvf

больше 3 лет назад

Windows Backup Service Elevation of Privilege Vulnerability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4v5w-7xfw-cxmr

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14865.

EPSS: Низкий
github логотип

GHSA-4v5v-pg2w-hjcf

почти 3 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Stored XSS.This issue affects Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo: from n/a through 2.2.24.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4v5v-52wm-9x72

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: add null check [WHY] Prevents null pointer dereferences to enhance function robustness [HOW] Adds early null check and return false if invalid.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v5r-xr6m-8fwr

3 месяца назад

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4v5r-p2wq-3j8j

больше 2 лет назад

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-4v5r-6pw6-j2rg

2 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v5r-686x-5pph

9 месяцев назад

The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v5r-3fh9-hjh3

больше 4 лет назад

KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v65-5rwc-6vwm

Cross-Site Request Forgery (CSRF) vulnerability in ThemeIsle Hestia allows Cross Site Request Forgery.This issue affects Hestia: from n/a through 3.1.2.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v65-2p65-mvwf

ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v64-w7v7-ch7f

An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.

CVSS3: 6.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-4v64-pj7p-h4rr

Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v64-3g6p-jfw6

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v63-pgpj-7w24

Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v63-9rgj-4j4x

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v62-8fqp-chch

Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5x-9m47-cqr2

Duplicate Advisory: WildFly Elytron OpenID Connect Client Extension authorization code injection attack

CVSS3: 4.2
почти 2 года назад
github логотип
GHSA-4v5x-6vf6-8x7f

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8477, CVE-2018-8622.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5x-46v5-4rgc

The Rastreador de Celulares (aka com.mobincube.android.sc_9KTH8) application 5.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5x-38hq-2rvf

Windows Backup Service Elevation of Privilege Vulnerability.

CVSS3: 7.1
5%
Низкий
больше 3 лет назад
github логотип
GHSA-4v5w-7xfw-cxmr

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14865.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5v-pg2w-hjcf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Stored XSS.This issue affects Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo: from n/a through 2.2.24.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-4v5v-52wm-9x72

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: add null check [WHY] Prevents null pointer dereferences to enhance function robustness [HOW] Adds early null check and return false if invalid.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4v5r-xr6m-8fwr

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.

CVSS3: 7.7
1%
Низкий
3 месяца назад
github логотип
GHSA-4v5r-p2wq-3j8j

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

CVSS3: 7.9
8%
Низкий
больше 2 лет назад
github логотип
GHSA-4v5r-6pw6-j2rg

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-4v5r-686x-5pph

The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-4v5r-3fh9-hjh3

KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу