Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v3m-mrm4-6g89

больше 1 года назад

SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4v3m-fhx4-qp25

больше 4 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v3j-q36m-pfpg

больше 4 лет назад

Windows Kerberos Elevation of Privilege Vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v3j-f48c-mxfv

больше 1 года назад

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v3j-7fcp-c89c

больше 4 лет назад

The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4v3j-3fr4-cjrj

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: Fix memory leak in wbrf_record() The tmp buffer is allocated using kcalloc() but is not freed if acpi_evaluate_dsm() fails. This causes a memory leak in the error path. Fix this by explicitly freeing the tmp buffer in the error handling path of acpi_evaluate_dsm().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v3g-g84w-hv7r

больше 4 лет назад

Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-4v3g-f433-532p

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4v3g-89jr-8hcp

больше 2 лет назад

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4v3f-x74x-h275

больше 3 лет назад

A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulation of the argument content/link/shares leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.2.8 is able to address this issue. The name of the patch is 7d5b9a89a27711aad76fd55ab4cc4185b545a1d0. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221479.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4v3f-mvph-6j7c

12 месяцев назад

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_DLG.ASP'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4v3f-ffrw-xcx6

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v3f-8w78-rm7j

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v3f-4r92-c6v3

больше 1 года назад

A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Высокий
github логотип

GHSA-4v3c-22g9-x3jm

больше 4 лет назад

IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v39-rw5r-p8jm

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder allows Stored XSS. This issue affects Team Members for Elementor Page Builder: from n/a through 1.0.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v39-q2jh-wjrw

около 3 лет назад

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4v39-fjgh-5mwf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Scroll Top allows Reflected XSS. This issue affects Scroll Top: from n/a through 1.3.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4v39-87g3-6x6j

больше 4 лет назад

Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.

EPSS: Низкий
github логотип

GHSA-4v38-w5qx-qhmh

больше 4 лет назад

In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v3m-mrm4-6g89

SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-4v3m-fhx4-qp25

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v3j-q36m-pfpg

Windows Kerberos Elevation of Privilege Vulnerability.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4v3j-f48c-mxfv

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4v3j-7fcp-c89c

The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v3j-3fr4-cjrj

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: Fix memory leak in wbrf_record() The tmp buffer is allocated using kcalloc() but is not freed if acpi_evaluate_dsm() fails. This causes a memory leak in the error path. Fix this by explicitly freeing the tmp buffer in the error handling path of acpi_evaluate_dsm().

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4v3g-g84w-hv7r

Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat

CVSS3: 9.1
10%
Средний
больше 4 лет назад
github логотип
GHSA-4v3g-f433-532p

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4v3g-89jr-8hcp

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.

CVSS3: 8.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4v3f-x74x-h275

A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulation of the argument content/link/shares leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.2.8 is able to address this issue. The name of the patch is 7d5b9a89a27711aad76fd55ab4cc4185b545a1d0. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221479.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4v3f-mvph-6j7c

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_DLG.ASP'.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-4v3f-ffrw-xcx6

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-4v3f-8w78-rm7j

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.9.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v3f-4r92-c6v3

A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
77%
Высокий
больше 1 года назад
github логотип
GHSA-4v3c-22g9-x3jm

IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v39-rw5r-p8jm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder allows Stored XSS. This issue affects Team Members for Elementor Page Builder: from n/a through 1.0.4.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v39-q2jh-wjrw

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

CVSS3: 9.8
94%
Критический
около 3 лет назад
github логотип
GHSA-4v39-fjgh-5mwf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Scroll Top allows Reflected XSS. This issue affects Scroll Top: from n/a through 1.3.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v39-87g3-6x6j

Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v38-w5qx-qhmh

In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад

Уязвимостей на страницу