Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4rvj-5qmg-gmxv

больше 4 лет назад

The Antivirus component in Comodo Internet Security before 3.8.64739.471 allows remote attackers to cause a denial of service (application crash) via a crafted file.

EPSS: Низкий
github логотип

GHSA-4rvh-v5w9-chgg

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.

EPSS: Низкий
github логотип

GHSA-4rvh-837w-4r69

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4rvg-j972-3xw2

3 дня назад

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword "lease_id" whereas the controller methods name the parameter "id" (and the wsme_pecan.wsexpose wrapper delivers it positionally). The lookup returns None, and thus authorization falls back to the requesting user's own project_id/user_id instead of the target lease owner. Any authenticated user who knows a lease ID can therefore modify or delete leases belonging to other users and projects, bypassing the intended ownership check.

EPSS: Низкий
github логотип

GHSA-4rvg-cqxf-frqm

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

EPSS: Низкий
github логотип

GHSA-4rvg-9g3m-4m9p

больше 4 лет назад

SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.

EPSS: Низкий
github логотип

GHSA-4rvg-955w-h68q

около 8 лет назад

Path Traversal in angular-http-server

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rvc-f57j-w38h

2 месяца назад

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4rvc-5hrh-qmwf

больше 4 лет назад

TYPO3 SQL injection vulnerability on the backend

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rv9-8872-9582

больше 4 лет назад

An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rv9-842w-4464

9 месяцев назад

CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.

EPSS: Низкий
github логотип

GHSA-4rv9-5vc4-88cg

больше 5 лет назад

Command injection in node-ps

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rv8-q9c8-6qpq

5 месяцев назад

An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted packet to the MTU length field

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rv8-5cmm-2r22

7 месяцев назад

osctrl has Stored Cross-Site Scripting (XSS) in On-Demand Query List

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rv8-3xqf-8gfm

8 месяцев назад

A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by initiating a denial of service (DoS) attack against the SSH port. A successful exploit could allow the attacker to cause the SSH service to be unresponsive during the period of the DoS attack. All other operations remain stable during the attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rv7-wj6m-6c6r

около 4 лет назад

Denial of Service due to parser crash

EPSS: Низкий
github логотип

GHSA-4rv7-7p6x-h8h6

около 4 лет назад

An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rv6-wmf7-vrhf

больше 4 лет назад

AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.

EPSS: Низкий
github логотип

GHSA-4rv6-f2p6-rhx5

12 дней назад

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4rv5-xm6p-7p7f

почти 3 года назад

Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rvj-5qmg-gmxv

The Antivirus component in Comodo Internet Security before 3.8.64739.471 allows remote attackers to cause a denial of service (application crash) via a crafted file.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rvh-v5w9-chgg

Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4rvh-837w-4r69

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4rvg-j972-3xw2

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword "lease_id" whereas the controller methods name the parameter "id" (and the wsme_pecan.wsexpose wrapper delivers it positionally). The lookup returns None, and thus authorization falls back to the requesting user's own project_id/user_id instead of the target lease owner. Any authenticated user who knows a lease ID can therefore modify or delete leases belonging to other users and projects, bypassing the intended ownership check.

0%
Низкий
3 дня назад
github логотип
GHSA-4rvg-cqxf-frqm

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4rvg-9g3m-4m9p

SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rvg-955w-h68q

Path Traversal in angular-http-server

CVSS3: 6.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-4rvc-f57j-w38h

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
0%
Низкий
2 месяца назад
github логотип
GHSA-4rvc-5hrh-qmwf

TYPO3 SQL injection vulnerability on the backend

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv9-8872-9582

An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv9-842w-4464

CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.

0%
Низкий
9 месяцев назад
github логотип
GHSA-4rv9-5vc4-88cg

Command injection in node-ps

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-4rv8-q9c8-6qpq

An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted packet to the MTU length field

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4rv8-5cmm-2r22

osctrl has Stored Cross-Site Scripting (XSS) in On-Demand Query List

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-4rv8-3xqf-8gfm

A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by initiating a denial of service (DoS) attack against the SSH port. A successful exploit could allow the attacker to cause the SSH service to be unresponsive during the period of the DoS attack. All other operations remain stable during the attack.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-4rv7-wj6m-6c6r

Denial of Service due to parser crash

около 4 лет назад
github логотип
GHSA-4rv7-7p6x-h8h6

An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4rv6-wmf7-vrhf

AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv6-f2p6-rhx5

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)

CVSS3: 3.5
0%
Низкий
12 дней назад
github логотип
GHSA-4rv5-xm6p-7p7f

Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons.

CVSS3: 9.8
1%
Низкий
почти 3 года назад

Уязвимостей на страницу