Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4rf9-3v3w-xg8c

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in lucksy Typekit plugin for WordPress allows Cross Site Request Forgery. This issue affects Typekit plugin for WordPress: from n/a through 1.2.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rf8-mj4r-9mgw

около 1 месяца назад

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rf8-j9gh-8qph

больше 4 лет назад

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4rf7-rfqf-gw8j

7 месяцев назад

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4rf7-qgf8-847c

7 месяцев назад

Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or reset resulting in denial of service.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-4rf7-f6mv-mgf9

около 3 лет назад

Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rf6-vjg6-7466

почти 2 года назад

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-4rf6-qx84-q9fv

4 дня назад

Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rf6-pvq6-2g27

больше 3 лет назад

Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rf6-m9g8-2fqj

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rf6-fwgf-ff5m

больше 4 лет назад

An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.

EPSS: Низкий
github логотип

GHSA-4rf6-4w52-c8p7

больше 4 лет назад

The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4rf5-qf66-5m85

больше 4 лет назад

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages, as demonstrated by an interpretation conflict between userinfo and scheme in an http://javascript:payload@example.com URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rf4-f8jg-vf5j

около 3 лет назад

User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4rf4-cv9g-449x

почти 5 лет назад

Microsoft Message Queuing Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43236.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rf3-jwvw-gw8p

2 месяца назад

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rf2-x7fh-vgpg

около 2 лет назад

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rf2-jfxm-vxmr

3 месяца назад

A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rf2-ggr7-2r38

около 1 месяца назад

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rf2-7phj-4vwq

почти 2 года назад

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rf9-3v3w-xg8c

Cross-Site Request Forgery (CSRF) vulnerability in lucksy Typekit plugin for WordPress allows Cross Site Request Forgery. This issue affects Typekit plugin for WordPress: from n/a through 1.2.3.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4rf8-mj4r-9mgw

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4rf8-j9gh-8qph

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

CVSS3: 7.5
37%
Средний
больше 4 лет назад
github логотип
GHSA-4rf7-rfqf-gw8j

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.

CVSS3: 3.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-4rf7-qgf8-847c

Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or reset resulting in denial of service.

CVSS3: 6
0%
Низкий
7 месяцев назад
github логотип
GHSA-4rf7-f6mv-mgf9

Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4rf6-vjg6-7466

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.

CVSS3: 9.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-4rf6-qx84-q9fv

Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)

CVSS3: 7.5
0%
Низкий
4 дня назад
github логотип
GHSA-4rf6-pvq6-2g27

Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4rf6-m9g8-2fqj

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4rf6-fwgf-ff5m

An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rf6-4w52-c8p7

The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rf5-qf66-5m85

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages, as demonstrated by an interpretation conflict between userinfo and scheme in an http://javascript:payload@example.com URL.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rf4-f8jg-vf5j

User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-4rf4-cv9g-449x

Microsoft Message Queuing Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43236.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
github логотип
GHSA-4rf3-jwvw-gw8p

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4rf2-x7fh-vgpg

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4rf2-jfxm-vxmr

A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4rf2-ggr7-2r38

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4rf2-7phj-4vwq

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

CVSS3: 7.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу