Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4rch-2fh8-94vw

больше 2 лет назад

MySQL2 for Node Arbitrary Code Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rcg-xhqc-237v

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rcg-2r46-4hcc

больше 4 лет назад

The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rcf-j8r8-4576

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0452 and CVE-2014-0458.

EPSS: Низкий
github логотип

GHSA-4rcf-g8pc-g743

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104222, 104910, 105071, and 105175.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rcf-f8m4-g24g

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.

EPSS: Низкий
github логотип

GHSA-4rcf-8m6c-xh78

около 3 лет назад

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rcc-r44q-jpcm

больше 4 лет назад

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.

EPSS: Низкий
github логотип

GHSA-4rcc-p7p9-8wqq

больше 4 лет назад

SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

EPSS: Низкий
github логотип

GHSA-4rcc-hgj8-2rw6

около 2 лет назад

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4rcc-7pg7-f57f

больше 1 года назад

Security Update for the OPC UA .NET Standard Stack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rcc-5h4g-2qgv

12 дней назад

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rcc-4cf7-q84c

12 месяцев назад

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rcc-2rmf-f973

больше 4 лет назад

The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local users to access restricted memory via a negative ppos argument, which bypasses a check that assumes that ppos is positive and causes an out-of-bounds read in the readb function.

EPSS: Низкий
github логотип

GHSA-4rc8-fprc-92jm

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/admin_index.php; (3) the karma_username parameter to module.php in the karma module; (4) q_1_low, (5) q_1_high, (6) q_2_low, or (7) q_2_high parameter in a configure action to module.php in the captcha module; or (8) the edit parameter to module.php in the admin_language module.

EPSS: Низкий
github логотип

GHSA-4rc8-3mc7-r96j

почти 2 года назад

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rc8-26x9-r9p2

22 дня назад

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rc7-r4rw-qrqp

больше 4 лет назад

Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/yopy_sync.php and (2) system-logger/print_logs.php.

EPSS: Низкий
github логотип

GHSA-4rc6-v4jg-27v9

больше 4 лет назад

A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/RgTime. The manipulation of the argument TimeServer1/TimeServer2/TimeServer3 with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4rc5-wfh7-f374

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashraful Sarkar Naiem License For Envato allows PHP Local File Inclusion. This issue affects License For Envato: from n/a through 1.0.0.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rch-2fh8-94vw

MySQL2 for Node Arbitrary Code Injection

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rcg-xhqc-237v

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-4rcg-2r46-4hcc

The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.

CVSS3: 5.3
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4rcf-j8r8-4576

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0452 and CVE-2014-0458.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4rcf-g8pc-g743

Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104222, 104910, 105071, and 105175.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rcf-f8m4-g24g

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4rcf-8m6c-xh78

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

CVSS3: 6.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-4rcc-r44q-jpcm

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4rcc-p7p9-8wqq

SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rcc-hgj8-2rw6

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

CVSS3: 9.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-4rcc-7pg7-f57f

Security Update for the OPC UA .NET Standard Stack

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4rcc-5h4g-2qgv

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
12 дней назад
github логотип
GHSA-4rcc-4cf7-q84c

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-4rcc-2rmf-f973

The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local users to access restricted memory via a negative ppos argument, which bypasses a check that assumes that ppos is positive and causes an out-of-bounds read in the readb function.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-4rc8-fprc-92jm

Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/admin_index.php; (3) the karma_username parameter to module.php in the karma module; (4) q_1_low, (5) q_1_high, (6) q_2_low, or (7) q_2_high parameter in a configure action to module.php in the captcha module; or (8) the edit parameter to module.php in the admin_language module.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4rc8-3mc7-r96j

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-4rc8-26x9-r9p2

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.

CVSS3: 7.5
0%
Низкий
22 дня назад
github логотип
GHSA-4rc7-r4rw-qrqp

Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/yopy_sync.php and (2) system-logger/print_logs.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4rc6-v4jg-27v9

A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/RgTime. The manipulation of the argument TimeServer1/TimeServer2/TimeServer3 with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rc5-wfh7-f374

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashraful Sarkar Naiem License For Envato allows PHP Local File Inclusion. This issue affects License For Envato: from n/a through 1.0.0.

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу