Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r7x-c2f7-5gfh

больше 4 лет назад

The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r7w-x5w5-gxg3

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-4r7w-q3jg-ff43

около 1 года назад

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

EPSS: Низкий
github логотип

GHSA-4r7w-gv7f-q74g

около 4 лет назад

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r7w-cvqp-58f8

больше 4 лет назад

Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4r7w-72j2-7p27

больше 1 года назад

The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. By executing the specific ABAP method within the ABAP system, an unauthorized attacker could call each transaction and view the inbound delivery details. This vulnerability has a low impact on the confidentiality with no effect on the integrity and the availability of the application.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-4r7w-4939-7h88

почти 3 года назад

In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r7w-2gx2-27xp

больше 4 лет назад

NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r7v-whpg-8rx3

почти 2 года назад

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-4r7v-vq9j-hv62

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker could exploit this vulnerability by modifying a log file with malicious code and getting a user to view the modified log file. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.

EPSS: Низкий
github логотип

GHSA-4r7v-h9fw-3r37

больше 4 лет назад

Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Object Server (AOS) instance, aka "Query Filter DoS Vulnerability."

EPSS: Средний
github логотип

GHSA-4r7v-8p9v-gphx

больше 4 лет назад

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

EPSS: Низкий
github логотип

GHSA-4r7r-xfq3-2r3v

больше 1 года назад

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4r7r-w926-gm5j

4 месяца назад

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary external scripts by setting the `shop_name` to an attacker-controlled URL (e.g., `https://attacker.com`), which causes the plugin to enqueue external JavaScript and CSS from the attacker-controlled domain via `wp_register_script()` and `wp_register_style()`. The injected scripts execute on every frontend page containing any Passeum Ticketing shortcode, affecting all site visitors. Please note that this does not affect single-site installations as administrators already have the `unfilt...

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4r7r-87cf-rc4r

больше 4 лет назад

In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r7q-rwrj-9wg2

около 2 лет назад

Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4r7q-g5mr-63x8

больше 1 года назад

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r7q-86hg-h98x

6 месяцев назад

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-4r7p-6629-62mj

больше 2 лет назад

PDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19487.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r7p-4rfr-6jwr

около 3 лет назад

A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r7x-c2f7-5gfh

The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7w-x5w5-gxg3

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-4r7w-q3jg-ff43

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

0%
Низкий
около 1 года назад
github логотип
GHSA-4r7w-gv7f-q74g

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-4r7w-cvqp-58f8

Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7w-72j2-7p27

The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. By executing the specific ABAP method within the ABAP system, an unauthorized attacker could call each transaction and view the inbound delivery details. This vulnerability has a low impact on the confidentiality with no effect on the integrity and the availability of the application.

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r7w-4939-7h88

In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4r7w-2gx2-27xp

NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7v-whpg-8rx3

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

CVSS3: 10
84%
Высокий
почти 2 года назад
github логотип
GHSA-4r7v-vq9j-hv62

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker could exploit this vulnerability by modifying a log file with malicious code and getting a user to view the modified log file. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7v-h9fw-3r37

Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Object Server (AOS) instance, aka "Query Filter DoS Vulnerability."

10%
Средний
больше 4 лет назад
github логотип
GHSA-4r7v-8p9v-gphx

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7r-xfq3-2r3v

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r7r-w926-gm5j

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary external scripts by setting the `shop_name` to an attacker-controlled URL (e.g., `https://attacker.com`), which causes the plugin to enqueue external JavaScript and CSS from the attacker-controlled domain via `wp_register_script()` and `wp_register_style()`. The injected scripts execute on every frontend page containing any Passeum Ticketing shortcode, affecting all site visitors. Please note that this does not affect single-site installations as administrators already have the `unfilt...

CVSS3: 4.4
0%
Низкий
4 месяца назад
github логотип
GHSA-4r7r-87cf-rc4r

In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.

CVSS3: 5.5
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7q-rwrj-9wg2

Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4r7q-g5mr-63x8

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r7q-86hg-h98x

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device.

CVSS3: 10
1%
Низкий
6 месяцев назад
github логотип
GHSA-4r7p-6629-62mj

PDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19487.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4r7p-4rfr-6jwr

A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 5.4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу