Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r4r-223f-8hjj

больше 4 лет назад

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r4q-86p7-2mpq

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the Current question field in a vote action to admin.php.

EPSS: Низкий
github логотип

GHSA-4r4q-4mqv-pv27

8 месяцев назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L).

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-4r4q-3gg9-w59h

больше 4 лет назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4r4m-v89p-5c69

около 2 лет назад

A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273523. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4r4m-qw57-chr8

больше 1 года назад

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-4r4m-hjwj-43p8

больше 7 лет назад

Insecure Defaults Allow MITM Over TLS in engine.io-client

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4r4m-3xf7-fv59

12 дней назад

Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4r4h-wxqr-24rc

15 дней назад

The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r4h-w86r-vj96

больше 4 лет назад

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.

EPSS: Средний
github логотип

GHSA-4r4g-q2r2-8qqw

больше 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rmformat.

EPSS: Низкий
github логотип

GHSA-4r4g-jmhw-hh6h

больше 4 лет назад

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

EPSS: Низкий
github логотип

GHSA-4r4f-w2v4-7wwr

больше 4 лет назад

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to bypass intended file-upload restrictions via a modified extension.

EPSS: Низкий
github логотип

GHSA-4r4f-jrvw-h727

около 4 лет назад

Feehi CMS host header injection vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r4f-gg25-rmg5

2 месяца назад

plone.app.textfield: Stored XSS by spoofing mime type

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4r4c-x4gq-3pcw

почти 2 года назад

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r4c-66gf-g9g5

больше 2 лет назад

rockhopper Buffer Overflow vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4r48-rxwv-p6qh

больше 1 года назад

A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4r48-pfgj-8jrr

3 месяца назад

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-4r48-c38p-vgcv

больше 2 лет назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r4r-223f-8hjj

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

CVSS3: 7.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4q-86p7-2mpq

Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the Current question field in a vote action to admin.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4q-4mqv-pv27

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L).

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-4r4q-3gg9-w59h

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4m-v89p-5c69

A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273523. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-4r4m-qw57-chr8

Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

CVSS3: 5.3
58%
Средний
больше 1 года назад
github логотип
GHSA-4r4m-hjwj-43p8

Insecure Defaults Allow MITM Over TLS in engine.io-client

CVSS3: 5.9
1%
Низкий
больше 7 лет назад
github логотип
GHSA-4r4m-3xf7-fv59

Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)

CVSS3: 4.8
0%
Низкий
12 дней назад
github логотип
GHSA-4r4h-wxqr-24rc

The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.

CVSS3: 5.4
0%
Низкий
15 дней назад
github логотип
GHSA-4r4h-w86r-vj96

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.

17%
Средний
больше 4 лет назад
github логотип
GHSA-4r4g-q2r2-8qqw

Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rmformat.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4g-jmhw-hh6h

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4f-w2v4-7wwr

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to bypass intended file-upload restrictions via a modified extension.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4f-jrvw-h727

Feehi CMS host header injection vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-4r4f-gg25-rmg5

plone.app.textfield: Stored XSS by spoofing mime type

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4r4c-x4gq-3pcw

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4r4c-66gf-g9g5

rockhopper Buffer Overflow vulnerability

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4r48-rxwv-p6qh

A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r48-pfgj-8jrr

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

CVSS3: 9.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4r48-c38p-vgcv

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 2 лет назад

Уязвимостей на страницу