Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r37-9m26-2c4m

2 месяца назад

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4r37-98w6-79rh

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-4r36-x7px-386g

больше 2 лет назад

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4r36-vxg8-p9vx

больше 3 лет назад

Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r36-f255-mccm

больше 2 лет назад

MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4r36-c55m-fp5v

больше 4 лет назад

The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to cause a denial of service (hang or crash) via invalid field length values in a malformed (1) document or (2) request.

EPSS: Низкий
github логотип

GHSA-4r33-j73q-cw77

около 2 месяцев назад

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r33-2453-cxc5

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249509 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4r32-r85g-4jqr

больше 4 лет назад

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4r32-8f4q-m264

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4r32-4xgr-6w96

больше 4 лет назад

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r2x-xpjr-7cvv

8 месяцев назад

vLLM has RCE In Video Processing

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r2x-95jf-w8hr

больше 4 лет назад

Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.

EPSS: Низкий
github логотип

GHSA-4r2x-685x-rf8p

больше 4 лет назад

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

EPSS: Низкий
github логотип

GHSA-4r2w-w73w-36jm

больше 4 лет назад

eyeD3 is vulnerable to arbitrary file modification via symlink attack

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-4r2w-rq9g-2cgf

больше 4 лет назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects GS728TPPv2 before 6.0.0.48, GS728TPv2 before 6.0.0.48, GS750E before 1.0.1.4, GS752TPP before 6.0.0.48, and GS752TPv2 before 6.0.0.48.

EPSS: Низкий
github логотип

GHSA-4r2w-j4p7-rw4p

больше 4 лет назад

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r2w-8q67-97q8

больше 4 лет назад

Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4r2w-35wr-w5ch

больше 4 лет назад

Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh. NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises.

EPSS: Низкий
github логотип

GHSA-4r2r-hjrw-mpq6

почти 2 года назад

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r37-9m26-2c4m

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.

CVSS3: 6.4
0%
Низкий
2 месяца назад
github логотип
GHSA-4r37-98w6-79rh

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-4r36-x7px-386g

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4r36-vxg8-p9vx

Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4r36-f255-mccm

MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4r36-c55m-fp5v

The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to cause a denial of service (hang or crash) via invalid field length values in a malformed (1) document or (2) request.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r33-j73q-cw77

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4r33-2453-cxc5

A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249509 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4r32-r85g-4jqr

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
11%
Средний
больше 4 лет назад
github логотип
GHSA-4r32-8f4q-m264

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4r32-4xgr-6w96

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2x-xpjr-7cvv

vLLM has RCE In Video Processing

CVSS3: 9.8
4%
Низкий
8 месяцев назад
github логотип
GHSA-4r2x-95jf-w8hr

Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2x-685x-rf8p

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2w-w73w-36jm

eyeD3 is vulnerable to arbitrary file modification via symlink attack

CVSS3: 4.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2w-rq9g-2cgf

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects GS728TPPv2 before 6.0.0.48, GS728TPv2 before 6.0.0.48, GS750E before 1.0.1.4, GS752TPP before 6.0.0.48, and GS752TPv2 before 6.0.0.48.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2w-j4p7-rw4p

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Networks 128 Technology Session Smart Router versions prior to 4.5.11, and all versions of 5.0 up to and including 5.0.1.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2w-8q67-97q8

Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2w-35wr-w5ch

Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh. NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2r-hjrw-mpq6

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

CVSS3: 8.5
2%
Низкий
почти 2 года назад

Уязвимостей на страницу