Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4qv6-37xq-mgq2

почти 3 года назад

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4qv6-2v4w-q82f

8 месяцев назад

Missing Authorization vulnerability in Jahid Hasan Admin login URL Change admin-login-url-change allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin login URL Change: from n/a through <= 1.1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4qv5-2qmr-5xhv

4 месяца назад

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4qv4-vh73-q92w

больше 2 лет назад

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qv4-f447-c9m2

16 дней назад

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qv3-q5hv-62xv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.

EPSS: Низкий
github логотип

GHSA-4qv3-968r-mh4q

около 4 лет назад

Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4qv2-qrrg-4f85

больше 4 лет назад

Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.

EPSS: Низкий
github логотип

GHSA-4qv2-grq4-x33q

больше 4 лет назад

Identix BioLogon 2.03 and earlier does not lock secondary displays on a multi-monitor system running Windows 98 or ME, which allows an attacker with physical access to the system to bypass authentication through a secondary display.

EPSS: Низкий
github логотип

GHSA-4qv2-3fq8-gvx4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

EPSS: Низкий
github логотип

GHSA-4qrx-q52x-7hwp

около 1 года назад

Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4qrw-gq38-58jq

больше 4 лет назад

The Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not set the secure flag for the ASP.NET session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-4qrv-q9xg-qj66

5 месяцев назад

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4qrv-gcg3-8h65

9 месяцев назад

Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has been patched and automatically deployed to all Apollo-managed Gotham Instances

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4qrv-c52g-rjr6

больше 3 лет назад

A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231013 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4qrv-8qq4-m334

около 2 лет назад

Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterBandList::unpack. This issue affects libfluid: 0.1.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4qrr-m2j4-wr3h

2 месяца назад

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qrq-qhhp-x9r2

больше 4 лет назад

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

EPSS: Низкий
github логотип

GHSA-4qrq-q3mh-x585

около 1 месяца назад

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-4qrq-mvr6-2gj3

больше 4 лет назад

Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a negative integer value.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qv6-37xq-mgq2

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-4qv6-2v4w-q82f

Missing Authorization vulnerability in Jahid Hasan Admin login URL Change admin-login-url-change allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin login URL Change: from n/a through <= 1.1.5.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-4qv5-2qmr-5xhv

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-4qv4-vh73-q92w

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4qv4-f447-c9m2

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.

CVSS3: 7.5
0%
Низкий
16 дней назад
github логотип
GHSA-4qv3-q5hv-62xv

Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qv3-968r-mh4q

Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-4qv2-qrrg-4f85

Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qv2-grq4-x33q

Identix BioLogon 2.03 and earlier does not lock secondary displays on a multi-monitor system running Windows 98 or ME, which allows an attacker with physical access to the system to bypass authentication through a secondary display.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4qv2-3fq8-gvx4

Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrx-q52x-7hwp

Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-4qrw-gq38-58jq

The Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not set the secure flag for the ASP.NET session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrv-q9xg-qj66

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-4qrv-gcg3-8h65

Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has been patched and automatically deployed to all Apollo-managed Gotham Instances

CVSS3: 9.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-4qrv-c52g-rjr6

A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231013 was assigned to this vulnerability.

CVSS3: 3.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4qrv-8qq4-m334

Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterBandList::unpack. This issue affects libfluid: 0.1.0.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-4qrr-m2j4-wr3h

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
2 месяца назад
github логотип
GHSA-4qrq-qhhp-x9r2

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrq-q3mh-x585

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4qrq-mvr6-2gj3

Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a negative integer value.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу