Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4qrq-ggqj-r6p9

больше 4 лет назад

read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4qrp-rfxq-585m

больше 4 лет назад

An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4qrp-r28g-j2vf

почти 2 года назад

A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be dropped, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of TCP/IP network traffic. An attacker could exploit this vulnerability by sending a large amount of TCP/IP network traffic through the affected device. A successful exploit could allow the attacker to cause the Cisco FTD device to drop network traffic, resulting in a DoS condition. The affected device must be rebooted to resolve the DoS condition.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4qrp-9fm8-gvg2

1 день назад

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

EPSS: Низкий
github логотип

GHSA-4qrp-27r3-66fj

больше 4 лет назад

Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4qrm-jp7g-x2p5

18 дней назад

Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4qrm-9h4r-v2fx

около 2 лет назад

Tina search token leak via lock file in TinaCMS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qrj-99r6-jfrh

больше 4 лет назад

Missing hostname validation in Email Extension Plugin

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4qrj-7fxc-vhj8

почти 2 года назад

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qrh-29x8-rv94

больше 4 лет назад

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

EPSS: Средний
github логотип

GHSA-4qrg-v6p3-7pjf

больше 4 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.

EPSS: Низкий
github логотип

GHSA-4qrg-gphx-m2ch

10 месяцев назад

Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4qrg-84mv-738w

около 2 месяцев назад

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4qrf-rvw4-3q4h

больше 3 лет назад

Microsoft Excel Spoofing Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4qrf-c84f-cqrh

больше 4 лет назад

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

EPSS: Низкий
github логотип

GHSA-4qrf-946m-6735

около 1 года назад

A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4qrf-4qfq-jhwq

26 дней назад

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4qrc-7v22-7qwh

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rameez Iqbal Real Estate Manager allows DOM-Based XSS. This issue affects Real Estate Manager: from n/a through 7.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qr9-wqj5-m42w

больше 1 года назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal allows Retrieve Embedded Sensitive Data. This issue affects QuickCal: from n/a through 1.0.15.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4qr9-h3h9-fwcc

7 месяцев назад

The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qrq-ggqj-r6p9

read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrp-rfxq-585m

An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrp-r28g-j2vf

A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be dropped, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of TCP/IP network traffic. An attacker could exploit this vulnerability by sending a large amount of TCP/IP network traffic through the affected device. A successful exploit could allow the attacker to cause the Cisco FTD device to drop network traffic, resulting in a DoS condition. The affected device must be rebooted to resolve the DoS condition.

CVSS3: 8.6
1%
Низкий
почти 2 года назад
github логотип
GHSA-4qrp-9fm8-gvg2

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

1 день назад
github логотип
GHSA-4qrp-27r3-66fj

Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrm-jp7g-x2p5

Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.

CVSS3: 4.3
0%
Низкий
18 дней назад
github логотип
GHSA-4qrm-9h4r-v2fx

Tina search token leak via lock file in TinaCMS

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4qrj-99r6-jfrh

Missing hostname validation in Email Extension Plugin

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrj-7fxc-vhj8

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4qrh-29x8-rv94

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

23%
Средний
больше 4 лет назад
github логотип
GHSA-4qrg-v6p3-7pjf

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrg-gphx-m2ch

Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-4qrg-84mv-738w

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4qrf-rvw4-3q4h

Microsoft Excel Spoofing Vulnerability

CVSS3: 7.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4qrf-c84f-cqrh

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4qrf-946m-6735

A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4qrf-4qfq-jhwq

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
1%
Низкий
26 дней назад
github логотип
GHSA-4qrc-7v22-7qwh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rameez Iqbal Real Estate Manager allows DOM-Based XSS. This issue affects Real Estate Manager: from n/a through 7.3.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-4qr9-wqj5-m42w

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal allows Retrieve Embedded Sensitive Data. This issue affects QuickCal: from n/a through 1.0.15.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4qr9-h3h9-fwcc

The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
7 месяцев назад

Уязвимостей на страницу