Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4qf7-45mf-9g63

9 дней назад

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4qf6-vpj8-p4r6

больше 4 лет назад

Cross site scripting in SSCMS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4qf6-pw5g-fjgf

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is the function formQosManageDouble_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be launched remotely. The identifier of this vulnerability is VDB-262136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qf5-rc23-77x7

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Head Meta Data head-meta-data allows Stored XSS.This issue affects Head Meta Data: from n/a through <= 20250327.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4qf5-r4mp-pqp5

больше 4 лет назад

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-4qf5-9r87-5gfh

7 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-4qf5-7xc2-wqpg

больше 4 лет назад

DNN Path Traversal via Zip Slip

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qf5-7jr3-q9pq

8 месяцев назад

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qf4-g53x-x6vr

больше 4 лет назад

Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.

EPSS: Низкий
github логотип

GHSA-4qf4-6x5x-m29p

11 дней назад

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages. For example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4qf3-4832-7qmj

больше 4 лет назад

Vulnerability in the Oracle Financial Services Balance Sheet Planning component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Balance Sheet Planning. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Balance Sheet Planning accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Balance Sheet Planning accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4qf2-r366-mwj6

больше 4 лет назад

admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.

EPSS: Низкий
github логотип

GHSA-4qf2-p32m-7hmf

4 месяца назад

AMF Vulnerable to Improper Resource Shutdown or Release

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4qf2-fgm5-c6v8

25 дней назад

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4qf2-cmvc-cch6

11 месяцев назад

HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4qf2-7vj7-p7mr

больше 4 лет назад

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

EPSS: Низкий
github логотип

GHSA-4qf2-7m52-qfp8

больше 4 лет назад

An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The overflowed data leads to segmentation fault and ultimately a denial-of-service condition, causing the device to reboot. The impact of this vulnerability is that an unauthenticated attacker could leverage this flaw to cause the target device to become unresponsive. An attacker could automate this attack to achieve persistent DoS, effectively rendering the target controller useless.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qcx-xfr8-6hf6

15 дней назад

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4qcx-qmp2-qpq6

больше 4 лет назад

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-4qcx-jx49-6qrh

больше 1 года назад

Aim path traversal in LockManager.release_locks

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qf7-45mf-9g63

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

CVSS3: 9.1
1%
Низкий
9 дней назад
github логотип
GHSA-4qf6-vpj8-p4r6

Cross site scripting in SSCMS

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qf6-pw5g-fjgf

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is the function formQosManageDouble_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be launched remotely. The identifier of this vulnerability is VDB-262136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4qf5-rc23-77x7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Head Meta Data head-meta-data allows Stored XSS.This issue affects Head Meta Data: from n/a through <= 20250327.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-4qf5-r4mp-pqp5

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.

CVSS3: 8.1
78%
Высокий
больше 4 лет назад
github логотип
GHSA-4qf5-9r87-5gfh

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

7 месяцев назад
github логотип
GHSA-4qf5-7xc2-wqpg

DNN Path Traversal via Zip Slip

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qf5-7jr3-q9pq

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4qf4-g53x-x6vr

Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qf4-6x5x-m29p

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages. For example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.

CVSS3: 6.1
0%
Низкий
11 дней назад
github логотип
GHSA-4qf3-4832-7qmj

Vulnerability in the Oracle Financial Services Balance Sheet Planning component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Balance Sheet Planning. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Balance Sheet Planning accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Balance Sheet Planning accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qf2-r366-mwj6

admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4qf2-p32m-7hmf

AMF Vulnerable to Improper Resource Shutdown or Release

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4qf2-fgm5-c6v8

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
0%
Низкий
25 дней назад
github логотип
GHSA-4qf2-cmvc-cch6

HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc.

CVSS3: 3.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-4qf2-7vj7-p7mr

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4qf2-7m52-qfp8

An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The overflowed data leads to segmentation fault and ultimately a denial-of-service condition, causing the device to reboot. The impact of this vulnerability is that an unauthenticated attacker could leverage this flaw to cause the target device to become unresponsive. An attacker could automate this attack to achieve persistent DoS, effectively rendering the target controller useless.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qcx-xfr8-6hf6

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.

CVSS3: 5.3
0%
Низкий
15 дней назад
github логотип
GHSA-4qcx-qmp2-qpq6

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4qcx-jx49-6qrh

Aim path traversal in LockManager.release_locks

CVSS3: 9.1
1%
Низкий
больше 1 года назад

Уязвимостей на страницу