Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-4m8m-2x96-7wq3

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-4m8j-77pp-fvjx

больше 4 лет назад

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not properly sanitize user-supplied input. An attacker who has valid administrator access to an affected device could exploit this vulnerability by supplying certain CLI commands with crafted arguments. A successful exploit could allow the attacker to run arbitrary commands as the root user, which could result in a complete system compromise.

EPSS: Низкий
github логотип

GHSA-4m8h-w9w3-cp2v

больше 3 лет назад

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4m8h-h59m-m34j

больше 4 лет назад

Prototype Pollution in bmoor

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4m8h-6737-hrw6

около 2 месяцев назад

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4m8g-w39f-pp44

9 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Local File Inclusion.This issue affects Panda: from n/a through <= 1.21.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4m8g-qfmv-jcqg

больше 3 лет назад

IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4m8g-g68p-w333

больше 4 лет назад

The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4m8f-h33w-f64v

почти 2 года назад

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl max_beams` .

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4m8f-fmhm-mchq

больше 4 лет назад

Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4m8f-4xr9-qm93

больше 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4m8c-h7fr-gq5c

больше 4 лет назад

Cloud Foundry vulnerable to Cross-Site Request Forgery

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4m8c-6ghq-qm6f

больше 4 лет назад

SQL injection vulnerability in gallery.asp in Xigla Absolute Image Gallery XE allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.

EPSS: Низкий
github логотип

GHSA-4m8c-59q5-hc8f

3 месяца назад

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via `Mappress_Api::rest_api_init()`, where the GET `/wp-json/mapp/v1/maps/{mapid}` endpoint uses `'permission_callback' => '__return_true'` and the write endpoints (POST update, DELETE, PATCH mutate, POST clone, POST empty_trash) only check the generic `edit_posts` capability without confirming that the requester owns the targeted map — a gap that is not compensated at the model layer, as `Mappress_Map::get()`, `save()`, `delete()`, `mutate()`, and `empty_trash()` all operate on any caller-supplied map ID without an ownership check. This makes it possible for unauthenticated attackers to read sensitive map data — including POI titles, addresses, coordinates, and body content — for any map on the site by enumerating map IDs, and for auth...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4m89-pj37-27gm

больше 2 лет назад

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4m89-9vr4-fxx8

почти 3 года назад

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4m88-wxj4-9qj6

5 месяцев назад

Incus Vulnerable to Panic via Snapshot Bounds Check

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4m88-v589-v3w7

больше 1 года назад

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4m88-fhx6-92j5

больше 2 лет назад

Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4m88-4rr7-5rq9

больше 4 лет назад

The Trading 212 FOREX (aka com.avuscapital.trading212) application before 2.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4m8m-2x96-7wq3

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 1 года назад
github логотип
GHSA-4m8j-77pp-fvjx

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not properly sanitize user-supplied input. An attacker who has valid administrator access to an affected device could exploit this vulnerability by supplying certain CLI commands with crafted arguments. A successful exploit could allow the attacker to run arbitrary commands as the root user, which could result in a complete system compromise.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4m8h-w9w3-cp2v

A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4m8h-h59m-m34j

Prototype Pollution in bmoor

CVSS3: 7.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4m8h-6737-hrw6

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4m8g-w39f-pp44

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Local File Inclusion.This issue affects Panda: from n/a through <= 1.21.

CVSS3: 8.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-4m8g-qfmv-jcqg

IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4m8g-g68p-w333

The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4m8f-h33w-f64v

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl max_beams` .

CVSS3: 9.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-4m8f-fmhm-mchq

Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4m8f-4xr9-qm93

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m8c-h7fr-gq5c

Cloud Foundry vulnerable to Cross-Site Request Forgery

CVSS3: 9.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m8c-6ghq-qm6f

SQL injection vulnerability in gallery.asp in Xigla Absolute Image Gallery XE allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m8c-59q5-hc8f

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via `Mappress_Api::rest_api_init()`, where the GET `/wp-json/mapp/v1/maps/{mapid}` endpoint uses `'permission_callback' => '__return_true'` and the write endpoints (POST update, DELETE, PATCH mutate, POST clone, POST empty_trash) only check the generic `edit_posts` capability without confirming that the requester owns the targeted map — a gap that is not compensated at the model layer, as `Mappress_Map::get()`, `save()`, `delete()`, `mutate()`, and `empty_trash()` all operate on any caller-supplied map ID without an ownership check. This makes it possible for unauthenticated attackers to read sensitive map data — including POI titles, addresses, coordinates, and body content — for any map on the site by enumerating map IDs, and for auth...

CVSS3: 5.3
1%
Низкий
3 месяца назад
github логотип
GHSA-4m89-pj37-27gm

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4m89-9vr4-fxx8

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-4m88-wxj4-9qj6

Incus Vulnerable to Panic via Snapshot Bounds Check

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4m88-v589-v3w7

The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m88-fhx6-92j5

Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4m88-4rr7-5rq9

The Trading 212 FOREX (aka com.avuscapital.trading212) application before 2.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу