Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-4jmq-66c3-gmj4

11 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code Inclusion.This issue affects WP Last Modified Info: from n/a through <= 1.9.2.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4jmq-3w5w-h4fc

больше 4 лет назад

In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173421110

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jmq-3rrv-cmcc

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: from n/a through 2.6.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4jmp-x7mh-rgmr

9 месяцев назад

Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration

EPSS: Низкий
github логотип

GHSA-4jmm-vm3q-jf46

10 месяцев назад

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4jmm-c6jw-g796

около 2 лет назад

Filestash configured to skip TLS certificate verification when using the FTPS protocol

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4jmj-xq3w-8f72

больше 4 лет назад

Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vulnerability than CVE-2006-5854. NOTE: this issue exists because of an incomplete fix for CVE-2007-6701.

EPSS: Средний
github логотип

GHSA-4jmj-j53j-vqfv

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitrary web script or HTML via (1) the Page parameter in a List action to modules/ereignis.php, (2) the Kontext parameter in a Search action to modules/kategorie.php, (3) the image parameter to modules/image.php, or (4) the ID parameter in a Detail action to modules/sitzung.php.

EPSS: Низкий
github логотип

GHSA-4jmj-7wjp-8959

больше 4 лет назад

An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.

EPSS: Низкий
github логотип

GHSA-4jmj-6pw4-g738

11 месяцев назад

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all versions up to, and including, 3.5.1. This makes it possible for unauthenticated attackers to disconnect the site from its API plan.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4jmh-86hw-fcxr

9 месяцев назад

Missing Authorization vulnerability in Essential Plugin Slider a SlidersPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider a SlidersPack: from n/a before 2.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4jmg-gg6g-x7j5

больше 4 лет назад

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4jmf-j564-cpmx

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix the error "trying to register non-static key in rxe_cleanup_task" In the function rxe_create_qp(), rxe_qp_from_init() is called to initialize qp, internally things like rxe_init_task are not setup until rxe_qp_init_req(). If an error occurred before this point then the unwind will call rxe_cleanup() and eventually to rxe_qp_do_cleanup()/rxe_cleanup_task() which will oops when trying to access the uninitialized spinlock. If rxe_init_task is not executed, rxe_cleanup_task will not be called.

EPSS: Низкий
github логотип

GHSA-4jmf-j4w5-68gx

больше 1 года назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4jmf-47xq-xvf3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.

EPSS: Низкий
github логотип

GHSA-4jmf-2ggr-ph9x

больше 2 лет назад

Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4jmc-cgpx-wfmf

больше 1 года назад

A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4jm9-v433-wx3f

больше 4 лет назад

WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (dsdiff.c:282). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/4c0faba32fddbd0745cbfaf1e1aeb3da5d35b9fc.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4jm9-m9m4-wcj4

больше 4 лет назад

HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4jm9-g5r9-6cj9

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jmq-66c3-gmj4

Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code Inclusion.This issue affects WP Last Modified Info: from n/a through <= 1.9.2.

CVSS3: 7.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-4jmq-3w5w-h4fc

In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173421110

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jmq-3rrv-cmcc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: from n/a through 2.6.5.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4jmp-x7mh-rgmr

Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration

9 месяцев назад
github логотип
GHSA-4jmm-vm3q-jf46

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-4jmm-c6jw-g796

Filestash configured to skip TLS certificate verification when using the FTPS protocol

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-4jmj-xq3w-8f72

Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vulnerability than CVE-2006-5854. NOTE: this issue exists because of an incomplete fix for CVE-2007-6701.

23%
Средний
больше 4 лет назад
github логотип
GHSA-4jmj-j53j-vqfv

Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitrary web script or HTML via (1) the Page parameter in a List action to modules/ereignis.php, (2) the Kontext parameter in a Search action to modules/kategorie.php, (3) the image parameter to modules/image.php, or (4) the ID parameter in a Detail action to modules/sitzung.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jmj-7wjp-8959

An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jmj-6pw4-g738

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all versions up to, and including, 3.5.1. This makes it possible for unauthenticated attackers to disconnect the site from its API plan.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-4jmh-86hw-fcxr

Missing Authorization vulnerability in Essential Plugin Slider a SlidersPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider a SlidersPack: from n/a before 2.3.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-4jmg-gg6g-x7j5

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

CVSS3: 5.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jmf-j564-cpmx

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix the error "trying to register non-static key in rxe_cleanup_task" In the function rxe_create_qp(), rxe_qp_from_init() is called to initialize qp, internally things like rxe_init_task are not setup until rxe_qp_init_req(). If an error occurred before this point then the unwind will call rxe_cleanup() and eventually to rxe_qp_do_cleanup()/rxe_cleanup_task() which will oops when trying to access the uninitialized spinlock. If rxe_init_task is not executed, rxe_cleanup_task will not be called.

0%
Низкий
9 месяцев назад
github логотип
GHSA-4jmf-j4w5-68gx

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4jmf-47xq-xvf3

Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jmf-2ggr-ph9x

Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4jmc-cgpx-wfmf

A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4jm9-v433-wx3f

WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (dsdiff.c:282). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/4c0faba32fddbd0745cbfaf1e1aeb3da5d35b9fc.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm9-m9m4-wcj4

HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm9-g5r9-6cj9

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.

CVSS3: 7.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу