Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-4jh2-3c85-q67h

больше 4 лет назад

Improper Privilege Management in apache-airflow

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4jgx-vqf2-p9g9

2 месяца назад

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jgx-rj97-j9f4

больше 4 лет назад

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of shared links by leveraging meeting-attendance privileges.

EPSS: Низкий
github логотип

GHSA-4jgx-p7cx-g39r

2 дня назад

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jgx-c8px-mmgc

больше 4 лет назад

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The keys is in the com/mobileiron/common/utils/C4928m.java file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jgx-c2mv-3qmc

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4jgw-6462-7fw2

больше 4 лет назад

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

EPSS: Низкий
github логотип

GHSA-4jgv-vww9-6wqw

больше 1 года назад

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4jgv-gpc4-9rmg

больше 4 лет назад

Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.

EPSS: Средний
github логотип

GHSA-4jgr-pg2m-m988

3 месяца назад

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

EPSS: Низкий
github логотип

GHSA-4jgr-9qc8-cc83

около 2 месяцев назад

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jgr-5qw5-7m4m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4jgr-2587-qr74

больше 4 лет назад

The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

EPSS: Низкий
github логотип

GHSA-4jgq-px27-8954

больше 3 лет назад

A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4jgq-fhgh-wpfp

больше 4 лет назад

The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.

EPSS: Низкий
github логотип

GHSA-4jgq-8v4m-g4qh

8 месяцев назад

The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_return_url function in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to mark any WooCommerce order as processing/completed.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4jgq-8mwg-w9q9

3 месяца назад

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements of the PDF rendering and editing libraries used, this is one of the few pages in our backend that do not have a strong Content-Security-Policy that would render this capability useless for most scenarios.

EPSS: Низкий
github логотип

GHSA-4jgp-jccm-6ppx

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: x86/fred: Correct speculative safety in fred_extint() array_index_nospec() is no use if the result gets spilled to the stack, as it makes the believed safe-under-speculation value subject to memory predictions. For all practical purposes, this means array_index_nospec() must be used in the expression that accesses the array. As the code currently stands, it's the wrong side of irqentry_enter(), and 'index' is put into %ebp across the function call. Remove the index variable and reposition array_index_nospec(), so it's calculated immediately before the array access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jgp-67cj-x7v5

больше 4 лет назад

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4jgm-xpqf-vqrj

больше 4 лет назад

A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jh2-3c85-q67h

Improper Privilege Management in apache-airflow

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgx-vqf2-p9g9

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-4jgx-rj97-j9f4

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of shared links by leveraging meeting-attendance privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgx-p7cx-g39r

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.

CVSS3: 7.8
0%
Низкий
2 дня назад
github логотип
GHSA-4jgx-c8px-mmgc

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The keys is in the com/mobileiron/common/utils/C4928m.java file.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgx-c2mv-3qmc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4jgw-6462-7fw2

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgv-vww9-6wqw

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4jgv-gpc4-9rmg

Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.

19%
Средний
больше 4 лет назад
github логотип
GHSA-4jgr-pg2m-m988

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

3 месяца назад
github логотип
GHSA-4jgr-9qc8-cc83

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4jgr-5qw5-7m4m

Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgr-2587-qr74

The FireWire driver in IOFireWireFamily in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgq-px27-8954

A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.

CVSS3: 3.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4jgq-fhgh-wpfp

The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgq-8v4m-g4qh

The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_return_url function in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to mark any WooCommerce order as processing/completed.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-4jgq-8mwg-w9q9

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements of the PDF rendering and editing libraries used, this is one of the few pages in our backend that do not have a strong Content-Security-Policy that would render this capability useless for most scenarios.

0%
Низкий
3 месяца назад
github логотип
GHSA-4jgp-jccm-6ppx

In the Linux kernel, the following vulnerability has been resolved: x86/fred: Correct speculative safety in fred_extint() array_index_nospec() is no use if the result gets spilled to the stack, as it makes the believed safe-under-speculation value subject to memory predictions. For all practical purposes, this means array_index_nospec() must be used in the expression that accesses the array. As the code currently stands, it's the wrong side of irqentry_enter(), and 'index' is put into %ebp across the function call. Remove the index variable and reposition array_index_nospec(), so it's calculated immediately before the array access.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-4jgp-67cj-x7v5

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jgm-xpqf-vqrj

A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад

Уязвимостей на страницу