Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g88-vp7j-rp6x

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-4g88-pvpj-755p

больше 4 лет назад

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

EPSS: Низкий
github логотип

GHSA-4g88-fppr-53pp

около 7 лет назад

Prototype Pollution in set-value

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g88-4hgm-m99x

почти 3 года назад

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g87-9x45-cx2h

10 месяцев назад

Mattermost fails to sanitize team email addresses

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4g86-mfr6-26v9

больше 2 лет назад

In Santesoft Sante FFT Imaging versions 1.4.1 and prior once a user opens a malicious DCM file on affected FFT Imaging installations, a local attacker could perform an out-of-bounds write, which could allow for arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g86-5q85-v98x

больше 4 лет назад

SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.

EPSS: Низкий
github логотип

GHSA-4g85-vrrc-6gq5

больше 3 лет назад

The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4g85-q6g8-m8qc

12 месяцев назад

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g85-cv2v-x664

больше 4 лет назад

In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g85-9mh4-6cw4

больше 3 лет назад

An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. SUSE Linux Enterprise Server for SAP 12-SP5 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. openSUSE Leap 15.4 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g84-qrqg-4cjp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in display_dialog.php in M2 OptimalSite 0.1 and 2.4 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

EPSS: Низкий
github логотип

GHSA-4g84-hqrm-78fw

больше 4 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). The supported version that is affected is 10.3.6.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4g84-h5fq-jcf7

больше 4 лет назад

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000008fe4."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g84-8f3p-rffh

больше 4 лет назад

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the CCITT fax PDF filter. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g83-m3vp-774r

больше 4 лет назад

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.

EPSS: Низкий
github логотип

GHSA-4g83-c799-59v3

больше 4 лет назад

Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 7.0, 8.1, and 8.2 allows remote attackers to affect integrity via unknown vectors related to Web Access.

EPSS: Низкий
github логотип

GHSA-4g83-8xc3-pp6v

больше 4 лет назад

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a heap-allocated memory. This flaw is caused by the lack of length checks in rfc1035.c:extract_name(), which could be abused to make the code execute memcpy() with a negative size in get_rdata() and cause a crash in dnsmasq, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 5.9
EPSS: Высокий
github логотип

GHSA-4g82-fhh4-4p9r

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Plugincraft Mediamatic – Media Library Folders plugin <= 2.8.1 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4g82-7r8h-h94r

больше 4 лет назад

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g88-vp7j-rp6x

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 10
1%
Низкий
больше 1 года назад
github логотип
GHSA-4g88-pvpj-755p

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g88-fppr-53pp

Prototype Pollution in set-value

CVSS3: 9.8
2%
Низкий
около 7 лет назад
github логотип
GHSA-4g88-4hgm-m99x

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4g87-9x45-cx2h

Mattermost fails to sanitize team email addresses

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-4g86-mfr6-26v9

In Santesoft Sante FFT Imaging versions 1.4.1 and prior once a user opens a malicious DCM file on affected FFT Imaging installations, a local attacker could perform an out-of-bounds write, which could allow for arbitrary code execution.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g86-5q85-v98x

SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g85-vrrc-6gq5

The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4g85-q6g8-m8qc

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

CVSS3: 8.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-4g85-cv2v-x664

In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g85-9mh4-6cw4

An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. SUSE Linux Enterprise Server for SAP 12-SP5 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. openSUSE Leap 15.4 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4g84-qrqg-4cjp

Cross-site scripting (XSS) vulnerability in display_dialog.php in M2 OptimalSite 0.1 and 2.4 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g84-hqrm-78fw

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). The supported version that is affected is 10.3.6.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g84-h5fq-jcf7

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000008fe4."

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g84-8f3p-rffh

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the CCITT fax PDF filter. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4g83-m3vp-774r

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4g83-c799-59v3

Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 7.0, 8.1, and 8.2 allows remote attackers to affect integrity via unknown vectors related to Web Access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g83-8xc3-pp6v

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a heap-allocated memory. This flaw is caused by the lack of length checks in rfc1035.c:extract_name(), which could be abused to make the code execute memcpy() with a negative size in get_rdata() and cause a crash in dnsmasq, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 5.9
86%
Высокий
больше 4 лет назад
github логотип
GHSA-4g82-fhh4-4p9r

Cross-Site Request Forgery (CSRF) vulnerability in Plugincraft Mediamatic – Media Library Folders plugin <= 2.8.1 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-4g82-7r8h-h94r

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу