Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4fwj-v7f6-pq59

больше 4 лет назад

Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1) components/com_search/views/search/tmpl/ and (2) templates/beez/html/com_search/search/.

EPSS: Средний
github логотип

GHSA-4fwj-m62q-pp47

больше 1 года назад

Password Pusher Allows Session Token Interception Leading to Potential Hijacking

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4fwj-8595-wp25

около 1 года назад

Mattermost has Insufficiently Protected Credentials

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-4fwh-vhv3-7xx7

больше 2 лет назад

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fwh-r866-pvh9

больше 4 лет назад

LibreNMS SQL Injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4fwh-62fj-p4ww

больше 4 лет назад

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4fwh-3qpr-42ff

больше 4 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. When parsing the uuid request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14110.

EPSS: Низкий
github логотип

GHSA-4fwg-m6rv-m2jr

около 2 месяцев назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4fwf-gvh7-mg58

11 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4fwf-7mx6-7ph9

больше 4 лет назад

Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' as it insecurely prints the 'Log Message' value on the web page without applying any proper filtration. This relates to the view=logs value.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4fwc-r99f-85f4

больше 4 лет назад

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4fwc-r6j4-9vgg

больше 4 лет назад

A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

EPSS: Низкий
github логотип

GHSA-4fw9-4m74-7p58

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Site Launcher allows Reflected XSS. This issue affects Site Launcher: from n/a through 0.9.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4fw8-6hp7-5whp

больше 4 лет назад

Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.

EPSS: Низкий
github логотип

GHSA-4fw7-9pw4-4mvx

больше 4 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

EPSS: Низкий
github логотип

GHSA-4fw6-xxwg-9332

5 месяцев назад

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4fw6-xfgg-vh7h

больше 4 лет назад

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than other Flash Player buffer overflow CVEs listed in APSB12-22.

EPSS: Низкий
github логотип

GHSA-4fw6-r8x4-6gcx

больше 4 лет назад

Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.

EPSS: Низкий
github логотип

GHSA-4fw6-r22r-32px

больше 4 лет назад

SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action.

EPSS: Низкий
github логотип

GHSA-4fw6-qxc4-gqgq

12 дней назад

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4fwj-v7f6-pq59

Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1) components/com_search/views/search/tmpl/ and (2) templates/beez/html/com_search/search/.

11%
Средний
больше 4 лет назад
github логотип
GHSA-4fwj-m62q-pp47

Password Pusher Allows Session Token Interception Leading to Potential Hijacking

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4fwj-8595-wp25

Mattermost has Insufficiently Protected Credentials

CVSS3: 2.2
0%
Низкий
около 1 года назад
github логотип
GHSA-4fwh-vhv3-7xx7

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4fwh-r866-pvh9

LibreNMS SQL Injection

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fwh-62fj-p4ww

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.

CVSS3: 6.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fwh-3qpr-42ff

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. When parsing the uuid request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14110.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4fwg-m6rv-m2jr

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4fwf-gvh7-mg58

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

CVSS3: 6.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-4fwf-7mx6-7ph9

Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' as it insecurely prints the 'Log Message' value on the web page without applying any proper filtration. This relates to the view=logs value.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fwc-r99f-85f4

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4fwc-r6j4-9vgg

A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fw9-4m74-7p58

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Site Launcher allows Reflected XSS. This issue affects Site Launcher: from n/a through 0.9.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4fw8-6hp7-5whp

Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fw7-9pw4-4mvx

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fw6-xxwg-9332

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-4fw6-xfgg-vh7h

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than other Flash Player buffer overflow CVEs listed in APSB12-22.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4fw6-r8x4-6gcx

Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4fw6-r22r-32px

SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fw6-qxc4-gqgq

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

0%
Низкий
12 дней назад

Уязвимостей на страницу