Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f24-v7j6-88wx

больше 4 лет назад

Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4f24-3c6c-gh99

больше 2 лет назад

The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4f23-rq6h-3p55

около 3 лет назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, Safari 16.5, tvOS 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4f22-7h3g-c989

больше 2 лет назад

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4cxx-m26f-jmx8

около 2 месяцев назад

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cxw-rrj3-g8mv

около 4 лет назад

In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4cxw-hq44-r344

больше 4 лет назад

Off-by-one Error in v2fly/v2ray-core

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4cxv-wp2w-88h7

больше 4 лет назад

Privatefirewall 5.0.14.2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for (1) NtOpenProcess and (2) NtOpenThread.

EPSS: Низкий
github логотип

GHSA-4cxv-rq6w-3ppq

больше 4 лет назад

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4cxv-gmm7-q86r

больше 4 лет назад

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cxv-c4qq-q263

больше 4 лет назад

custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4cxv-4ppr-px4m

12 месяцев назад

The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google Maps markers, Lightbox captions, Image Gallery data attributes, Progress Pie prefix/suffix fields, and Text Path URL fields. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4cxr-ppvr-vppg

9 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4cxr-9fjv-2m3m

больше 1 года назад

The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4cxr-8c43-3frp

почти 3 года назад

TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cxr-4vwc-6pg7

больше 4 лет назад

Jenkins Bitbucket Approve Plugin stores credentials in plain text

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4cxq-fp26-wf3w

больше 4 лет назад

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4cxq-66m5-gvgm

5 месяцев назад

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cxp-jjp3-3qpw

больше 4 лет назад

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cxp-jj37-cmrx

больше 1 года назад

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `EUTRAN_CGI` field.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f24-v7j6-88wx

Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f24-3c6c-gh99

The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4f23-rq6h-3p55

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, Safari 16.5, tvOS 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4f22-7h3g-c989

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

CVSS3: 8.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4cxx-m26f-jmx8

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4cxw-rrj3-g8mv

In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-4cxw-hq44-r344

Off-by-one Error in v2fly/v2ray-core

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxv-wp2w-88h7

Privatefirewall 5.0.14.2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for (1) NtOpenProcess and (2) NtOpenThread.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxv-rq6w-3ppq

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxv-gmm7-q86r

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.

CVSS3: 7.5
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxv-c4qq-q263

custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxv-4ppr-px4m

The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google Maps markers, Lightbox captions, Image Gallery data attributes, Progress Pie prefix/suffix fields, and Text Path URL fields. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-4cxr-ppvr-vppg

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-4cxr-9fjv-2m3m

The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cxr-8c43-3frp

TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-4cxr-4vwc-6pg7

Jenkins Bitbucket Approve Plugin stores credentials in plain text

CVSS3: 3.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxq-fp26-wf3w

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxq-66m5-gvgm

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4cxp-jjp3-3qpw

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4cxp-jj37-cmrx

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `EUTRAN_CGI` field.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу