Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cg3-gfhj-x3xm

больше 4 лет назад

Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

EPSS: Низкий
github логотип

GHSA-4cg2-c6h6-v749

больше 1 года назад

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-4cfx-p6p6-jpvw

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

EPSS: Низкий
github логотип

GHSA-4cfx-h9gq-xpx3

около 3 лет назад

Heap overflow in COMMAND GETKEYS and ACL evaluation

CVSS3: 7.4
EPSS: Высокий
github логотип

GHSA-4cfw-gc9p-jwf4

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-4cfw-g6m2-82xj

больше 4 лет назад

** DISPUTED ** An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4cfw-fmc2-h845

5 месяцев назад

A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4cfr-xp32-h9c9

больше 1 года назад

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4cfr-h84p-cp36

больше 4 лет назад

Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.

EPSS: Низкий
github логотип

GHSA-4cfr-gjfx-fj3x

почти 5 лет назад

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4cfr-8c5p-5jg6

больше 4 лет назад

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

EPSS: Низкий
github логотип

GHSA-4cfq-849g-j9jx

больше 4 лет назад

I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.

EPSS: Низкий
github логотип

GHSA-4cfp-g6j6-f76r

больше 4 лет назад

ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-4cfp-2523-96q2

больше 3 лет назад

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4cfm-6q3x-wgvm

больше 1 года назад

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4cfm-33p5-g53v

больше 2 лет назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-4cfj-pm5j-9qhf

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cfj-fw6h-v7f4

больше 4 лет назад

Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4cfj-cvw8-f4m2

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4cfh-gw3m-q584

больше 4 лет назад

In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cg3-gfhj-x3xm

Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cg2-c6h6-v749

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cfx-p6p6-jpvw

Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfx-h9gq-xpx3

Heap overflow in COMMAND GETKEYS and ACL evaluation

CVSS3: 7.4
77%
Высокий
около 3 лет назад
github логотип
GHSA-4cfw-gc9p-jwf4

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-4cfw-g6m2-82xj

** DISPUTED ** An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfw-fmc2-h845

A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-4cfr-xp32-h9c9

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cfr-h84p-cp36

Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfr-gjfx-fj3x

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

CVSS3: 7.5
69%
Средний
почти 5 лет назад
github логотип
GHSA-4cfr-8c5p-5jg6

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfq-849g-j9jx

I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfp-g6j6-f76r

ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfp-2523-96q2

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4cfm-6q3x-wgvm

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cfm-33p5-g53v

Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.

CVSS3: 9.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4cfj-pm5j-9qhf

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-4cfj-fw6h-v7f4

Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cfj-cvw8-f4m2

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-4cfh-gw3m-q584

In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу