Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-486g-jg8g-q4pg

больше 4 лет назад

Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php.

EPSS: Средний
github логотип

GHSA-486g-47cc-8wxf

почти 2 года назад

aiocpa contains credential harvesting code

EPSS: Низкий
github логотип

GHSA-486g-3323-7948

больше 4 лет назад

Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-486f-hjj9-9vhh

больше 3 лет назад

Inefficient Regular Expression Complexity in Loofah

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-486c-vrv4-hh35

около 1 года назад

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-486c-fgp8-q4mj

больше 4 лет назад

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4869-x4pr-q22x

3 месяца назад

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4869-v738-xvvg

около 2 лет назад

2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4869-ghp2-7x5q

почти 3 года назад

Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4868-5x3w-95q3

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php.

EPSS: Низкий
github логотип

GHSA-4866-p686-25f3

больше 4 лет назад

DrayTek Vigor2960 1.3.1_Beta; Vigor3900 1.4.4_Beta; and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4863-57r9-m6xc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Connect Contact Form 7 to Constant Contact allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through 1.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4862-x8vr-278v

больше 4 лет назад

IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-485w-vv83-53fx

больше 4 лет назад

Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.

EPSS: Низкий
github логотип

GHSA-485w-jm59-qvxp

больше 4 лет назад

Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-485w-3qw7-xvjq

больше 4 лет назад

The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.

EPSS: Низкий
github логотип

GHSA-485v-wc7x-92fx

3 месяца назад

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-485v-639h-vm9r

10 месяцев назад

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-485v-466m-9mjv

почти 2 года назад

In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-485r-rp8v-998v

около 3 лет назад

Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-486g-jg8g-q4pg

Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php.

13%
Средний
больше 4 лет назад
github логотип
GHSA-486g-47cc-8wxf

aiocpa contains credential harvesting code

почти 2 года назад
github логотип
GHSA-486g-3323-7948

Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-486f-hjj9-9vhh

Inefficient Regular Expression Complexity in Loofah

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-486c-vrv4-hh35

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-486c-fgp8-q4mj

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4869-x4pr-q22x

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

CVSS3: 9.8
3 месяца назад
github логотип
GHSA-4869-v738-xvvg

2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4869-ghp2-7x5q

Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4868-5x3w-95q3

Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4866-p686-25f3

DrayTek Vigor2960 1.3.1_Beta; Vigor3900 1.4.4_Beta; and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI.

CVSS3: 9.8
100%
Критический
больше 4 лет назад
github логотип
GHSA-4863-57r9-m6xc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Connect Contact Form 7 to Constant Contact allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through 1.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4862-x8vr-278v

IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-485w-vv83-53fx

Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-485w-jm59-qvxp

Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-485w-3qw7-xvjq

The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-485v-wc7x-92fx

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.

CVSS3: 6.2
0%
Низкий
3 месяца назад
github логотип
GHSA-485v-639h-vm9r

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-485v-466m-9mjv

In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-485r-rp8v-998v

Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability

CVSS3: 8.1
2%
Низкий
около 3 лет назад

Уязвимостей на страницу