Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-4847-gqxx-v9xp

около 3 лет назад

ThinkCMF Cross-site Scripting Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4847-3cw5-45xm

больше 3 лет назад

The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4846-8x25-45mr

больше 4 лет назад

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0806, and CVE-2018-0807

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4846-7xwg-pw5m

около 2 месяцев назад

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4846-33hj-w865

больше 4 лет назад

GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4846-269g-37mp

больше 4 лет назад

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

EPSS: Низкий
github логотип

GHSA-4845-x49f-5m4r

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web script or HTML via the user parameter.

EPSS: Низкий
github логотип

GHSA-4845-jm5w-pm5q

больше 4 лет назад

Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.

EPSS: Низкий
github логотип

GHSA-4845-j55w-6rx6

больше 4 лет назад

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

EPSS: Средний
github логотип

GHSA-4844-xhp4-vx37

больше 3 лет назад

A vulnerability classified as critical has been found in ningzichun Student Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument user/pass leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230355.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4844-fjxq-2qmw

больше 1 года назад

The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4844-9f5j-f96x

больше 4 лет назад

An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet can cause a logic flaw, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4844-58w2-p88q

больше 4 лет назад

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."

EPSS: Низкий
github логотип

GHSA-4844-58hp-rqwx

больше 2 лет назад

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4844-25m4-j7hc

2 месяца назад

Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-4843-wqq7-hm2g

больше 4 лет назад

marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.

EPSS: Низкий
github логотип

GHSA-4843-jw5m-c4mr

почти 2 года назад

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4842-r7qr-qmjq

больше 4 лет назад

Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.

EPSS: Средний
github логотип

GHSA-4842-pw8g-w8wv

больше 4 лет назад

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

EPSS: Низкий
github логотип

GHSA-4842-39rx-hq8h

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4847-gqxx-v9xp

ThinkCMF Cross-site Scripting Vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-4847-3cw5-45xm

The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4846-8x25-45mr

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0806, and CVE-2018-0807

CVSS3: 8.8
24%
Средний
больше 4 лет назад
github логотип
GHSA-4846-7xwg-pw5m

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4846-33hj-w865

GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4846-269g-37mp

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4845-x49f-5m4r

Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web script or HTML via the user parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4845-jm5w-pm5q

Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4845-j55w-6rx6

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

69%
Средний
больше 4 лет назад
github логотип
GHSA-4844-xhp4-vx37

A vulnerability classified as critical has been found in ningzichun Student Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument user/pass leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230355.

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4844-fjxq-2qmw

The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-4844-9f5j-f96x

An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet can cause a logic flaw, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4844-58w2-p88q

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4844-58hp-rqwx

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4844-25m4-j7hc

Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

CVSS3: 2.7
0%
Низкий
2 месяца назад
github логотип
GHSA-4843-wqq7-hm2g

marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4843-jw5m-c4mr

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

CVSS3: 6.7
2%
Низкий
почти 2 года назад
github логотип
GHSA-4842-r7qr-qmjq

Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.

11%
Средний
больше 4 лет назад
github логотип
GHSA-4842-pw8g-w8wv

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4842-39rx-hq8h

Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу