Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-47xx-cqxv-2m23

больше 4 лет назад

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-47xx-c7pc-hm29

больше 4 лет назад

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-47xx-5583-pmg9

12 месяцев назад

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-47xw-xrjr-j2jv

больше 4 лет назад

The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includes/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

EPSS: Низкий
github логотип

GHSA-47xw-xh86-4m2j

больше 4 лет назад

Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.

EPSS: Низкий
github логотип

GHSA-47xw-vw6m-w9fq

почти 3 года назад

HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-47xw-gpq6-2gmf

больше 4 лет назад

The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application.

EPSS: Низкий
github логотип

GHSA-47xw-cmcm-mpqp

больше 4 лет назад

MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.

EPSS: Низкий
github логотип

GHSA-47xw-2q7j-49hw

больше 1 года назад

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-47xw-24jg-pc7q

больше 4 лет назад

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-47xv-rr7v-mrp5

больше 4 лет назад

Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-47xr-vqf6-fqhm

больше 4 лет назад

IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user to gain unauthorized access to a user's session. IBM X-Force ID: 175211.

EPSS: Низкий
github логотип

GHSA-47xr-344c-wgc3

больше 4 лет назад

An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.

EPSS: Низкий
github логотип

GHSA-47xq-mwq7-mw56

больше 4 лет назад

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."

EPSS: Низкий
github логотип

GHSA-47xq-cq66-m24x

5 месяцев назад

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-47xq-6f8h-pg46

около 2 лет назад

A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_deductions. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-47xm-m74m-9r46

больше 4 лет назад

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47xm-jj6p-4p66

больше 4 лет назад

An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47xm-cjc8-2m58

больше 4 лет назад

Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

EPSS: Низкий
github логотип

GHSA-47xm-854m-6fp7

больше 1 года назад

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Add User Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.

CVSS3: 2.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-47xx-cqxv-2m23

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xx-c7pc-hm29

Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-47xx-5583-pmg9

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-47xw-xrjr-j2jv

The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includes/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xw-xh86-4m2j

Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-47xw-vw6m-w9fq

HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability

CVSS3: 3.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-47xw-gpq6-2gmf

The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xw-cmcm-mpqp

MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xw-2q7j-49hw

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-47xw-24jg-pc7q

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-47xv-rr7v-mrp5

Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-47xr-vqf6-fqhm

IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user to gain unauthorized access to a user's session. IBM X-Force ID: 175211.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xr-344c-wgc3

An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-47xq-mwq7-mw56

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."

7%
Низкий
больше 4 лет назад
github логотип
GHSA-47xq-cq66-m24x

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-47xq-6f8h-pg46

A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_deductions. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-47xm-m74m-9r46

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xm-jj6p-4p66

An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-47xm-cjc8-2m58

Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-47xm-854m-6fp7

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Add User Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.

CVSS3: 2.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу