Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-47xm-33q8-pw6w

3 месяца назад

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup, causing the planted entry to be automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-47xj-xr7q-9hhq

около 3 лет назад

File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-47xh-qxqv-mgvg

почти 4 года назад

kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)

EPSS: Низкий
github логотип

GHSA-47xh-88vf-mqw7

больше 3 лет назад

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47xg-jggc-w6c4

около 1 года назад

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-47xg-7rw2-23v2

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.

EPSS: Низкий
github логотип

GHSA-47xf-g9q2-hc3g

больше 3 лет назад

A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-47xc-xmwq-4cxw

около 1 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-47xc-9rr2-q7p4

почти 4 года назад

Improper Control of Generation of Code ('Code Injection') in Azure CLI

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-47xc-94f4-86xr

больше 4 лет назад

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-47xc-8r2q-5m83

больше 4 лет назад

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47xc-86q6-rh6j

почти 2 года назад

In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-47x9-rgw2-xh4h

больше 1 года назад

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /campaign.php. The manipulation of the argument cname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-47x9-8rm9-jcx3

около 3 лет назад

DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-47x8-96vw-5wg6

4 месяца назад

vm2 Access to Host Object Enables Sandbox Escape

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-47x8-856c-g54q

больше 4 лет назад

The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bug ID CSCts01106.

EPSS: Низкий
github логотип

GHSA-47x7-rp2q-7phv

больше 4 лет назад

Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.

EPSS: Низкий
github логотип

GHSA-47x7-jrhw-hvpc

больше 4 лет назад

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731.

EPSS: Низкий
github логотип

GHSA-47x7-6hxv-jc24

больше 4 лет назад

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-47x6-r8v9-4w8c

больше 4 лет назад

Heap-based buffer overflow in the IBM ThinkVantage TPM Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-47xm-33q8-pw6w

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup, causing the planted entry to be automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction.

CVSS3: 9.1
3%
Низкий
3 месяца назад
github логотип
GHSA-47xj-xr7q-9hhq

File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

CVSS3: 7.2
6%
Низкий
около 3 лет назад
github логотип
GHSA-47xh-qxqv-mgvg

kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)

почти 4 года назад
github логотип
GHSA-47xh-88vf-mqw7

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-47xg-jggc-w6c4

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-47xg-7rw2-23v2

Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xf-g9q2-hc3g

A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-47xc-xmwq-4cxw

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 1 месяца назад
github логотип
GHSA-47xc-9rr2-q7p4

Improper Control of Generation of Code ('Code Injection') in Azure CLI

CVSS3: 8.1
3%
Низкий
почти 4 года назад
github логотип
GHSA-47xc-94f4-86xr

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-47xc-8r2q-5m83

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-47xc-86q6-rh6j

In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-47x9-rgw2-xh4h

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /campaign.php. The manipulation of the argument cname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-47x9-8rm9-jcx3

DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-47x8-96vw-5wg6

vm2 Access to Host Object Enables Sandbox Escape

CVSS3: 10
1%
Низкий
4 месяца назад
github логотип
GHSA-47x8-856c-g54q

The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bug ID CSCts01106.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47x7-rp2q-7phv

Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-47x7-jrhw-hvpc

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47x7-6hxv-jc24

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47x6-r8v9-4w8c

Heap-based buffer overflow in the IBM ThinkVantage TPM Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

5%
Низкий
больше 4 лет назад

Уязвимостей на страницу