Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-4528-gx3q-g73r

14 дней назад

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4527-qc36-r4c9

3 месяца назад

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4527-g864-c7mh

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sahifa allows DOM-Based XSS.This issue affects Sahifa: from n/a through < 5.8.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4527-385c-q8r6

почти 2 года назад

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4526-r3g2-c73j

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4526-q5cq-pcrg

9 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4526-pqcm-97mm

больше 4 лет назад

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4526-ppgm-5hff

больше 4 лет назад

Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.

EPSS: Низкий
github логотип

GHSA-4526-48hj-jf4q

больше 4 лет назад

Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOTE: this might be the same issue as CVE-2004-2463.

EPSS: Низкий
github логотип

GHSA-4525-wg6p-34mx

около 3 лет назад

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-4525-8cq6-cf8m

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_net, at 0x9d018234, the value for the `sub` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-4525-66vv-3hwf

больше 4 лет назад

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4524-x6pc-rr9x

4 месяца назад

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths that survives process exit.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4524-hxm7-m92p

почти 5 лет назад

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4524-cj9j-g4fj

6 месяцев назад

OneUptime: Password Reset Token Logged at INFO Level

EPSS: Низкий
github логотип

GHSA-4523-qqfr-gg5w

больше 3 лет назад

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4523-grj5-wxfg

9 месяцев назад

Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4523-4wmc-wwmr

больше 4 лет назад

Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution.

EPSS: Низкий
github логотип

GHSA-4522-qq94-2q92

больше 4 лет назад

An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Server Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1224.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4522-mh29-ff78

больше 4 лет назад

Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4528-gx3q-g73r

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover.

CVSS3: 8.8
0%
Низкий
14 дней назад
github логотип
GHSA-4527-qc36-r4c9

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4527-g864-c7mh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sahifa allows DOM-Based XSS.This issue affects Sahifa: from n/a through < 5.8.6.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-4527-385c-q8r6

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-4526-r3g2-c73j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4526-q5cq-pcrg

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-4526-pqcm-97mm

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism.

CVSS3: 7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4526-ppgm-5hff

Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4526-48hj-jf4q

Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOTE: this might be the same issue as CVE-2004-2463.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4525-wg6p-34mx

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.

CVSS3: 9.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-4525-8cq6-cf8m

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_net, at 0x9d018234, the value for the `sub` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4525-66vv-3hwf

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4524-x6pc-rr9x

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths that survives process exit.

CVSS3: 3.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4524-hxm7-m92p

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

CVSS3: 7.5
5%
Низкий
почти 5 лет назад
github логотип
GHSA-4524-cj9j-g4fj

OneUptime: Password Reset Token Logged at INFO Level

0%
Низкий
6 месяцев назад
github логотип
GHSA-4523-qqfr-gg5w

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4523-grj5-wxfg

Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-4523-4wmc-wwmr

Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4522-qq94-2q92

An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Server Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1224.

CVSS3: 7.5
10%
Низкий
больше 4 лет назад
github логотип
GHSA-4522-mh29-ff78

Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."

25%
Средний
больше 4 лет назад

Уязвимостей на страницу