Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-44w3-wrmw-j9hx

больше 4 лет назад

IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-44w3-qvp9-4hh4

больше 4 лет назад

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44w3-4x9p-xmff

больше 1 года назад

The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44w2-xrgw-gqvj

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.

EPSS: Низкий
github логотип

GHSA-44w2-crmp-vc4v

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44w2-cgm4-695p

около 1 года назад

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined.

EPSS: Низкий
github логотип

GHSA-44w2-c6gq-2xxx

больше 1 года назад

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44vx-q8jj-wcwm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.

EPSS: Низкий
github логотип

GHSA-44vx-c3xh-577j

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-44vw-x4jf-3q2f

больше 2 лет назад

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-44vw-5m8p-p6fc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

EPSS: Низкий
github логотип

GHSA-44vv-qwrx-c34r

10 месяцев назад

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44vv-mm86-7cg6

больше 4 лет назад

phpMyAdmin server-side request forgery (SSRF)

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-44vv-j7c4-9vf4

почти 3 года назад

Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-44vv-6vcv-9h7r

больше 1 года назад

Windows Telephony Service Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44vv-4w2p-9wqf

больше 4 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44vv-2mpg-8hv5

больше 2 лет назад

Microsoft Office OneNote Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44vr-rwwj-p88h

около 4 лет назад

Shescape vulnerable to insufficient escaping of whitespace

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-44vr-phh9-75gf

почти 3 года назад

Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44vr-jgwf-45qh

больше 4 лет назад

Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44w3-wrmw-j9hx

IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.

CVSS3: 8.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-44w3-qvp9-4hh4

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-44w3-4x9p-xmff

The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-44w2-xrgw-gqvj

Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-44w2-crmp-vc4v

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-44w2-cgm4-695p

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined.

1%
Низкий
около 1 года назад
github логотип
GHSA-44w2-c6gq-2xxx

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-44vx-q8jj-wcwm

Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-44vx-c3xh-577j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-44vw-x4jf-3q2f

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-44vw-5m8p-p6fc

Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-44vv-qwrx-c34r

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-44vv-mm86-7cg6

phpMyAdmin server-side request forgery (SSRF)

CVSS3: 8.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-44vv-j7c4-9vf4

Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-44vv-6vcv-9h7r

Windows Telephony Service Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-44vv-4w2p-9wqf

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-44vv-2mpg-8hv5

Microsoft Office OneNote Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-44vr-rwwj-p88h

Shescape vulnerable to insufficient escaping of whitespace

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-44vr-phh9-75gf

Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-44vr-jgwf-45qh

Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу