Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-4429-qgp7-2cwq

больше 1 года назад

The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4429-pqf2-hv4m

больше 4 лет назад

Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4429-9xv8-3xpm

около 2 лет назад

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4429-757q-f87q

больше 4 лет назад

An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (on the heap) can be overrun. With this fixed, it prefers to look only at the answer RRs which come after the CNAME, which is at least arguably correct.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4428-9rh9-r27g

8 месяцев назад

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-4427-hxx6-cmx7

больше 4 лет назад

Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4427-h6h2-wh2w

почти 3 года назад

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4427-7f3w-mqv6

больше 4 лет назад

OpenStack Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4426-wxwq-q9rv

больше 4 лет назад

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17106, CVE-2020-17108, CVE-2020-17109, CVE-2020-17110.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4426-5gmw-3hrf

больше 1 года назад

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4426-49xv-wxg5

больше 4 лет назад

Multiple format string vulnerabilities in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in certain data chunk values in an aircraft xml model to (1) fgfs/flightgear/src/Cockpit/panel.cxx or (2) fgfs/flightgear/src/Network/generic.cxx, or (3) a scene graph model to simgear/simgear/scene/model/SGText.cxx.

EPSS: Низкий
github логотип

GHSA-4426-3833-j328

около 3 лет назад

A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4425-xxq2-j38q

11 месяцев назад

The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the saveFields() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4425-vvcm-jqxw

4 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4425-mwr9-99xc

больше 4 лет назад

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

EPSS: Низкий
github логотип

GHSA-4425-fxh6-87fr

больше 4 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4425-9m6f-3ppg

больше 2 лет назад

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4425-83hj-m78v

больше 4 лет назад

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

EPSS: Средний
github логотип

GHSA-4425-3v92-m6q6

больше 2 лет назад

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4422-p6xr-vfgh

больше 4 лет назад

Windows Installer Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26415.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4429-qgp7-2cwq

The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-4429-pqf2-hv4m

Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4429-9xv8-3xpm

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4429-757q-f87q

An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (on the heap) can be overrun. With this fixed, it prefers to look only at the answer RRs which come after the CNAME, which is at least arguably correct.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4428-9rh9-r27g

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

CVSS3: 9.9
1%
Низкий
8 месяцев назад
github логотип
GHSA-4427-hxx6-cmx7

Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4427-h6h2-wh2w

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4427-7f3w-mqv6

OpenStack Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4426-wxwq-q9rv

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17106, CVE-2020-17108, CVE-2020-17109, CVE-2020-17110.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4426-5gmw-3hrf

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4426-49xv-wxg5

Multiple format string vulnerabilities in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in certain data chunk values in an aircraft xml model to (1) fgfs/flightgear/src/Cockpit/panel.cxx or (2) fgfs/flightgear/src/Network/generic.cxx, or (3) a scene graph model to simgear/simgear/scene/model/SGText.cxx.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4426-3833-j328

A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4425-xxq2-j38q

The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the saveFields() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-4425-vvcm-jqxw

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4425-mwr9-99xc

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4425-fxh6-87fr

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

CVSS3: 7.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4425-9m6f-3ppg

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4425-83hj-m78v

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

31%
Средний
больше 4 лет назад
github логотип
GHSA-4425-3v92-m6q6

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4422-p6xr-vfgh

Windows Installer Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26415.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу