Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43r3-p9qg-f74p

больше 4 лет назад

Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-43r3-f7j4-6552

больше 4 лет назад

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

EPSS: Низкий
github логотип

GHSA-43r2-vc56-g759

больше 4 лет назад

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43r2-rv47-2g9m

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPyog WPYog Documents allows Reflected XSS. This issue affects WPYog Documents: from n/a through 1.3.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43r2-pvj9-5h7x

около 2 месяцев назад

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43r2-j3m4-vcpc

больше 4 лет назад

Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

EPSS: Низкий
github логотип

GHSA-43qx-6r5f-7vgw

около 3 лет назад

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-43qx-5g4q-qv73

больше 4 лет назад

The mintToken function of a smart contract implementation for ETHERCASH (ETC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43qw-p4wg-qvxr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.

EPSS: Низкий
github логотип

GHSA-43qv-gqwc-rjxf

больше 4 лет назад

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

EPSS: Низкий
github логотип

GHSA-43qr-pjmr-cgfv

больше 1 года назад

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43qr-ph4f-wq48

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43qr-7pjx-rp3v

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FameThemes OnePress allows Stored XSS.This issue affects OnePress: from n/a through 2.3.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43qq-qw4x-28f8

почти 4 года назад

Kirby CMS vulnerable to user enumeration in the code-based login and password reset forms

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-43qp-rp4g-mx9r

больше 4 лет назад

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-43qp-hphf-5rjw

больше 4 лет назад

Chakra Core vulnerable to privilege escalation due to reading an invalid pointer

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43qp-56c9-mg75

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43qm-4w5w-7m4c

больше 3 лет назад

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-43qj-8555-mr85

около 3 лет назад

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43qh-64c2-wvgp

около 1 года назад

The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43r3-p9qg-f74p

Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-43r3-f7j4-6552

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43r2-vc56-g759

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43r2-rv47-2g9m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPyog WPYog Documents allows Reflected XSS. This issue affects WPYog Documents: from n/a through 1.3.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-43r2-pvj9-5h7x

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-43r2-j3m4-vcpc

Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-43qx-6r5f-7vgw

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-43qx-5g4q-qv73

The mintToken function of a smart contract implementation for ETHERCASH (ETC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43qw-p4wg-qvxr

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43qv-gqwc-rjxf

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43qr-pjmr-cgfv

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVSS3: 5.4
8%
Низкий
больше 1 года назад
github логотип
GHSA-43qr-ph4f-wq48

Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43qr-7pjx-rp3v

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FameThemes OnePress allows Stored XSS.This issue affects OnePress: from n/a through 2.3.8.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-43qq-qw4x-28f8

Kirby CMS vulnerable to user enumeration in the code-based login and password reset forms

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-43qp-rp4g-mx9r

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43qp-hphf-5rjw

Chakra Core vulnerable to privilege escalation due to reading an invalid pointer

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-43qp-56c9-mg75

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43qm-4w5w-7m4c

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43qj-8555-mr85

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-43qh-64c2-wvgp

The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу