Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43h6-fcm4-w3mq

почти 4 года назад

A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43h5-hjxq-m9rj

больше 4 лет назад

Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.

EPSS: Низкий
github логотип

GHSA-43h5-c8qq-fwqf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Add custom content after post allows Reflected XSS. This issue affects Add custom content after post: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43h5-8p3v-hfvv

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aniketji007 Ultimate Flipbox Addon for Elementor allows Stored XSS.This issue affects Ultimate Flipbox Addon for Elementor: from n/a through .4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43h4-q69g-56g6

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-43h4-6rw5-hg63

больше 4 лет назад

The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43h4-6cw6-2rm4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.

EPSS: Низкий
github логотип

GHSA-43h2-vrg5-h3qp

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/ras: Fix NULL deref in ras_core_get_utc_second_timestamp() ras_core_get_utc_second_timestamp() retrieves the current UTC timestamp (in seconds since the Unix epoch) through a platform-specific RAS system callback and is used for timestamping RAS error events. The function checks ras_core in the conditional statement before calling the sys_fn callback. However, when the condition fails, the function prints an error message using ras_core->dev. If ras_core is NULL, this can lead to a potential NULL pointer dereference when accessing ras_core->dev. Add an early NULL check for ras_core at the beginning of the function and return 0 when the pointer is not valid. This prevents the dereference and makes the control flow clearer.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43h2-r954-f6w6

около 1 года назад

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-43h2-3jvw-fm7r

около 1 года назад

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=save_settings of the component About Content Page. The manipulation of the argument img leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43gx-fr8q-99g5

больше 3 лет назад

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43gx-6gv6-3jcp

6 месяцев назад

Products.isurlinportal has possible open redirect when using more than 2 forward slashes

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43gx-3jr2-gx6w

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in fromdoppler Doppler Forms allows Stored XSS. This issue affects Doppler Forms: from n/a through 2.4.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43gw-3r3x-6rm5

около 2 лет назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-43gr-pj36-rwvj

больше 4 лет назад

Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter.

EPSS: Низкий
github логотип

GHSA-43gr-9jjm-9rf2

больше 4 лет назад

An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password.

EPSS: Низкий
github логотип

GHSA-43gq-7wp4-9vh5

больше 4 лет назад

plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-43gp-phvm-pqvg

больше 4 лет назад

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Низкий
github логотип

GHSA-43gp-53vg-4cr3

больше 4 лет назад

CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.

EPSS: Низкий
github логотип

GHSA-43gp-2vcj-4vxj

больше 4 лет назад

Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43h6-fcm4-w3mq

A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-43h5-hjxq-m9rj

Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43h5-c8qq-fwqf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Add custom content after post allows Reflected XSS. This issue affects Add custom content after post: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-43h5-8p3v-hfvv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aniketji007 Ultimate Flipbox Addon for Elementor allows Stored XSS.This issue affects Ultimate Flipbox Addon for Elementor: from n/a through .4.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-43h4-q69g-56g6

Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-43h4-6rw5-hg63

The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43h4-6cw6-2rm4

Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43h2-vrg5-h3qp

In the Linux kernel, the following vulnerability has been resolved: drm/amd/ras: Fix NULL deref in ras_core_get_utc_second_timestamp() ras_core_get_utc_second_timestamp() retrieves the current UTC timestamp (in seconds since the Unix epoch) through a platform-specific RAS system callback and is used for timestamping RAS error events. The function checks ras_core in the conditional statement before calling the sys_fn callback. However, when the condition fails, the function prints an error message using ras_core->dev. If ras_core is NULL, this can lead to a potential NULL pointer dereference when accessing ras_core->dev. Add an early NULL check for ras_core at the beginning of the function and return 0 when the pointer is not valid. This prevents the dereference and makes the control flow clearer.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-43h2-r954-f6w6

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-43h2-3jvw-fm7r

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=save_settings of the component About Content Page. The manipulation of the argument img leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-43gx-fr8q-99g5

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43gx-6gv6-3jcp

Products.isurlinportal has possible open redirect when using more than 2 forward slashes

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-43gx-3jr2-gx6w

Cross-Site Request Forgery (CSRF) vulnerability in fromdoppler Doppler Forms allows Stored XSS. This issue affects Doppler Forms: from n/a through 2.4.5.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-43gw-3r3x-6rm5

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 2 лет назад
github логотип
GHSA-43gr-pj36-rwvj

Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-43gr-9jjm-9rf2

An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43gq-7wp4-9vh5

plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43gp-phvm-pqvg

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-43gp-53vg-4cr3

CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43gp-2vcj-4vxj

Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу