Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43fr-qgqj-789v

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43fr-jpf5-3wcf

больше 4 лет назад

Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer overflows, which may lead to remote code execution.

EPSS: Низкий
github логотип

GHSA-43fr-2m4w-5h7x

6 месяцев назад

The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input sanitization and output escaping on the 'client' shortcode attribute. The ad_func() shortcode handler at line 71 accepts a 'client' attribute via shortcode_atts() and directly concatenates it into a double-quoted HTML attribute (data-ad-client) at line 130 without applying esc_attr() or any other sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-43fq-w8qq-v88h

около 6 лет назад

Out-of-bounds read in Pillow

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-43fq-73ph-565p

5 месяцев назад

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43fp-vwwg-qgv6

больше 7 лет назад

Apache NiFi Improper Input Validation vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43fp-rhv2-5gv8

больше 3 лет назад

Certifi removing TrustCor root certificate

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43fp-fmc5-45qr

больше 4 лет назад

Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.

EPSS: Низкий
github логотип

GHSA-43fm-wrjr-xr6x

около 1 года назад

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-43fm-r495-g6gq

больше 4 лет назад

The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows local privilege escalation via a race condition in logrotate. By using an exploit chain, an attacker with access to the network can get root access on the gateway.

EPSS: Низкий
github логотип

GHSA-43fm-mhm5-jf78

больше 4 лет назад

Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

EPSS: Низкий
github логотип

GHSA-43fm-hvcc-q6xw

18 дней назад

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-43fm-9f2q-hw2w

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWave Hide My WP hide_my_wp allows Reflected XSS.This issue affects Hide My WP: from n/a through <= 6.2.12.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43fm-84hp-5r6r

больше 4 лет назад

Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-43fm-4vqq-x9qh

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) USRLNM parameter to myaccount/mysettings.edit.validate.asp or the frame parameter to (2) iframe.picker.statchannels.asp, (3) iframe.picker.channelgroups.asp, (4) iframe.picker.extensions.asp, (5) iframe.picker.licenseusergroups.asp, (6) iframe.picker.licenseusers.asp, (7) iframe.picker.lookup.asp, or (8) iframe.picker.marks.asp in _ifr/.

EPSS: Низкий
github логотип

GHSA-43fj-qp3h-hrh5

5 месяцев назад

Sync-in Server has Username Enumeration via Timing Attack

EPSS: Низкий
github логотип

GHSA-43fj-2mp7-xmm4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-43fh-63xp-xhfw

больше 1 года назад

Missing Authorization vulnerability in Flothemes Flo Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flo Forms: from n/a through 1.0.41.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-43fh-5xpm-3q9m

3 месяца назад

Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43fg-2qr4-qfpx

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deshine Video Gallery by Huzzaz huzzaz-video-gallery allows Stored XSS.This issue affects Video Gallery by Huzzaz: from n/a through <= 10.5.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43fr-qgqj-789v

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-43fr-jpf5-3wcf

Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer overflows, which may lead to remote code execution.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-43fr-2m4w-5h7x

The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input sanitization and output escaping on the 'client' shortcode attribute. The ad_func() shortcode handler at line 71 accepts a 'client' attribute via shortcode_atts() and directly concatenates it into a double-quoted HTML attribute (data-ad-client) at line 130 without applying esc_attr() or any other sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-43fq-w8qq-v88h

Out-of-bounds read in Pillow

CVSS3: 8.1
3%
Низкий
около 6 лет назад
github логотип
GHSA-43fq-73ph-565p

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-43fp-vwwg-qgv6

Apache NiFi Improper Input Validation vulnerability

CVSS3: 7.5
3%
Низкий
больше 7 лет назад
github логотип
GHSA-43fp-rhv2-5gv8

Certifi removing TrustCor root certificate

CVSS3: 6.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43fp-fmc5-45qr

Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43fm-wrjr-xr6x

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.

CVSS3: 9.1
1%
Низкий
около 1 года назад
github логотип
GHSA-43fm-r495-g6gq

The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows local privilege escalation via a race condition in logrotate. By using an exploit chain, an attacker with access to the network can get root access on the gateway.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43fm-mhm5-jf78

Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43fm-hvcc-q6xw

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

CVSS3: 7.3
0%
Низкий
18 дней назад
github логотип
GHSA-43fm-9f2q-hw2w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWave Hide My WP hide_my_wp allows Reflected XSS.This issue affects Hide My WP: from n/a through <= 6.2.12.

CVSS3: 6.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-43fm-84hp-5r6r

Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.

CVSS3: 7.5
64%
Средний
больше 4 лет назад
github логотип
GHSA-43fm-4vqq-x9qh

Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) USRLNM parameter to myaccount/mysettings.edit.validate.asp or the frame parameter to (2) iframe.picker.statchannels.asp, (3) iframe.picker.channelgroups.asp, (4) iframe.picker.extensions.asp, (5) iframe.picker.licenseusergroups.asp, (6) iframe.picker.licenseusers.asp, (7) iframe.picker.lookup.asp, or (8) iframe.picker.marks.asp in _ifr/.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43fj-qp3h-hrh5

Sync-in Server has Username Enumeration via Timing Attack

0%
Низкий
5 месяцев назад
github логотип
GHSA-43fj-2mp7-xmm4

Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43fh-63xp-xhfw

Missing Authorization vulnerability in Flothemes Flo Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flo Forms: from n/a through 1.0.41.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-43fh-5xpm-3q9m

Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-43fg-2qr4-qfpx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deshine Video Gallery by Huzzaz huzzaz-video-gallery allows Stored XSS.This issue affects Video Gallery by Huzzaz: from n/a through <= 10.5.

CVSS3: 5.4
0%
Низкий
10 месяцев назад

Уязвимостей на страницу