Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43ff-rr26-8hx4

11 месяцев назад

OpenSearch Data Prepper plugins trust all SSL certificates by default

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-43ff-jh97-jcx5

больше 4 лет назад

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary commands in the local database.

EPSS: Низкий
github логотип

GHSA-43ff-74cr-2r98

больше 1 года назад

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43ff-4wjr-j993

больше 4 лет назад

An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump does not require authentication if the pump is configured to allow FTP connections.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-43ff-2vc5-g28f

больше 4 лет назад

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43fc-v873-qw85

около 2 месяцев назад

Waku has an Open Redirect via `unstable_redirect` Helper

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-43fc-v55w-5mx4

больше 2 лет назад

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. 

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-43fc-qcr8-6g6r

больше 4 лет назад

Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.

EPSS: Низкий
github логотип

GHSA-43fc-jf86-j433

7 месяцев назад

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43fc-fqg5-m549

почти 2 года назад

The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including, 7.1.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-43f9-pjg6-9rw4

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php.

EPSS: Низкий
github логотип

GHSA-43f9-2fj2-35xm

больше 4 лет назад

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-43f8-p5w3-5m25

больше 5 лет назад

vrana/adminer vulnerable to SSRF by connecting to privileged ports

EPSS: Низкий
github логотип

GHSA-43f8-j7wq-qhwm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43f8-f3f2-rc3j

7 месяцев назад

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application does not enforce role-based access control on this function, allowing a standard user to submit a crafted POST request to /jsonrpc/management specifying another username to have that account removed without elevated permissions or additional confirmation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43f8-2h32-f4cj

больше 5 лет назад

Regular Expression Denial of Service in hosted-git-info

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43f7-xpq7-4gc9

почти 5 лет назад

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43f7-fp52-3g5h

больше 4 лет назад

The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.

EPSS: Низкий
github логотип

GHSA-43f7-4mcw-62jx

больше 4 лет назад

The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43f6-crvm-c3cv

больше 4 лет назад

Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43ff-rr26-8hx4

OpenSearch Data Prepper plugins trust all SSL certificates by default

CVSS3: 7.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-43ff-jh97-jcx5

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary commands in the local database.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43ff-74cr-2r98

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-43ff-4wjr-j993

An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump does not require authentication if the pump is configured to allow FTP connections.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43ff-2vc5-g28f

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43fc-v873-qw85

Waku has an Open Redirect via `unstable_redirect` Helper

CVSS3: 3.1
около 2 месяцев назад
github логотип
GHSA-43fc-v55w-5mx4

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high. 

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43fc-qcr8-6g6r

Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

CVSS3: 7.5
3%
Низкий
7 месяцев назад
github логотип
GHSA-43fc-fqg5-m549

The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including, 7.1.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-43f9-pjg6-9rw4

Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f9-2fj2-35xm

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f8-p5w3-5m25

vrana/adminer vulnerable to SSRF by connecting to privileged ports

4%
Низкий
больше 5 лет назад
github логотип
GHSA-43f8-j7wq-qhwm

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43f8-f3f2-rc3j

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application does not enforce role-based access control on this function, allowing a standard user to submit a crafted POST request to /jsonrpc/management specifying another username to have that account removed without elevated permissions or additional confirmation.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-43f8-2h32-f4cj

Regular Expression Denial of Service in hosted-git-info

CVSS3: 5.3
4%
Низкий
больше 5 лет назад
github логотип
GHSA-43f7-xpq7-4gc9

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

CVSS3: 7.8
2%
Низкий
почти 5 лет назад
github логотип
GHSA-43f7-fp52-3g5h

The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f7-4mcw-62jx

The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f6-crvm-c3cv

Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

CVSS3: 4.6
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу