Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-4378-f9mm-5685

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4377-w6r6-fpff

почти 2 года назад

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-4377-hq3v-hgqh

больше 3 лет назад

In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220733496

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4377-g9q2-3wh5

около 1 года назад

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4376-ff9v-5wj2

15 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-4376-93v6-4h5m

больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-4375-54m2-mm7p

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by adding specific strings to multiple configuration fields. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4374-q6w2-q795

больше 1 года назад

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4374-p667-p6c8

почти 3 года назад

HTTP/2 rapid reset can cause excessive work in net/http

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4374-j4qr-5p28

больше 4 лет назад

components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.

EPSS: Низкий
github логотип

GHSA-4374-6xfq-3wjw

7 месяцев назад

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4374-5gxx-h9r3

больше 3 лет назад

Microsoft Exchange Server Information Disclosure Vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4373-qwqg-vgwm

больше 4 лет назад

Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.

EPSS: Средний
github логотип

GHSA-4373-44w4-v53r

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4372-pgmc-78wq

больше 3 лет назад

Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-436x-j7j9-9jv7

около 3 лет назад

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-436x-9fhf-jq78

больше 4 лет назад

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

EPSS: Средний
github логотип

GHSA-436w-wv2w-q46v

больше 4 лет назад

An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

EPSS: Низкий
github логотип

GHSA-436v-rwrw-9mfh

больше 4 лет назад

Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.

EPSS: Низкий
github логотип

GHSA-436v-jg82-p533

7 месяцев назад

Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4378-f9mm-5685

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-4377-w6r6-fpff

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

CVSS3: 6.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-4377-hq3v-hgqh

In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220733496

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4377-g9q2-3wh5

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-4376-ff9v-5wj2

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

15 дней назад
github логотип
GHSA-4376-93v6-4h5m

A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4375-54m2-mm7p

A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by adding specific strings to multiple configuration fields. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4374-q6w2-q795

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4374-p667-p6c8

HTTP/2 rapid reset can cause excessive work in net/http

CVSS3: 7.5
4%
Низкий
почти 3 года назад
github логотип
GHSA-4374-j4qr-5p28

components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4374-6xfq-3wjw

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.

CVSS3: 9.8
5%
Низкий
7 месяцев назад
github логотип
GHSA-4374-5gxx-h9r3

Microsoft Exchange Server Information Disclosure Vulnerability.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-4373-qwqg-vgwm

Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.

33%
Средний
больше 4 лет назад
github логотип
GHSA-4373-44w4-v53r

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-4372-pgmc-78wq

Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-436x-j7j9-9jv7

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-436x-9fhf-jq78

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

20%
Средний
больше 4 лет назад
github логотип
GHSA-436w-wv2w-q46v

An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

0%
Низкий
больше 4 лет назад
github логотип
GHSA-436v-rwrw-9mfh

Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-436v-jg82-p533

Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE

CVSS3: 9.8
2%
Низкий
7 месяцев назад

Уязвимостей на страницу