Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-42m7-x4gf-gj25

около 3 лет назад

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42m7-jqh7-g85c

14 дней назад

Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name.

EPSS: Низкий
github логотип

GHSA-42m7-8557-x95x

почти 2 года назад

Windows Mobile Broadband Driver Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42m7-33x8-mvrh

почти 2 года назад

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42m6-xh7c-6xm4

3 месяца назад

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42m6-v976-v7cf

около 4 лет назад

A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42m6-mm85-f999

больше 4 лет назад

SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42m6-m8gm-pwp9

больше 4 лет назад

Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-42m6-m7p8-vqwv

9 месяцев назад

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application allows administrators to modify the server's network configuration through the Django application. This configuration is processed by Bash scripts (TSsetnoproxy and TSsetproxy) that write user-controlled data directly to environment variables without proper sanitization. After updating environment variables, the scripts execute a source command on /etc/environment; if an attacker injects malicious data into environment variables, this command can enable arbitrary command execution. The vulnerability begins with the /admin/network endpoint, which passes user-supplied form data as arguments to subprocess.Popen calls. The user-supplied input is then used to update environme...

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-42m6-g935-5vmq

около 4 лет назад

@ianwalter/merge Prototype Pollution via `merge` function

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-42m6-9p28-3cfp

больше 4 лет назад

Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.

EPSS: Низкий
github логотип

GHSA-42m6-7xff-9v9m

больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Jenkins

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-42m6-6jcq-4m5x

больше 4 лет назад

Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG layout.

EPSS: Низкий
github логотип

GHSA-42m6-5vm7-fjv2

около 1 года назад

Mattermost Confluence Plugin has Missing Authorization vulnerability

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-42m5-rf78-8h9x

около 3 лет назад

Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42m5-g3g4-g4j9

больше 4 лет назад

The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42m5-3r2p-wr92

10 месяцев назад

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

EPSS: Высокий
github логотип

GHSA-42m5-34mg-qrv6

больше 4 лет назад

cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42m4-q6r2-jh92

почти 3 года назад

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8.8, 3.9.3, and 3.10.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-42m4-gw8j-vjvg

около 2 лет назад

A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42m7-x4gf-gj25

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-42m7-jqh7-g85c

Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name.

0%
Низкий
14 дней назад
github логотип
GHSA-42m7-8557-x95x

Windows Mobile Broadband Driver Denial of Service Vulnerability

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-42m7-33x8-mvrh

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-42m6-xh7c-6xm4

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-42m6-v976-v7cf

A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-42m6-mm85-f999

SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-42m6-m8gm-pwp9

Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

25%
Средний
больше 4 лет назад
github логотип
GHSA-42m6-m7p8-vqwv

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application allows administrators to modify the server's network configuration through the Django application. This configuration is processed by Bash scripts (TSsetnoproxy and TSsetproxy) that write user-controlled data directly to environment variables without proper sanitization. After updating environment variables, the scripts execute a source command on /etc/environment; if an attacker injects malicious data into environment variables, this command can enable arbitrary command execution. The vulnerability begins with the /admin/network endpoint, which passes user-supplied form data as arguments to subprocess.Popen calls. The user-supplied input is then used to update environme...

CVSS3: 7.2
1%
Низкий
9 месяцев назад
github логотип
GHSA-42m6-g935-5vmq

@ianwalter/merge Prototype Pollution via `merge` function

CVSS3: 5.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-42m6-9p28-3cfp

Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-42m6-7xff-9v9m

Improper Neutralization of Input During Web Page Generation in Jenkins

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-42m6-6jcq-4m5x

Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG layout.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-42m6-5vm7-fjv2

Mattermost Confluence Plugin has Missing Authorization vulnerability

CVSS3: 3.7
0%
Низкий
около 1 года назад
github логотип
GHSA-42m5-rf78-8h9x

Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-42m5-g3g4-g4j9

The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-42m5-3r2p-wr92

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

73%
Высокий
10 месяцев назад
github логотип
GHSA-42m5-34mg-qrv6

cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-42m4-q6r2-jh92

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8.8, 3.9.3, and 3.10.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 4.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-42m4-gw8j-vjvg

A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.

CVSS3: 6.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу