Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3x4g-259h-5p7c

4 месяца назад

AMF Improperly Restricts Operations within the Bounds of a Memory Buffer

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x4f-24vq-5mhp

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3x4c-pq33-4w3q

около 5 лет назад

Improper authorisation of members discloses room membership to non-members

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x4c-7xq6-9pq8

6 месяцев назад

Next.js: Unbounded next/image disk cache growth can exhaust storage

EPSS: Низкий
github логотип

GHSA-3x49-p9xf-cg52

больше 4 лет назад

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

EPSS: Низкий
github логотип

GHSA-3x49-h2mv-h459

больше 1 года назад

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3x49-g6rc-c284

больше 3 лет назад

LiteDB may deserialize bad JSON on object type using _type

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x48-c5fq-3p9x

почти 2 года назад

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x48-6948-gjj7

больше 4 лет назад

Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

EPSS: Низкий
github логотип

GHSA-3x47-w4rx-6pm7

около 2 лет назад

LoLLMS Path Traversal vulnerability

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3x47-pxw6-fmvq

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x47-j85r-45r9

больше 4 лет назад

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x47-hh2w-gf29

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3x46-vw5g-qxj4

больше 4 лет назад

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

EPSS: Низкий
github логотип

GHSA-3x46-hg82-953f

около 4 лет назад

A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x46-fhq4-2cp2

больше 3 лет назад

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x46-c2g7-344x

больше 2 лет назад

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3x46-6xw6-vv9h

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3x46-395m-v3qc

больше 3 лет назад

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x46-2jq5-628v

больше 4 лет назад

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x4g-259h-5p7c

AMF Improperly Restricts Operations within the Bounds of a Memory Buffer

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3x4f-24vq-5mhp

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3x4c-pq33-4w3q

Improper authorisation of members discloses room membership to non-members

CVSS3: 3.1
1%
Низкий
около 5 лет назад
github логотип
GHSA-3x4c-7xq6-9pq8

Next.js: Unbounded next/image disk cache growth can exhaust storage

1%
Низкий
6 месяцев назад
github логотип
GHSA-3x49-p9xf-cg52

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3x49-h2mv-h459

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x49-g6rc-c284

LiteDB may deserialize bad JSON on object type using _type

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x48-c5fq-3p9x

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3x48-6948-gjj7

Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3x47-w4rx-6pm7

LoLLMS Path Traversal vulnerability

CVSS3: 9.8
28%
Средний
около 2 лет назад
github логотип
GHSA-3x47-pxw6-fmvq

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3x47-j85r-45r9

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3x47-hh2w-gf29

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-3x46-vw5g-qxj4

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3x46-hg82-953f

A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3x46-fhq4-2cp2

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x46-c2g7-344x

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

CVSS3: 8.8
13%
Средний
больше 2 лет назад
github логотип
GHSA-3x46-6xw6-vv9h

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-3x46-395m-v3qc

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x46-2jq5-628v

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

20%
Средний
больше 4 лет назад

Уязвимостей на страницу