Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wwc-wj68-5rvm

больше 4 лет назад

Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

EPSS: Низкий
github логотип

GHSA-3wwc-jjmg-r6gq

почти 3 года назад

Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3wwc-8979-r93x

больше 4 лет назад

CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

EPSS: Низкий
github логотип

GHSA-3ww9-jwr8-mpg3

почти 4 года назад

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3ww9-9g46-xw9x

около 1 месяца назад

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3ww8-jw56-9f5h

5 месяцев назад

FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3ww8-8v8c-wrr2

около 4 лет назад

In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3ww8-82c8-5vpr

больше 4 лет назад

Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification.

EPSS: Низкий
github логотип

GHSA-3ww7-w2h2-5c4x

больше 4 лет назад

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ww7-qxrg-gc3h

больше 4 лет назад

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.

EPSS: Низкий
github логотип

GHSA-3ww7-mwq4-x3gc

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3ww7-mpcv-cwwh

больше 4 лет назад

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3ww7-h83j-f3rc

около 2 лет назад

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3ww5-qm6q-xhcg

больше 1 года назад

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3ww4-hpff-r8mv

больше 4 лет назад

Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

EPSS: Низкий
github логотип

GHSA-3ww4-gg4f-jr7f

больше 2 лет назад

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ww4-cp53-6g2x

почти 5 лет назад

Cross Site Request Forgery in kindeditor

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ww4-5jv9-j5gm

3 месяца назад

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3ww4-5h8f-6c2q

больше 4 лет назад

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.

EPSS: Низкий
github логотип

GHSA-3ww4-528c-xcv7

7 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wwc-wj68-5rvm

Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3wwc-jjmg-r6gq

Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3wwc-8979-r93x

CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww9-jwr8-mpg3

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-3ww9-9g46-xw9x

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3ww8-jw56-9f5h

FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing

CVSS3: 5.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3ww8-8v8c-wrr2

In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-3ww8-82c8-5vpr

Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww7-w2h2-5c4x

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww7-qxrg-gc3h

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww7-mwq4-x3gc

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-3ww7-mpcv-cwwh

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww7-h83j-f3rc

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS3: 5.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3ww5-qm6q-xhcg

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3ww4-hpff-r8mv

Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww4-gg4f-jr7f

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3ww4-cp53-6g2x

Cross Site Request Forgery in kindeditor

CVSS3: 8.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-3ww4-5jv9-j5gm

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3ww4-5h8f-6c2q

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww4-528c-xcv7

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.

CVSS3: 5.5
0%
Низкий
7 месяцев назад

Уязвимостей на страницу