Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wcq-hf94-333f

больше 4 лет назад

In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wcp-pwj7-fwmf

больше 1 года назад

Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3wcp-g7h4-2r32

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Moose Moose Elementor Kit allows DOM-Based XSS.This issue affects Moose Elementor Kit: from n/a through 1.0.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wcp-fjfh-pw9r

больше 4 лет назад

The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem".

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wcp-53mw-3rwq

21 день назад

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wcm-x9f4-v99q

больше 4 лет назад

MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

EPSS: Низкий
github логотип

GHSA-3wcm-vppv-p3q9

больше 4 лет назад

IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wcm-m2wj-fj25

больше 1 года назад

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3wcj-rg8q-9cqv

больше 4 лет назад

Open redirect in ASP.NET Core

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wcj-pc96-v578

около 1 года назад

A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wcj-gjvf-fvch

около 2 месяцев назад

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wcj-f5mq-gxw2

больше 4 лет назад

Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wch-cp8h-4vh3

больше 4 лет назад

Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wch-6hwj-h7f9

около 2 месяцев назад

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wch-675q-fgx7

18 дней назад

In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use after free In dma_release_channel(), check chan->device->privatecnt after call dma_chan_put(). However, dma_chan_put() call dma_device_put() which could release the last reference of the device if the DMA provider is already gone and hence free it. Fixes it by moving dma_chan_put() after the check.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wch-5xm2-547f

около 2 лет назад

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3wcg-3hq8-89r6

больше 4 лет назад

Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wcf-94mw-cwgf

4 дня назад

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wcf-84jq-4rxx

больше 2 лет назад

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the path '/pdf'.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wcf-67jh-m3g8

больше 4 лет назад

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20."

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wcq-hf94-333f

In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcp-pwj7-fwmf

Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.

CVSS3: 7.2
2%
Низкий
больше 1 года назад
github логотип
GHSA-3wcp-g7h4-2r32

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Moose Moose Elementor Kit allows DOM-Based XSS.This issue affects Moose Elementor Kit: from n/a through 1.0.0.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wcp-fjfh-pw9r

The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem".

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcp-53mw-3rwq

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
21 день назад
github логотип
GHSA-3wcm-x9f4-v99q

MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcm-vppv-p3q9

IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcm-m2wj-fj25

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 7.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-3wcj-rg8q-9cqv

Open redirect in ASP.NET Core

CVSS3: 8.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcj-pc96-v578

A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wcj-gjvf-fvch

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior.

CVSS3: 4.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3wcj-f5mq-gxw2

Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wch-cp8h-4vh3

Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.

CVSS3: 9.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3wch-6hwj-h7f9

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3wch-675q-fgx7

In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use after free In dma_release_channel(), check chan->device->privatecnt after call dma_chan_put(). However, dma_chan_put() call dma_device_put() which could release the last reference of the device if the DMA provider is already gone and hence free it. Fixes it by moving dma_chan_put() after the check.

CVSS3: 7.8
0%
Низкий
18 дней назад
github логотип
GHSA-3wch-5xm2-547f

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.

CVSS3: 9.9
2%
Низкий
около 2 лет назад
github логотип
GHSA-3wcg-3hq8-89r6

Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wcf-94mw-cwgf

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

CVSS3: 7.5
0%
Низкий
4 дня назад
github логотип
GHSA-3wcf-84jq-4rxx

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the path '/pdf'.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3wcf-67jh-m3g8

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20."

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу