Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3w6x-7r98-7q22

6 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax FormGent formgent allows Path Traversal.This issue affects FormGent: from n/a through <= 1.4.2.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3w6x-2g7m-8v23

4 месяца назад

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w6w-r9vq-3r79

больше 2 лет назад

Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3w6w-q6rh-xhgj

больше 2 лет назад

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w6w-3mq9-wprw

3 месяца назад

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3w6w-26ch-mqc9

больше 4 лет назад

SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.

EPSS: Низкий
github логотип

GHSA-3w6v-h5wr-h9rh

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w6v-5j67-jj7h

почти 3 года назад

An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w6r-r33r-cfg6

2 месяца назад

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3w6q-rqw9-h6qx

10 месяцев назад

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3w6q-chqr-4j8j

больше 4 лет назад

MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.

EPSS: Низкий
github логотип

GHSA-3w6q-cgc3-v6vv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

EPSS: Средний
github логотип

GHSA-3w6q-64v5-g7qw

14 дней назад

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w6p-qff7-qc9f

больше 4 лет назад

EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-reading restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3w6p-8f82-gw8r

больше 4 лет назад

Using JMSAppender in log4j configuration may lead to deserialization of untrusted data

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3w6m-x2x7-982w

больше 4 лет назад

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3w6m-h87r-x45q

больше 1 года назад

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The manipulation of the argument Notice leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3w6m-fc8w-97c4

больше 4 лет назад

Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

EPSS: Низкий
github логотип

GHSA-3w6j-gj2m-vh4c

больше 4 лет назад

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

EPSS: Низкий
github логотип

GHSA-3w6j-f4xj-hmhr

почти 4 года назад

xpdfreader 4.03 is vulnerable to Buffer Overflow.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w6x-7r98-7q22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax FormGent formgent allows Path Traversal.This issue affects FormGent: from n/a through <= 1.4.2.

CVSS3: 8.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-3w6x-2g7m-8v23

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

CVSS3: 6.5
1%
Низкий
4 месяца назад
github логотип
GHSA-3w6w-r9vq-3r79

Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w6w-q6rh-xhgj

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3w6w-3mq9-wprw

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3w6w-26ch-mqc9

SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6v-h5wr-h9rh

Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-3w6v-5j67-jj7h

An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3w6r-r33r-cfg6

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys.

CVSS3: 9.6
1%
Низкий
2 месяца назад
github логотип
GHSA-3w6q-rqw9-h6qx

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).

CVSS3: 3.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3w6q-chqr-4j8j

MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6q-cgc3-v6vv

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

11%
Средний
больше 4 лет назад
github логотип
GHSA-3w6q-64v5-g7qw

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
0%
Низкий
14 дней назад
github логотип
GHSA-3w6p-qff7-qc9f

EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-reading restrictions via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6p-8f82-gw8r

Using JMSAppender in log4j configuration may lead to deserialization of untrusted data

CVSS3: 8.1
больше 4 лет назад
github логотип
GHSA-3w6m-x2x7-982w

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6m-h87r-x45q

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The manipulation of the argument Notice leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3w6m-fc8w-97c4

Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6j-gj2m-vh4c

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6j-f4xj-hmhr

xpdfreader 4.03 is vulnerable to Buffer Overflow.

CVSS3: 7.5
1%
Низкий
почти 4 года назад

Уязвимостей на страницу