Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-3r5c-2xxx-h872

около 1 месяца назад

Gitea: Webhook Authorization Header Returned in Plaintext via API

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3r58-xjch-5xjp

больше 2 лет назад

The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3r58-vgpx-8w42

больше 4 лет назад

Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.

EPSS: Низкий
github логотип

GHSA-3r58-6hw4-672v

около 2 лет назад

A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3r57-cvmr-xwg9

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3r56-xx7r-cr9c

6 месяцев назад

Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r56-gc76-cxqc

больше 1 года назад

Missing Authorization vulnerability in Brady Vercher Cue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cue: from n/a through 2.4.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3r56-7hhr-vfg9

4 месяца назад

Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3r56-5r55-j5mh

больше 1 года назад

An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.

EPSS: Низкий
github логотип

GHSA-3r55-8c76-hvc2

больше 3 лет назад

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r54-xjq4-jwjm

13 дней назад

A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3r53-w9gm-6mc6

больше 4 лет назад

The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.

EPSS: Низкий
github логотип

GHSA-3r53-83gh-9p5m

больше 4 лет назад

Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.

EPSS: Средний
github логотип

GHSA-3r53-75j5-3g7j

около 1 месяца назад

Quasar: Prototype pollution in the extend() utility

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3r52-vc36-mfv6

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.

EPSS: Низкий
github логотип

GHSA-3r52-r3h6-pp5w

около 4 лет назад

Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r52-h47w-2p2j

10 месяцев назад

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later retrieved in the `DMZ_run` function of `librcm.so` using `nvram_safe_get` and concatenated into `iptables` shell commands executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r52-23hx-qw5v

больше 4 лет назад

Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-3r4x-v5v7-fm2r

7 дней назад

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code or pre element text to break the inline span, causing sanitized HTML to be emitted unescaped and re-parsed as live Markdown by compliant renderers.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3r4x-4pr5-j666

5 месяцев назад

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r5c-2xxx-h872

Gitea: Webhook Authorization Header Returned in Plaintext via API

CVSS3: 2.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r58-xjch-5xjp

The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3r58-vgpx-8w42

Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3r58-6hw4-672v

A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-3r57-cvmr-xwg9

Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r56-xx7r-cr9c

Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3r56-gc76-cxqc

Missing Authorization vulnerability in Brady Vercher Cue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cue: from n/a through 2.4.4.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3r56-7hhr-vfg9

Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

CVSS3: 7.7
4 месяца назад
github логотип
GHSA-3r56-5r55-j5mh

An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.

0%
Низкий
больше 1 года назад
github логотип
GHSA-3r55-8c76-hvc2

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.

CVSS3: 5.4
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3r54-xjq4-jwjm

A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
0%
Низкий
13 дней назад
github логотип
GHSA-3r53-w9gm-6mc6

The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3r53-83gh-9p5m

Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.

38%
Средний
больше 4 лет назад
github логотип
GHSA-3r53-75j5-3g7j

Quasar: Prototype pollution in the extend() utility

CVSS3: 5.6
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r52-vc36-mfv6

Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3r52-r3h6-pp5w

Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-3r52-h47w-2p2j

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later retrieved in the `DMZ_run` function of `librcm.so` using `nvram_safe_get` and concatenated into `iptables` shell commands executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.

CVSS3: 6.5
3%
Низкий
10 месяцев назад
github логотип
GHSA-3r52-23hx-qw5v

Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r4x-v5v7-fm2r

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code or pre element text to break the inline span, causing sanitized HTML to be emitted unescaped and re-parsed as live Markdown by compliant renderers.

CVSS3: 6.1
0%
Низкий
7 дней назад
github логотип
GHSA-3r4x-4pr5-j666

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.

CVSS3: 5.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу