Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-xr9q-85p6-f6xr

около 1 года назад

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9p-wqhw-3w78

больше 4 лет назад

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.

EPSS: Низкий
github логотип

GHSA-xr9p-qj4x-c6c7

больше 4 лет назад

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

EPSS: Низкий
github логотип

GHSA-xr9p-mfhc-2mwc

больше 4 лет назад

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter.

EPSS: Средний
github логотип

GHSA-xr9m-gphc-9p63

26 дней назад

Snipe-IT has a path traversal vulnerability via CSV import `image` field

EPSS: Низкий
github логотип

GHSA-xr9m-34vg-p986

больше 4 лет назад

The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.

EPSS: Низкий
github логотип

GHSA-xr9j-c7v6-7542

почти 3 года назад

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr9j-92x7-g2w2

больше 4 лет назад

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr9j-2jxx-p2h8

8 месяцев назад

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9h-p2rc-rpqm

больше 3 лет назад

WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xr9h-fv82-7r7g

11 месяцев назад

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr9h-9m79-x29g

больше 5 лет назад

SSRF in Rendertron

EPSS: Низкий
github логотип

GHSA-xr9g-g7xh-rw7g

больше 4 лет назад

The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.

EPSS: Низкий
github логотип

GHSA-xr9g-f9v2-9m3h

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr9f-3r4j-v7r6

около 2 лет назад

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr9c-w7f8-3p75

почти 3 года назад

The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9c-3v5w-98m9

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Push Envoy Notifications allows Reflected XSS. This issue affects Push Envoy Notifications: from n/a through 1.0.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xr99-q8hp-qjj7

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_event_alarm, at 0x9d01eb8c, the value for the `s_event_group` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xr99-79r8-rjm6

2 месяца назад

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xr99-57mh-xrxf

больше 4 лет назад

Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr9q-85p6-f6xr

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xr9p-wqhw-3w78

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9p-qj4x-c6c7

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9p-mfhc-2mwc

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter.

22%
Средний
больше 4 лет назад
github логотип
GHSA-xr9m-gphc-9p63

Snipe-IT has a path traversal vulnerability via CSV import `image` field

1%
Низкий
26 дней назад
github логотип
GHSA-xr9m-34vg-p986

The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9j-c7v6-7542

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges.

CVSS3: 8.8
9%
Низкий
почти 3 года назад
github логотип
GHSA-xr9j-92x7-g2w2

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9j-2jxx-p2h8

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xr9h-p2rc-rpqm

WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xr9h-fv82-7r7g

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xr9h-9m79-x29g

SSRF in Rendertron

0%
Низкий
больше 5 лет назад
github логотип
GHSA-xr9g-g7xh-rw7g

The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9g-f9v2-9m3h

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr9f-3r4j-v7r6

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr9c-w7f8-3p75

The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xr9c-3v5w-98m9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Push Envoy Notifications allows Reflected XSS. This issue affects Push Envoy Notifications: from n/a through 1.0.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr99-q8hp-qjj7

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_event_alarm, at 0x9d01eb8c, the value for the `s_event_group` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xr99-79r8-rjm6

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-xr99-57mh-xrxf

Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1.

CVSS3: 4.9
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу