Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 363 419

Количество 363 419

github логотип

GHSA-3mhr-hwm3-pcr6

5 месяцев назад

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mhr-frr8-qmc6

больше 4 лет назад

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3mhr-8gcj-264p

больше 4 лет назад

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

EPSS: Низкий
github логотип

GHSA-3mhq-vj94-wvcw

около 4 лет назад

The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mhq-jqrv-fc88

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perform __free_pages(page, order) using this pointer as we would free any arbitrary pages. Fix this by stop modifying the page pointer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mhq-gg8j-mxrw

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mhq-4g6r-v5q4

больше 4 лет назад

A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mhp-fp4h-jm6r

больше 3 лет назад

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this issue is the function delete_brand of the file /admin/maintenance/brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-225338 is the identifier assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mhm-jvqj-fvhg

почти 6 лет назад

Malicious Package in js-sia3

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mhm-cc78-hw48

4 месяца назад

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn, ImageWDTColumn, and EmailWDTColumn classes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, given that they can trick an Administrator into importing data from an attacker-controlled source and the affected column types (Link, Image, or Email) are configured.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3mhh-v2cc-54m6

больше 4 лет назад

Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.

EPSS: Высокий
github логотип

GHSA-3mhh-q9gx-fwpr

больше 4 лет назад

DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.

EPSS: Низкий
github логотип

GHSA-3mhh-fjjv-vfrh

больше 2 лет назад

Azure Storage Mover Remote Code Execution Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3mhh-97mg-5hxp

около 1 месяца назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-3mhh-8825-8jw3

больше 4 лет назад

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mhg-xg79-hhx6

больше 3 лет назад

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file /classes/Master.php?f=delete_sub_category. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225345 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mhg-jrw2-wqwp

12 месяцев назад

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mhg-j5fx-98c7

больше 4 лет назад

Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

EPSS: Низкий
github логотип

GHSA-3mhg-g23j-g83p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.

EPSS: Низкий
github логотип

GHSA-3mhg-8478-5f87

больше 4 лет назад

SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mhr-hwm3-pcr6

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3mhr-frr8-qmc6

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.

CVSS3: 5.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhr-8gcj-264p

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhq-vj94-wvcw

The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3mhq-jqrv-fc88

In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perform __free_pages(page, order) using this pointer as we would free any arbitrary pages. Fix this by stop modifying the page pointer.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mhq-gg8j-mxrw

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3mhq-4g6r-v5q4

A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhp-fp4h-jm6r

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this issue is the function delete_brand of the file /admin/maintenance/brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-225338 is the identifier assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mhm-jvqj-fvhg

Malicious Package in js-sia3

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-3mhm-cc78-hw48

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn, ImageWDTColumn, and EmailWDTColumn classes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, given that they can trick an Administrator into importing data from an attacker-controlled source and the affected column types (Link, Image, or Email) are configured.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-3mhh-v2cc-54m6

Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.

78%
Высокий
больше 4 лет назад
github логотип
GHSA-3mhh-q9gx-fwpr

DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhh-fjjv-vfrh

Azure Storage Mover Remote Code Execution Vulnerability

CVSS3: 8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-3mhh-97mg-5hxp

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.

CVSS3: 2.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mhh-8825-8jw3

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhg-xg79-hhx6

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file /classes/Master.php?f=delete_sub_category. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225345 was assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mhg-jrw2-wqwp

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3mhg-j5fx-98c7

Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhg-g23j-g83p

Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhg-8478-5f87

SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу