Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 363 419

Количество 363 419

github логотип

GHSA-3m3x-cxhv-x999

больше 4 лет назад

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m3x-8r3c-954w

больше 1 года назад

The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3m3w-vxfv-jm2w

3 месяца назад

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3m3v-xv6x-mhqh

больше 2 лет назад

In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3m3v-363x-rf9h

около 2 месяцев назад

Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3m3r-vcpm-3xvw

больше 4 лет назад

The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m3r-f94v-4mf8

около 2 месяцев назад

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m3r-82gc-53mj

больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Mojarra

EPSS: Низкий
github логотип

GHSA-3m3q-x3gj-f79x

6 месяцев назад

OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3m3m-q3hw-6qq6

больше 2 лет назад

The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3m3m-h7hm-44xx

больше 4 лет назад

Directory traversal vulnerability in Widcomm Bluetooth for Windows (BTW) 3.0.1.905 allows remote attackers to conduct unauthorized file operations via a .. (dot dot) in an unspecified parameter.

EPSS: Низкий
github логотип

GHSA-3m3m-fw9q-ff94

больше 4 лет назад

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

EPSS: Средний
github логотип

GHSA-3m3m-6r6c-8m58

больше 4 лет назад

Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

EPSS: Низкий
github логотип

GHSA-3m3j-wxmw-vm2c

почти 3 года назад

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file update.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-239354 is the identifier assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m3j-jxfh-jw6m

9 месяцев назад

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

EPSS: Низкий
github логотип

GHSA-3m3j-g6jr-6c5m

больше 2 лет назад

A vulnerability has been found in DedeCMS 5.7.112-UTF8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file update_guide.php. The manipulation of the argument files leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260473 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m3j-3mx3-jmxc

больше 3 лет назад

Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3m3h-v9hv-9j4h

больше 4 лет назад

Cross-site Scripting in django-wiki

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3m3h-4jjr-fc29

10 месяцев назад

Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3m3g-56cx-59q7

4 месяца назад

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3m3x-cxhv-x999

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3m3x-8r3c-954w

The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3m3w-vxfv-jm2w

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3m3v-xv6x-mhqh

In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3m3v-363x-rf9h

Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3m3r-vcpm-3xvw

The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m3r-f94v-4mf8

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3m3r-82gc-53mj

Improper Neutralization of Input During Web Page Generation in Mojarra

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3m3q-x3gj-f79x

OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations

CVSS3: 5.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-3m3m-q3hw-6qq6

The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3m3m-h7hm-44xx

Directory traversal vulnerability in Widcomm Bluetooth for Windows (BTW) 3.0.1.905 allows remote attackers to conduct unauthorized file operations via a .. (dot dot) in an unspecified parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m3m-fw9q-ff94

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

50%
Средний
больше 4 лет назад
github логотип
GHSA-3m3m-6r6c-8m58

Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3m3j-wxmw-vm2c

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file update.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-239354 is the identifier assigned to this vulnerability.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3m3j-jxfh-jw6m

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

1%
Низкий
9 месяцев назад
github логотип
GHSA-3m3j-g6jr-6c5m

A vulnerability has been found in DedeCMS 5.7.112-UTF8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file update_guide.php. The manipulation of the argument files leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260473 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3m3j-3mx3-jmxc

Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.

CVSS3: 4.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m3h-v9hv-9j4h

Cross-site Scripting in django-wiki

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m3h-4jjr-fc29

Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting a malicious payload through the creation of a transcript that is sent by email. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3m3g-56cx-59q7

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу