Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hhp-286q-9r4c

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hhm-v674-2qc2

больше 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3hhm-c9rq-5x5x

больше 4 лет назад

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.

EPSS: Средний
github логотип

GHSA-3hhj-3rqm-6fp9

около 1 месяца назад

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by GeneralSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the General Settings page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3hhh-hv27-4gjh

больше 4 лет назад

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-3hhh-46fw-chvg

почти 2 года назад

DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3hhg-75h3-g9cw

больше 4 лет назад

Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.

EPSS: Средний
github логотип

GHSA-3hhg-38p8-799x

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Statsenko Terms descriptions terms-descriptions allows DOM-Based XSS.This issue affects Terms descriptions: from n/a through <= 3.4.9.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3hhf-g967-wcf6

больше 1 года назад

Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hhc-qp5v-9p2j

около 4 лет назад

Active Record RCE bug with Serialized Columns

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hhc-gfj2-qgg7

около 3 лет назад

Tablet Windows User Interface Application Core Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hhc-2692-pw9v

4 месяца назад

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

CVSS3: 6.2
EPSS: Средний
github логотип

GHSA-3hh9-wx4j-9h8m

больше 4 лет назад

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hh9-m6jx-r3jg

больше 2 лет назад

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hh9-hvm7-hpc8

почти 4 года назад

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3hh9-752g-5g22

3 месяца назад

LMCache: 16-bit multimodal hash collision can poison KV cache entries

CVSS3: 3.6
EPSS: Низкий
github логотип

GHSA-3hh9-649f-frq3

больше 4 лет назад

newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-3hh8-qg3m-6qv4

больше 4 лет назад

Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hh7-86f2-m64w

больше 3 лет назад

Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hh7-4gv3-gf58

больше 4 лет назад

The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hhp-286q-9r4c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hhm-v674-2qc2

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hhm-c9rq-5x5x

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.

36%
Средний
больше 4 лет назад
github логотип
GHSA-3hhj-3rqm-6fp9

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by GeneralSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the General Settings page.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hhh-hv27-4gjh

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.

CVSS3: 8
14%
Средний
больше 4 лет назад
github логотип
GHSA-3hhh-46fw-chvg

DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.

CVSS3: 8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3hhg-75h3-g9cw

Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.

18%
Средний
больше 4 лет назад
github логотип
GHSA-3hhg-38p8-799x

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Statsenko Terms descriptions terms-descriptions allows DOM-Based XSS.This issue affects Terms descriptions: from n/a through <= 3.4.9.

CVSS3: 4.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3hhf-g967-wcf6

Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hhc-qp5v-9p2j

Active Record RCE bug with Serialized Columns

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-3hhc-gfj2-qgg7

Tablet Windows User Interface Application Core Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3hhc-2692-pw9v

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

CVSS3: 6.2
26%
Средний
4 месяца назад
github логотип
GHSA-3hh9-wx4j-9h8m

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh9-m6jx-r3jg

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3hh9-hvm7-hpc8

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-3hh9-752g-5g22

LMCache: 16-bit multimodal hash collision can poison KV cache entries

CVSS3: 3.6
0%
Низкий
3 месяца назад
github логотип
GHSA-3hh9-649f-frq3

newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh8-qg3m-6qv4

Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh7-86f2-m64w

Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hh7-4gv3-gf58

The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу