Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 328

Количество 362 328

github логотип

GHSA-3h6c-6qpq-hv5j

почти 2 года назад

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3h69-hjjf-qcc3

почти 3 года назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <= 0.2.3 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h69-fjjv-586m

больше 4 лет назад

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3h69-8qf2-5hg7

около 1 года назад

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php files can be uploaded and included.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h69-7jmr-q5h4

больше 4 лет назад

AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

EPSS: Низкий
github логотип

GHSA-3h69-4frw-g2jm

около 4 лет назад

Magento 2 Community Unrestricted File Upload

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h68-wvv6-8r5h

больше 4 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h67-wjhc-r8m7

больше 4 лет назад

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h67-j53j-m22p

около 1 года назад

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3h67-9pvc-gvv9

больше 4 лет назад

updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.

EPSS: Низкий
github логотип

GHSA-3h67-94ff-4pcq

6 месяцев назад

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h67-687r-7fpc

около 1 года назад

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

EPSS: Низкий
github логотип

GHSA-3h66-9xgh-v229

около 1 года назад

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h66-68qg-wvwr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

EPSS: Низкий
github логотип

GHSA-3h65-qwh5-2r5j

3 месяца назад

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to extract sensitive database information including the current user, database name, and DBMS version.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3h65-qjq4-488h

около 3 лет назад

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h65-3mjq-qqj8

больше 4 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h64-fx5v-2f3q

8 месяцев назад

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server via the 'current_user_avatar' parameter in a two-stage attack which can make remote code execution possible. This only affects sites with the custom avatar setting enabled.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3h64-ff22-jvm6

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Set video drvdata before register video device The video drvdata should be set before the video device is registered, otherwise video_drvdata() may return NULL in the open() file ops, and led to oops.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h64-25x5-v8wv

больше 4 лет назад

Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h6c-6qpq-hv5j

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3h69-hjjf-qcc3

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <= 0.2.3 versions.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3h69-fjjv-586m

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVSS3: 9.8
40%
Средний
больше 4 лет назад
github логотип
GHSA-3h69-8qf2-5hg7

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php files can be uploaded and included.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3h69-7jmr-q5h4

AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h69-4frw-g2jm

Magento 2 Community Unrestricted File Upload

CVSS3: 7.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-3h68-wvv6-8r5h

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3h67-wjhc-r8m7

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h67-j53j-m22p

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3h67-9pvc-gvv9

updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3h67-94ff-4pcq

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

CVSS3: 7.2
1%
Низкий
6 месяцев назад
github логотип
GHSA-3h67-687r-7fpc

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

6%
Низкий
около 1 года назад
github логотип
GHSA-3h66-9xgh-v229

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-3h66-68qg-wvwr

Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h65-qwh5-2r5j

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to extract sensitive database information including the current user, database name, and DBMS version.

CVSS3: 8.2
0%
Низкий
3 месяца назад
github логотип
GHSA-3h65-qjq4-488h

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-3h65-3mjq-qqj8

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h64-fx5v-2f3q

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server via the 'current_user_avatar' parameter in a two-stage attack which can make remote code execution possible. This only affects sites with the custom avatar setting enabled.

CVSS3: 6.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-3h64-ff22-jvm6

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Set video drvdata before register video device The video drvdata should be set before the video device is registered, otherwise video_drvdata() may return NULL in the open() file ops, and led to oops.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h64-25x5-v8wv

Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу