Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-3f2f-2p2j-r4w2

больше 4 лет назад

The Buy 99 Cents Only Products (aka com.ww99CentsOnlyStores) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3f2c-xwqh-4w82

больше 4 лет назад

Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f2c-jm6v-cr35

больше 4 лет назад

Django DNS Rebinding Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3f29-xc6q-j293

больше 2 лет назад

LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyTemplateAll method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-19922.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3f29-pqwf-v4j4

4 месяца назад

Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f29-4g5p-wvc9

11 месяцев назад

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f29-39mf-32c5

больше 4 лет назад

Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3f29-2mxq-538c

около 4 лет назад

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1408, CVE-2019-1434.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f28-vrfj-2cwc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f28-8p95-qq7j

10 месяцев назад

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3f27-r52q-f7jv

больше 4 лет назад

The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a denial of service (panic) by triggering a fault, as demonstrated by an unaligned memory operand or a non-canonical address memory operand.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3f26-j6r7-9q8v

больше 1 года назад

In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3f26-hjxq-9434

7 месяцев назад

ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and cause a denial of service.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-3f26-8r72-46wh

около 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress allows Upload a Web Shell to a Web Server. This issue affects File Manager Plugin For Wordpress: from n/a through 7.5.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3f26-542m-36hv

около 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

EPSS: Низкий
github логотип

GHSA-3f25-9wj6-fhrv

больше 4 лет назад

Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, does not properly check a buffer during an IOCTL 0x9c402420 call, which allows local users to cause a denial of service (machine crash) and possibly gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3f24-pcvm-5jqc

5 месяцев назад

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3f24-8wqg-chhj

почти 2 года назад

Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3f24-4xhj-mpvj

около 2 лет назад

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272582 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3f23-79pf-grrm

больше 2 лет назад

The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f2f-2p2j-r4w2

The Buy 99 Cents Only Products (aka com.ww99CentsOnlyStores) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3f2c-xwqh-4w82

Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3f2c-jm6v-cr35

Django DNS Rebinding Vulnerability

CVSS3: 8.1
6%
Низкий
больше 4 лет назад
github логотип
GHSA-3f29-xc6q-j293

LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyTemplateAll method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-19922.

CVSS3: 7.5
77%
Высокий
больше 2 лет назад
github логотип
GHSA-3f29-pqwf-v4j4

Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3f29-4g5p-wvc9

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them.

CVSS3: 9.8
2%
Низкий
11 месяцев назад
github логотип
GHSA-3f29-39mf-32c5

Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f29-2mxq-538c

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1408, CVE-2019-1434.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3f28-vrfj-2cwc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f28-8p95-qq7j

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
10 месяцев назад
github логотип
GHSA-3f27-r52q-f7jv

The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a denial of service (panic) by triggering a fault, as demonstrated by an unaligned memory operand or a non-canonical address memory operand.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3f26-j6r7-9q8v

In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f26-hjxq-9434

ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and cause a denial of service.

CVSS3: 6.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-3f26-8r72-46wh

Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress allows Upload a Web Shell to a Web Server. This issue affects File Manager Plugin For Wordpress: from n/a through 7.5.

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3f26-542m-36hv

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

1%
Низкий
около 4 лет назад
github логотип
GHSA-3f25-9wj6-fhrv

Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, does not properly check a buffer during an IOCTL 0x9c402420 call, which allows local users to cause a denial of service (machine crash) and possibly gain privileges via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3f24-pcvm-5jqc

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

CVSS3: 4.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-3f24-8wqg-chhj

Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3f24-4xhj-mpvj

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272582 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-3f23-79pf-grrm

The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу