Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-388v-6f9f-263v

около 4 лет назад

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

EPSS: Средний
github логотип

GHSA-388r-w9fg-m2x5

6 месяцев назад

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-388r-rxw2-v9f9

больше 3 лет назад

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-388r-hw74-wm79

больше 4 лет назад

FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

EPSS: Низкий
github логотип

GHSA-388q-gvg4-w5x2

больше 4 лет назад

Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-388p-p6mh-7f4g

около 4 лет назад

The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-388p-85c7-wr6g

больше 3 лет назад

A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-388m-42jq-jjrp

больше 4 лет назад

RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.

CVSS3: 7.1
EPSS: Средний
github логотип

GHSA-388j-jw77-hhcj

больше 1 года назад

The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-388j-hgw2-75wf

около 4 лет назад

Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

EPSS: Низкий
github логотип

GHSA-388j-3575-x477

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-388j-24wv-pfqq

больше 1 года назад

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-388h-jxj2-x3jp

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-388h-g8mc-3g8v

около 4 лет назад

Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface. Administrators can lock the ENS client interface through ePO to prevent users being able to edit the configuration.

EPSS: Низкий
github логотип

GHSA-388g-xpph-h5rv

больше 4 лет назад

Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.

EPSS: Средний
github логотип

GHSA-388g-rj94-7qvv

больше 4 лет назад

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.

EPSS: Низкий
github логотип

GHSA-388g-pgp3-x5mx

9 месяцев назад

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-388g-jwpg-x6j4

почти 6 лет назад

Cross-Site Scripting in swagger-ui

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-388g-hxhw-5c6q

больше 1 года назад

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-388g-95vj-q36x

больше 4 лет назад

A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-388v-6f9f-263v

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

47%
Средний
около 4 лет назад
github логотип
GHSA-388r-w9fg-m2x5

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-388r-rxw2-v9f9

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-388r-hw74-wm79

FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-388q-gvg4-w5x2

Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-388p-p6mh-7f4g

The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-388p-85c7-wr6g

A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-388m-42jq-jjrp

RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.

CVSS3: 7.1
16%
Средний
больше 4 лет назад
github логотип
GHSA-388j-jw77-hhcj

The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-388j-hgw2-75wf

Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

1%
Низкий
около 4 лет назад
github логотип
GHSA-388j-3575-x477

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-388j-24wv-pfqq

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-388h-jxj2-x3jp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-388h-g8mc-3g8v

Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface. Administrators can lock the ENS client interface through ePO to prevent users being able to edit the configuration.

0%
Низкий
около 4 лет назад
github логотип
GHSA-388g-xpph-h5rv

Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.

14%
Средний
больше 4 лет назад
github логотип
GHSA-388g-rj94-7qvv

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-388g-pgp3-x5mx

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-388g-jwpg-x6j4

Cross-Site Scripting in swagger-ui

CVSS3: 6.5
почти 6 лет назад
github логотип
GHSA-388g-hxhw-5c6q

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-388g-95vj-q36x

A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу