Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-3875-gc8x-5cmm

около 4 лет назад

The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3875-8gcx-7v46

3 месяца назад

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3874-v58r-hmr4

больше 3 лет назад

A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-226102 is the identifier assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3874-c4vv-qxvf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.

EPSS: Низкий
github логотип

GHSA-3873-x9wv-xhwq

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure side), if length of rights string is very large, a buffer over read occurs, exposing TZ App memory to non-secure side.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3873-898q-6f32

больше 4 лет назад

OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.

EPSS: Средний
github логотип

GHSA-3873-529g-4g7g

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP-Lister Lite for eBay allows Reflected XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.6.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3873-3x3p-6gpc

больше 4 лет назад

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3872-f48p-pxqj

больше 4 лет назад

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3872-7h3q-h629

около 4 лет назад

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-386x-hp87-5862

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-386w-c86g-88qj

больше 4 лет назад

Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.

EPSS: Низкий
github логотип

GHSA-386v-w8vv-pcqx

больше 4 лет назад

Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.

EPSS: Средний
github логотип

GHSA-386r-pqqg-j97c

больше 4 лет назад

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-386r-9hqf-3f7p

около 4 лет назад

WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may allow arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-386r-5f2r-6m92

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

EPSS: Низкий
github логотип

GHSA-386q-xj43-6wfr

около 4 лет назад

Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-386q-8gmc-924g

больше 4 лет назад

The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, as demonstrated by a wddx_deserialize call that mishandles a dateTime element in a wddxPacket XML document.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-386q-5vfw-9f3x

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the autocomplete text field widget without Views.module.

EPSS: Низкий
github логотип

GHSA-386q-5hp3-95m9

20 дней назад

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3875-gc8x-5cmm

The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-3875-8gcx-7v46

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3874-v58r-hmr4

A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-226102 is the identifier assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3874-c4vv-qxvf

Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3873-x9wv-xhwq

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure side), if length of rights string is very large, a buffer over read occurs, exposing TZ App memory to non-secure side.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3873-898q-6f32

OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3873-529g-4g7g

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP-Lister Lite for eBay allows Reflected XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.6.0.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3873-3x3p-6gpc

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3872-f48p-pxqj

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3872-7h3q-h629

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

CVSS3: 7
1%
Низкий
около 4 лет назад
github логотип
GHSA-386x-hp87-5862

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-386w-c86g-88qj

Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-386v-w8vv-pcqx

Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.

16%
Средний
больше 4 лет назад
github логотип
GHSA-386r-pqqg-j97c

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8459, CVE-2015-8460, and CVE-2015-8645.

CVSS3: 8.8
21%
Средний
больше 4 лет назад
github логотип
GHSA-386r-9hqf-3f7p

WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may allow arbitrary code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-386r-5f2r-6m92

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

1%
Низкий
около 4 лет назад
github логотип
GHSA-386q-xj43-6wfr

Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-386q-8gmc-924g

The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, as demonstrated by a wddx_deserialize call that mishandles a dateTime element in a wddxPacket XML document.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-386q-5vfw-9f3x

Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the autocomplete text field widget without Views.module.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-386q-5hp3-95m9

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

CVSS3: 8.8
0%
Низкий
20 дней назад

Уязвимостей на страницу