Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-3866-cc7f-3jx4

больше 4 лет назад

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3866-98fq-wg7f

больше 4 лет назад

The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.

EPSS: Низкий
github логотип

GHSA-3866-72wv-xq49

6 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS).This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3866-5rgc-4rr9

больше 4 лет назад

Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.

EPSS: Низкий
github логотип

GHSA-3865-xcmr-qxp5

больше 3 лет назад

In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3864-rp2m-2qfj

больше 1 года назад

libre-chat Path Traversal vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3864-88qj-q5jc

больше 1 года назад

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3863-q6pp-rrcg

больше 1 года назад

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3863-h4xw-2xv3

около 4 лет назад

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

EPSS: Низкий
github логотип

GHSA-3863-2447-669p

больше 2 лет назад

transformers has a Deserialization of Untrusted Data vulnerability

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3862-v28r-vqw4

больше 4 лет назад

seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3862-j6jr-jg22

больше 4 лет назад

Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.

EPSS: Средний
github логотип

GHSA-3862-fmr3-4f3h

около 3 лет назад

Broadleaf vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3862-f8g9-4ffc

больше 1 года назад

Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3862-c622-v4fp

больше 3 лет назад

Cross-site Scripting in Backdrop CMS

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3862-5qvv-3rvv

около 2 лет назад

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-385x-88c3-c379

около 4 лет назад

Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-385w-hjpp-r4cx

около 3 лет назад

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-385w-3r67-h9rr

больше 1 года назад

Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-385r-vgx4-4g7p

больше 4 лет назад

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3866-cc7f-3jx4

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3866-98fq-wg7f

The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3866-72wv-xq49

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS).This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3866-5rgc-4rr9

Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3865-xcmr-qxp5

In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3864-rp2m-2qfj

libre-chat Path Traversal vulnerability

CVSS3: 9.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-3864-88qj-q5jc

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

CVSS3: 6.5
11%
Средний
больше 1 года назад
github логотип
GHSA-3863-q6pp-rrcg

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3863-h4xw-2xv3

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

7%
Низкий
около 4 лет назад
github логотип
GHSA-3863-2447-669p

transformers has a Deserialization of Untrusted Data vulnerability

CVSS3: 9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3862-v28r-vqw4

seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3862-j6jr-jg22

Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.

28%
Средний
больше 4 лет назад
github логотип
GHSA-3862-fmr3-4f3h

Broadleaf vulnerable to Cross-site Scripting

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3862-f8g9-4ffc

Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3862-c622-v4fp

Cross-site Scripting in Backdrop CMS

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3862-5qvv-3rvv

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-385x-88c3-c379

Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376.

CVSS3: 6.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-385w-hjpp-r4cx

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

CVSS3: 7.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-385w-3r67-h9rr

Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-385r-vgx4-4g7p

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад

Уязвимостей на страницу