Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-37mg-65fg-9hr9

около 4 лет назад

A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37mg-42pw-cvp2

почти 3 года назад

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-37mc-f722-26x4

больше 4 лет назад

In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37m9-g2hc-mjp2

около 3 лет назад

A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37m8-vrcv-2x3f

больше 1 года назад

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-37m7-xg97-7h4c

около 2 лет назад

Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37m7-jq3g-46vx

больше 2 лет назад

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37m7-669m-h8r7

2 месяца назад

Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37m7-3gj6-4wrx

около 1 года назад

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-37m6-8rw8-wh8f

3 месяца назад

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-37m6-73f6-jm7w

около 4 лет назад

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

EPSS: Низкий
github логотип

GHSA-37m6-2cm3-x5m2

около 4 лет назад

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

EPSS: Низкий
github логотип

GHSA-37m5-m4q3-fc6x

2 месяца назад

Froxlor: BIND Zone File Injection via TXT Record Content

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-37m5-593h-89wf

больше 4 лет назад

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37m5-42qp-4qpr

около 5 лет назад

Cross-site scripting in LocalStack

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37m4-w5jp-r3px

больше 2 лет назад

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37m4-hvw3-vwmc

7 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37m4-hqxv-w26g

больше 2 лет назад

XWiki Platform CSRF remote code execution through scheduler job's document reference

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-37m3-qp37-x3c6

больше 4 лет назад

Apache Geode gfsh query vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37m3-29m6-vgxq

больше 4 лет назад

PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37mg-65fg-9hr9

A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-37mg-42pw-cvp2

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-37mc-f722-26x4

In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37m9-g2hc-mjp2

A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-37m8-vrcv-2x3f

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-37m7-xg97-7h4c

Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-37m7-jq3g-46vx

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-37m7-669m-h8r7

Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-37m7-3gj6-4wrx

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-37m6-8rw8-wh8f

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-37m6-73f6-jm7w

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

2%
Низкий
около 4 лет назад
github логотип
GHSA-37m6-2cm3-x5m2

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-37m5-m4q3-fc6x

Froxlor: BIND Zone File Injection via TXT Record Content

CVSS3: 7.6
0%
Низкий
2 месяца назад
github логотип
GHSA-37m5-593h-89wf

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37m5-42qp-4qpr

Cross-site scripting in LocalStack

CVSS3: 6.1
1%
Низкий
около 5 лет назад
github логотип
GHSA-37m4-w5jp-r3px

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37m4-hvw3-vwmc

Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-37m4-hqxv-w26g

XWiki Platform CSRF remote code execution through scheduler job's document reference

CVSS3: 9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37m3-qp37-x3c6

Apache Geode gfsh query vulnerability

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37m3-29m6-vgxq

PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу