Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33qq-m8g7-4j8j

5 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33qq-5jq7-v446

около 2 месяцев назад

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-33qp-rrww-3f5q

больше 4 лет назад

Elgg through 1.7.10 has a SQL injection vulnerability

EPSS: Низкий
github логотип

GHSA-33qm-768m-wx8p

около 1 года назад

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-33qj-cxq7-xmmr

больше 4 лет назад

Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

EPSS: Высокий
github логотип

GHSA-33qj-7hm4-jp7v

больше 4 лет назад

Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.

EPSS: Высокий
github логотип

GHSA-33qh-fj99-2gvg

больше 2 лет назад

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33qg-rqxq-9ghc

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Theme Builder <= 3.24.2 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33qg-r99w-m2x7

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_script/frontend_render/navigation/.

EPSS: Средний
github логотип

GHSA-33qg-7wpp-89cq

4 месяца назад

Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization

EPSS: Низкий
github логотип

GHSA-33qg-28r7-x7mg

около 4 лет назад

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

EPSS: Низкий
github логотип

GHSA-33qf-q99x-wpm8

4 месяца назад

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-33qf-6xj8-p2pq

больше 1 года назад

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-33qf-5jfw-2vp9

около 4 лет назад

EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain privileges via a request for a superuser ticket.

EPSS: Низкий
github логотип

GHSA-33qc-w569-hr38

29 дней назад

NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33qc-p77x-82rf

больше 4 лет назад

abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

EPSS: Низкий
github логотип

GHSA-33qc-76rw-rxcm

больше 1 года назад

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to activate/deactivate arbitrary plugins.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33q9-hj3m-p778

около 4 лет назад

The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers to conduct heap-based buffer overflow attacks and execute arbitrary code via a crafted response.

EPSS: Низкий
github логотип

GHSA-33q9-fp3q-fw2p

больше 1 года назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-33q9-f52j-gc75

21 день назад

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33qq-m8g7-4j8j

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-33qq-5jq7-v446

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

CVSS3: 9.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-33qp-rrww-3f5q

Elgg through 1.7.10 has a SQL injection vulnerability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33qm-768m-wx8p

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.

CVSS3: 9.3
0%
Низкий
около 1 года назад
github логотип
GHSA-33qj-cxq7-xmmr

Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

86%
Высокий
больше 4 лет назад
github логотип
GHSA-33qj-7hm4-jp7v

Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.

74%
Высокий
больше 4 лет назад
github логотип
GHSA-33qh-fj99-2gvg

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33qg-rqxq-9ghc

Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Theme Builder <= 3.24.2 versions.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33qg-r99w-m2x7

Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_script/frontend_render/navigation/.

42%
Средний
больше 4 лет назад
github логотип
GHSA-33qg-7wpp-89cq

Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization

0%
Низкий
4 месяца назад
github логотип
GHSA-33qg-28r7-x7mg

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-33qf-q99x-wpm8

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

CVSS3: 5.6
0%
Низкий
4 месяца назад
github логотип
GHSA-33qf-6xj8-p2pq

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-33qf-5jfw-2vp9

EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain privileges via a request for a superuser ticket.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33qc-w569-hr38

NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.

CVSS3: 7.5
0%
Низкий
29 дней назад
github логотип
GHSA-33qc-p77x-82rf

abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33qc-76rw-rxcm

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to activate/deactivate arbitrary plugins.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-33q9-hj3m-p778

The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers to conduct heap-based buffer overflow attacks and execute arbitrary code via a crafted response.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33q9-fp3q-fw2p

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-33q9-f52j-gc75

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

0%
Низкий
21 день назад

Уязвимостей на страницу