Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-xr4f-cr86-pfhv

больше 4 лет назад

Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xr4f-2rrr-cm48

почти 3 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr4c-xrjh-v47v

3 месяца назад

Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xr4c-mmrv-3h6c

почти 2 года назад

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xr4c-88wp-frr7

больше 4 лет назад

Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."

EPSS: Низкий
github логотип

GHSA-xr49-qh48-cff9

больше 2 лет назад

Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xr49-pr22-vxc8

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.

EPSS: Низкий
github логотип

GHSA-xr49-f4rh-qcjf

3 месяца назад

AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization

EPSS: Низкий
github логотип

GHSA-xr49-7fhc-h2jh

почти 4 года назад

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr48-rvqv-pwjm

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr47-pcmx-fq2m

больше 2 лет назад

Certain sequence of payloads may lead to remote code execution

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xr47-8jmm-28wq

около 2 лет назад

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr47-4wf6-2gmw

около 4 лет назад

Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-xr46-9c78-g7pg

около 4 лет назад

Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful attack).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr45-qc77-mx25

9 месяцев назад

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable and subsequently passed to require_once. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server via the `[code_snippet]` shortcode using PHP filter chains granted they can trick an administrator into enabling the "Enable file-based execution" setting and creating at least one active Content snippet.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xr45-m2xg-h479

около 4 лет назад

Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr45-72jm-wpcw

больше 1 года назад

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr45-42h9-q5rf

около 4 лет назад

PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.

EPSS: Низкий
github логотип

GHSA-xr44-v6xx-f99r

около 4 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.

EPSS: Низкий
github логотип

GHSA-xr44-9893-8w63

почти 3 года назад

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr4f-cr86-pfhv

Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr4f-2rrr-cm48

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xr4c-xrjh-v47v

Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xr4c-mmrv-3h6c

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr4c-88wp-frr7

Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xr49-qh48-cff9

Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr49-pr22-vxc8

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr49-f4rh-qcjf

AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization

0%
Низкий
3 месяца назад
github логотип
GHSA-xr49-7fhc-h2jh

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xr48-rvqv-pwjm

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xr47-pcmx-fq2m

Certain sequence of payloads may lead to remote code execution

CVSS3: 8.1
3%
Низкий
больше 2 лет назад
github логотип
GHSA-xr47-8jmm-28wq

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr47-4wf6-2gmw

Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.

19%
Средний
около 4 лет назад
github логотип
GHSA-xr46-9c78-g7pg

Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful attack).

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xr45-qc77-mx25

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable and subsequently passed to require_once. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server via the `[code_snippet]` shortcode using PHP filter chains granted they can trick an administrator into enabling the "Enable file-based execution" setting and creating at least one active Content snippet.

CVSS3: 8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xr45-m2xg-h479

Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xr45-72jm-wpcw

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr45-42h9-q5rf

PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xr44-v6xx-f99r

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr44-9893-8w63

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 6.8
1%
Низкий
почти 3 года назад

Уязвимостей на страницу