Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-324p-3f7r-2rf5

больше 2 лет назад

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-324m-xxrv-v73q

14 дней назад

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier.

EPSS: Низкий
github логотип

GHSA-324m-p5mr-m7mp

около 4 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

EPSS: Низкий
github логотип

GHSA-324m-7g42-gmmr

около 4 лет назад

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-324j-grr2-6cg2

больше 4 лет назад

Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.

EPSS: Средний
github логотип

GHSA-324j-gr3g-9jhv

около 4 лет назад

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-324h-vh92-m23h

больше 4 лет назад

Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-324h-8gv8-f3xm

больше 4 лет назад

Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.

EPSS: Низкий
github логотип

GHSA-324h-2v7h-q3xx

около 4 лет назад

RCE vulnerability in Jenkins Yaml Axis Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-324g-rp4q-gr7p

почти 2 года назад

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-324f-g94h-3w6p

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative plugin <= 1.3.0 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-324f-g2g5-rj4m

около 4 лет назад

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-324f-c4g7-9r7j

больше 2 лет назад

A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-324f-35v9-jxhh

26 дней назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-324c-r2g2-547c

около 1 года назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3249-ch6f-5vrf

больше 2 лет назад

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3248-f932-c76p

больше 1 года назад

DB-GPT vulnerable to Cross-Site Request Forgery

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3248-f5xr-jwg7

почти 3 года назад

Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3248-52cq-vhgx

больше 4 лет назад

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

EPSS: Низкий
github логотип

GHSA-3247-q928-6mr7

около 4 лет назад

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-324p-3f7r-2rf5

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

CVSS3: 7.5
5%
Низкий
больше 2 лет назад
github логотип
GHSA-324m-xxrv-v73q

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier.

0%
Низкий
14 дней назад
github логотип
GHSA-324m-p5mr-m7mp

An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

1%
Низкий
около 4 лет назад
github логотип
GHSA-324m-7g42-gmmr

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

CVSS3: 9.8
9%
Низкий
около 4 лет назад
github логотип
GHSA-324j-grr2-6cg2

Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.

15%
Средний
больше 4 лет назад
github логотип
GHSA-324j-gr3g-9jhv

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-324h-vh92-m23h

Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-324h-8gv8-f3xm

Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-324h-2v7h-q3xx

RCE vulnerability in Jenkins Yaml Axis Plugin

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-324g-rp4q-gr7p

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-324f-g94h-3w6p

Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative plugin <= 1.3.0 versions.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-324f-g2g5-rj4m

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-324f-c4g7-9r7j

A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-324f-35v9-jxhh

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.

CVSS3: 6.5
0%
Низкий
26 дней назад
github логотип
GHSA-324c-r2g2-547c

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3249-ch6f-5vrf

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3248-f932-c76p

DB-GPT vulnerable to Cross-Site Request Forgery

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3248-f5xr-jwg7

Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3248-52cq-vhgx

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3247-q928-6mr7

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу