Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-2xx4-jj5v-6mff

около 3 лет назад

Nuclei Path Traversal vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xx3-w7pj-fmgj

около 4 лет назад

The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.

EPSS: Низкий
github логотип

GHSA-2xx3-ghv4-f2fv

около 4 лет назад

Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.

EPSS: Средний
github логотип

GHSA-2xx3-8jg7-cq2x

5 месяцев назад

A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-2xx2-7jhq-rw7v

около 4 лет назад

common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence.

EPSS: Низкий
github логотип

GHSA-2xwx-qwxw-x89v

больше 3 лет назад

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2xwx-3gmg-f9vj

около 4 лет назад

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xww-r24j-8xmc

больше 4 лет назад

calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.

EPSS: Низкий
github логотип

GHSA-2xwv-qmvc-f3g6

около 4 лет назад

, aka 'RETRACTED'.

EPSS: Низкий
github логотип

GHSA-2xwv-qj35-wxv7

около 4 лет назад

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2xwv-qh99-36jq

4 месяца назад

InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by importing a maliciously crafted text file. Attackers can create a text file containing 6000 bytes of data and import it through the Edit menu's Import function to trigger an application crash.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2xwv-mhjq-356g

3 месяца назад

Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2xwv-3cc9-fp7c

почти 7 лет назад

Sensitive Data Exposure in seneca

EPSS: Низкий
github логотип

GHSA-2xwv-25cq-66xr

около 1 года назад

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xwr-gh6x-hm86

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl->opt->opt_nflen` when an option block is present. Exclusive flowlabels currently free `fl->opt` as soon as `fl->users` drops to zero in `fl_release()`. However, the surrounding `struct ip6_flowlabel` remains visible in the global hash table until later garbage collection removes it and `fl_free_rcu()` finally tears it down. A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that early `kfree()` and dereference freed option state, triggering a crash in `ip6fl_seq_show()`. Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches the lifetime already required for the enclosing flowlabel while readers can still reach it under RCU.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xwr-53m3-98jw

больше 4 лет назад

SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.

EPSS: Низкий
github логотип

GHSA-2xwq-p62f-cjrm

около 4 лет назад

PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xwq-h7r9-6w27

больше 4 лет назад

Cross-site Scripting in kimai2

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2xwq-3g46-4j22

больше 4 лет назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xwp-m9v6-767p

4 дня назад

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xx4-jj5v-6mff

Nuclei Path Traversal vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2xx3-w7pj-fmgj

The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.

10%
Низкий
около 4 лет назад
github логотип
GHSA-2xx3-ghv4-f2fv

Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.

11%
Средний
около 4 лет назад
github логотип
GHSA-2xx3-8jg7-cq2x

A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
39%
Средний
5 месяцев назад
github логотип
GHSA-2xx2-7jhq-rw7v

common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2xwx-qwxw-x89v

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account

CVSS3: 2.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwx-3gmg-f9vj

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2xww-r24j-8xmc

calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2xwv-qmvc-f3g6

, aka 'RETRACTED'.

около 4 лет назад
github логотип
GHSA-2xwv-qj35-wxv7

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

CVSS3: 9.8
93%
Критический
около 4 лет назад
github логотип
GHSA-2xwv-qh99-36jq

InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by importing a maliciously crafted text file. Attackers can create a text file containing 6000 bytes of data and import it through the Edit menu's Import function to trigger an application crash.

CVSS3: 6.2
0%
Низкий
4 месяца назад
github логотип
GHSA-2xwv-mhjq-356g

Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2xwv-3cc9-fp7c

Sensitive Data Exposure in seneca

1%
Низкий
почти 7 лет назад
github логотип
GHSA-2xwv-25cq-66xr

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2xwr-gh6x-hm86

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl->opt->opt_nflen` when an option block is present. Exclusive flowlabels currently free `fl->opt` as soon as `fl->users` drops to zero in `fl_release()`. However, the surrounding `struct ip6_flowlabel` remains visible in the global hash table until later garbage collection removes it and `fl_free_rcu()` finally tears it down. A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that early `kfree()` and dereference freed option state, triggering a crash in `ip6fl_seq_show()`. Fix this by keeping `fl->opt` alive until `fl_free_rcu()`. That matches the lifetime already required for the enclosing flowlabel while readers can still reach it under RCU.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2xwr-53m3-98jw

SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2xwq-p62f-cjrm

PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2xwq-h7r9-6w27

Cross-site Scripting in kimai2

CVSS3: 4.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2xwq-3g46-4j22

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2xwp-m9v6-767p

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.

CVSS3: 4.8
0%
Низкий
4 дня назад

Уязвимостей на страницу