Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2x2j-3c2v-g3c2

около 1 года назад

Microweber XSS Vulnerability in the homepage Endpoint

EPSS: Низкий
github логотип

GHSA-2x2h-mgrr-fp68

около 4 лет назад

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.

EPSS: Низкий
github логотип

GHSA-2x2h-53cj-6jjx

почти 2 года назад

Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2x2g-qj89-46xx

больше 4 лет назад

Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.

EPSS: Низкий
github логотип

GHSA-2x2g-fcpp-7fr9

6 месяцев назад

HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a significantly longer lifetime (default one year), an authenticated client could use a refresh token in place of an access token to maintain long-term access without token rotation. Additionally, old access tokens remained valid after refresh, enabling concurrent or extended use beyond intended session boundaries. This vulnerability could allow prolonged unauthorized access if a token is disclosed.

EPSS: Низкий
github логотип

GHSA-2x2g-32r7-p4x8

больше 1 года назад

Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x2c-w34j-v42x

4 месяца назад

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2x2c-h542-whv5

около 4 лет назад

An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2x29-88x9-wfrj

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x28-xwcm-wq72

больше 3 лет назад

TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2x28-ghj8-5fhc

около 2 месяцев назад

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x28-c7j7-23gv

почти 3 года назад

Subrion remote command execution vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2x28-576q-2wr5

около 2 лет назад

Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2x28-2cqf-228j

около 4 лет назад

Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2x27-qff4-6hf8

около 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2x27-jmf7-8fj3

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2x27-jcrc-gj3p

около 4 лет назад

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8422.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2x26-r374-v69m

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Query Posts query-posts allows Stored XSS.This issue affects Query Posts: from n/a through <= 0.3.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2x26-cf8j-qvpf

около 4 лет назад

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. An unauthenticated attacker could send, or claim to send, large input values and consume server resources waiting for those inputs, denying service to other valid connections.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x25-w5h9-6hg2

около 4 лет назад

The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2x2j-3c2v-g3c2

Microweber XSS Vulnerability in the homepage Endpoint

0%
Низкий
около 1 года назад
github логотип
GHSA-2x2h-mgrr-fp68

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2x2h-53cj-6jjx

Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2x2g-qj89-46xx

Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2x2g-fcpp-7fr9

HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a significantly longer lifetime (default one year), an authenticated client could use a refresh token in place of an access token to maintain long-term access without token rotation. Additionally, old access tokens remained valid after refresh, enabling concurrent or extended use beyond intended session boundaries. This vulnerability could allow prolonged unauthorized access if a token is disclosed.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2x2g-32r7-p4x8

Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2x2c-w34j-v42x

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-2x2c-h542-whv5

An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2x29-88x9-wfrj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-2x28-xwcm-wq72

TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2x28-ghj8-5fhc

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2x28-c7j7-23gv

Subrion remote command execution vulnerability

CVSS3: 7.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-2x28-576q-2wr5

Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2x28-2cqf-228j

Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2x27-qff4-6hf8

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2x27-jmf7-8fj3

Rejected reason: Not used

7 месяцев назад
github логотип
GHSA-2x27-jcrc-gj3p

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8422.

CVSS3: 6.5
13%
Средний
около 4 лет назад
github логотип
GHSA-2x26-r374-v69m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Query Posts query-posts allows Stored XSS.This issue affects Query Posts: from n/a through <= 0.3.2.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2x26-cf8j-qvpf

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. An unauthenticated attacker could send, or claim to send, large input values and consume server resources waiting for those inputs, denying service to other valid connections.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2x25-w5h9-6hg2

The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу