Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2ww2-4h6w-cc6c

около 4 лет назад

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wvx-75wc-hc4w

около 4 лет назад

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wvw-h8hc-x343

около 4 лет назад

Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2wvw-246g-ffw7

около 4 лет назад

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

EPSS: Низкий
github логотип

GHSA-2wvv-vggf-ggr9

около 4 лет назад

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2wvv-pxv7-cgf7

больше 3 лет назад

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2wvv-phhw-qvmc

около 3 лет назад

Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wvv-6r6q-wwcj

около 4 лет назад

Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wvv-4p4q-7mq5

больше 1 года назад

Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wvq-xm2v-3mr6

больше 4 лет назад

Deliantra Server before 2.82 allows remote authenticated users to cause a denial of service (daemon crash) via vectors involving an empty treasure list.

EPSS: Низкий
github логотип

GHSA-2wvq-34x3-5vhj

около 1 года назад

Users who were required to change their password could still access system information before changing their password

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2wvq-2hj6-8g26

около 4 лет назад

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0426.

EPSS: Низкий
github логотип

GHSA-2wvp-q72m-cfq8

около 4 лет назад

Cross-site scripting (XSS) vulnerability in config.php in AdaptCMS 2.0.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2wvp-gfcw-56p6

около 4 лет назад

While rendering the layout background, Error status check is not caught properly and also incorrect status handling is being done leading to unintended SUI behaviour in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9150, MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX24, SXR1130

EPSS: Низкий
github логотип

GHSA-2wvm-9j4x-757c

около 4 лет назад

templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2wvj-gvc7-gfhx

3 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wvj-9m7h-43j3

около 4 лет назад

An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wvj-7gj7-2j5w

около 4 лет назад

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2wvh-w7fv-6223

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.

EPSS: Низкий
github логотип

GHSA-2wvh-87g2-89hr

4 месяца назад

OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2ww2-4h6w-cc6c

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wvx-75wc-hc4w

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2wvw-h8hc-x343

Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wvw-246g-ffw7

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2wvv-vggf-ggr9

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.

CVSS3: 8.8
18%
Средний
около 4 лет назад
github логотип
GHSA-2wvv-pxv7-cgf7

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wvv-phhw-qvmc

Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2wvv-6r6q-wwcj

Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2wvv-4p4q-7mq5

Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wvq-xm2v-3mr6

Deliantra Server before 2.82 allows remote authenticated users to cause a denial of service (daemon crash) via vectors involving an empty treasure list.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wvq-34x3-5vhj

Users who were required to change their password could still access system information before changing their password

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2wvq-2hj6-8g26

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0426.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2wvp-q72m-cfq8

Cross-site scripting (XSS) vulnerability in config.php in AdaptCMS 2.0.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2wvp-gfcw-56p6

While rendering the layout background, Error status check is not caught properly and also incorrect status handling is being done leading to unintended SUI behaviour in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9150, MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX24, SXR1130

0%
Низкий
около 4 лет назад
github логотип
GHSA-2wvm-9j4x-757c

templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wvj-gvc7-gfhx

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-2wvj-9m7h-43j3

An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2wvj-7gj7-2j5w

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.

CVSS3: 7.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-2wvh-w7fv-6223

Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2wvh-87g2-89hr

OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool

CVSS3: 9.6
4 месяца назад

Уязвимостей на страницу