Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-2w9c-58xw-cr7x

около 4 лет назад

The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2w99-mpmh-5r22

6 месяцев назад

The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in the request. This makes it possible for unauthenticated attackers to change the publish status of popups via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2w99-6h4v-j323

больше 1 года назад

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2w98-wcf4-f6w2

10 месяцев назад

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'company' at the endpoint '/clients/client/x.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2w98-h9rr-xfqq

около 1 года назад

NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2w98-fvw7-3w85

около 4 лет назад

The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL.

EPSS: Низкий
github логотип

GHSA-2w97-q69c-frhf

около 1 года назад

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2w97-hp83-3ghv

12 дней назад

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (application crash), information disclosure, or potential arbitrary code execution via a crafted MP3 file. The vulnerability occurs due to missing bounds validation on attacker-controlled frame size and improper memory access during lyric parsing.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2w97-hhmp-jmj9

больше 3 лет назад

The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2w97-78m3-mph6

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder allows Stored XSS. This issue affects Cost Calculator Builder: from n/a through 3.2.74.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2w96-x49m-vc2j

больше 4 лет назад

Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2w96-8922-g8xr

7 месяцев назад

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w96-264r-66qf

больше 4 лет назад

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.

EPSS: Низкий
github логотип

GHSA-2w95-w2p8-6r8j

около 1 года назад

Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through 6.4.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w95-7g9v-5582

больше 1 года назад

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2w94-phv7-xjw4

больше 2 лет назад

Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2w94-97wx-8cvr

около 4 лет назад

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198923.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2w93-qwpp-vgvj

8 месяцев назад

trytond does not enforce access rights for data export

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w93-9gpp-wf7v

около 4 лет назад

SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, (3) JPEG2000, or (4) FBX file, aka "Out-Of-Bounds Indexing" vulnerabilities.

EPSS: Низкий
github логотип

GHSA-2w93-5qhr-rvc6

около 4 лет назад

RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN number via a brute force attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2w9c-58xw-cr7x

The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2w99-mpmh-5r22

The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in the request. This makes it possible for unauthenticated attackers to change the publish status of popups via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2w99-6h4v-j323

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2w98-wcf4-f6w2

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a POST request in the parameter 'company' at the endpoint '/clients/client/x.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2w98-h9rr-xfqq

NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-2w98-fvw7-3w85

The HTTPAuthentication implementation in CFNetwork in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted credentials in a URL.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2w97-q69c-frhf

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-2w97-hp83-3ghv

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (application crash), information disclosure, or potential arbitrary code execution via a crafted MP3 file. The vulnerability occurs due to missing bounds validation on attacker-controlled frame size and improper memory access during lyric parsing.

CVSS3: 8.8
12 дней назад
github логотип
GHSA-2w97-hhmp-jmj9

The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2w97-78m3-mph6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder allows Stored XSS. This issue affects Cost Calculator Builder: from n/a through 3.2.74.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-2w96-x49m-vc2j

Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2w96-8922-g8xr

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-2w96-264r-66qf

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2w95-w2p8-6r8j

Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through 6.4.0.2.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2w95-7g9v-5582

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2w94-phv7-xjw4

Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2w94-97wx-8cvr

IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information could be used in further attacks against the system. IBM X-Force ID: 198923.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2w93-qwpp-vgvj

trytond does not enforce access rights for data export

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2w93-9gpp-wf7v

SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, (3) JPEG2000, or (4) FBX file, aka "Out-Of-Bounds Indexing" vulnerabilities.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2w93-5qhr-rvc6

RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN number via a brute force attack.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу