Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vm7-vmfj-m5rm

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh KUMAR Mukhiya Anywhere Flash Embed plugin <= 1.0.5 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vm7-46v4-pr85

около 4 лет назад

An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2vm7-4348-jv9f

2 месяца назад

Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vm6-973m-fwf6

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) new_name parameter to apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified parameters to unknown files in apps/contacts/ajax/.

EPSS: Низкий
github логотип

GHSA-2vm6-24x2-fw9m

больше 4 лет назад

There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user's nickname is maliciously tampered with.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vm5-6gc7-pcvr

около 4 лет назад

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vm4-w283-mr2p

около 1 месяца назад

A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the component MCP Response Handler. This manipulation causes improper synchronization. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2vm4-q57w-7x2c

5 месяцев назад

Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vm4-jjww-7x6m

7 месяцев назад

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the `wsaw-log[]` POST parameter, which can be leveraged to delete critical files like `wp-config.php` or read sensitive configuration files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vm4-g44x-w548

около 4 лет назад

Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows local users to gain privileges via a malicious artefact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vjx-vmx2-m3h4

около 4 лет назад

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vjx-rcxr-r2p5

около 4 лет назад

Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2vjx-96pr-9r8r

больше 4 лет назад

A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.

EPSS: Низкий
github логотип

GHSA-2vjx-859r-qm27

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_ipi_destroy() is not currently doing this, that would lead to a memory leak. So, fix it.

EPSS: Низкий
github логотип

GHSA-2vjw-w57f-jmf6

10 месяцев назад

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vjv-m9hw-qvjf

2 месяца назад

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to traverse outside FRONTEND_DIST and exposing sensitive files such as SSH private keys, TLS certificates, and application secrets with a single HTTP request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vjv-62j5-c7h3

около 3 лет назад

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vjv-2jwr-w8hr

12 месяцев назад

An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vjr-qrh8-pp9c

около 1 года назад

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vjr-cvf4-9474

около 4 лет назад

The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, allowing attackers to inject SQL commands into the URL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vm7-vmfj-m5rm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh KUMAR Mukhiya Anywhere Flash Embed plugin <= 1.0.5 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vm7-46v4-pr85

An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vm7-4348-jv9f

Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2vm6-973m-fwf6

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) new_name parameter to apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified parameters to unknown files in apps/contacts/ajax/.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vm6-24x2-fw9m

There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user's nickname is maliciously tampered with.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2vm5-6gc7-pcvr

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vm4-w283-mr2p

A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the component MCP Response Handler. This manipulation causes improper synchronization. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2vm4-q57w-7x2c

Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2vm4-jjww-7x6m

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the `wsaw-log[]` POST parameter, which can be leveraged to delete critical files like `wp-config.php` or read sensitive configuration files.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-2vm4-g44x-w548

Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows local users to gain privileges via a malicious artefact.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2vjx-vmx2-m3h4

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vjx-rcxr-r2p5

Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vjx-96pr-9r8r

A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vjx-859r-qm27

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_ipi_destroy() is not currently doing this, that would lead to a memory leak. So, fix it.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2vjw-w57f-jmf6

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2vjv-m9hw-qvjf

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to traverse outside FRONTEND_DIST and exposing sensitive files such as SSH private keys, TLS certificates, and application secrets with a single HTTP request.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2vjv-62j5-c7h3

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2vjv-2jwr-w8hr

An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

CVSS3: 5.4
1%
Низкий
12 месяцев назад
github логотип
GHSA-2vjr-qrh8-pp9c

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2vjr-cvf4-9474

The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, allowing attackers to inject SQL commands into the URL.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу