Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vg6-77g8-24mp

около 1 месяца назад

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2vg6-3mr6-w5mp

больше 4 лет назад

lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.

EPSS: Низкий
github логотип

GHSA-2vg5-px79-v62f

9 месяцев назад

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2vg5-gq78-m2fx

около 4 лет назад

Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

EPSS: Низкий
github логотип

GHSA-2vg5-5q9m-8f9q

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Matt van Andel Custom List Table Example allows Reflected XSS.This issue affects Custom List Table Example: from n/a through 1.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vg5-244r-2cmh

около 4 лет назад

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vg4-rrx4-qcpq

4 месяца назад

AVideo: Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vg4-g4gm-pvj7

больше 4 лет назад

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-2vg3-xrfw-fx8c

17 дней назад

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2vg3-8hw9-v322

больше 1 года назад

An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vg3-2jpr-xp58

больше 4 лет назад

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

EPSS: Низкий
github логотип

GHSA-2vg2-p84m-hhr5

около 4 лет назад

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vg2-f293-3rc8

около 4 лет назад

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.

EPSS: Низкий
github логотип

GHSA-2vfx-mj86-p92f

больше 4 лет назад

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

EPSS: Низкий
github логотип

GHSA-2vfx-8pj2-gpp8

больше 2 лет назад

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19477.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vfx-6mjq-9ccv

около 4 лет назад

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2vfw-8m4f-jmc8

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.

EPSS: Низкий
github логотип

GHSA-2vfv-v6m4-65x6

больше 4 лет назад

Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

EPSS: Низкий
github логотип

GHSA-2vfr-ch7v-7754

3 месяца назад

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2vfq-pq87-ph87

больше 1 года назад

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vg6-77g8-24mp

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

CVSS3: 3.8
около 1 месяца назад
github логотип
GHSA-2vg6-3mr6-w5mp

lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2vg5-px79-v62f

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS3: 4.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-2vg5-gq78-m2fx

Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vg5-5q9m-8f9q

Cross-Site Request Forgery (CSRF) vulnerability in Matt van Andel Custom List Table Example allows Reflected XSS.This issue affects Custom List Table Example: from n/a through 1.4.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vg5-244r-2cmh

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vg4-rrx4-qcpq

AVideo: Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2vg4-g4gm-pvj7

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vg3-xrfw-fx8c

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 4.4
0%
Низкий
17 дней назад
github логотип
GHSA-2vg3-8hw9-v322

An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2vg3-2jpr-xp58

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vg2-p84m-hhr5

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2vg2-f293-3rc8

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfx-mj86-p92f

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2vfx-8pj2-gpp8

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19477.

CVSS3: 7.8
4%
Низкий
больше 2 лет назад
github логотип
GHSA-2vfx-6mjq-9ccv

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfw-8m4f-jmc8

Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfv-v6m4-65x6

Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2vfr-ch7v-7754

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.

CVSS3: 7.7
0%
Низкий
3 месяца назад
github логотип
GHSA-2vfq-pq87-ph87

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

CVSS3: 9.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу