Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2v4v-84h9-hhvr

около 4 лет назад

YzmCMS v5.2 has admin/role/add.html CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v4r-w4rj-qv25

около 4 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v4r-jr99-4q4h

около 4 лет назад

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2v4r-7m2m-5chh

около 4 лет назад

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-2v4q-7r62-3cvj

больше 4 лет назад

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, directory traversal vulnerabilities exist in undisclosed iControl REST endpoints and TMOS Shell (tmsh) commands in F5 BIG-IP Guided Configuration, which may allow an authenticated attacker with at least resource administrator role privileges to read arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2v4p-65pc-4gv4

3 дня назад

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2v4m-jrfw-pm9p

около 4 лет назад

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4243, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v4m-fw6c-g78f

около 1 месяца назад

GeoNetwork has reflected XSS through client-side template injection

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2v4m-8pv2-3frg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter in a new entry, as demonstrated by a CSS property in the STYLE attribute of a DIV element, a different vulnerability than CVE-2008-1873.

EPSS: Низкий
github логотип

GHSA-2v4j-cxx2-mgp4

около 4 лет назад

Buffer overflow in Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2v4h-c2w7-48pw

7 месяцев назад

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing attackers with authenticated access to inject malicious scripts that will be executed in other users' browsers when they view the affected content.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2v4h-4vvv-j9ph

около 4 лет назад

An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2v4g-w3qw-prh4

больше 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2v4g-65gf-w58f

8 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v4f-h7wf-hprx

почти 2 года назад

Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2v4c-p54v-w3r7

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tobias Spiess TS Comfort DB allows Reflected XSS.This issue affects TS Comfort DB: from n/a through 2.0.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2v49-56rv-5c2h

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Arbor Networks Peakflow SP 3.5.1 before patch 14, and 3.6.1 before patch 5, when scope accounts are enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving GET or POST requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2v49-2q3c-3x2g

около 4 лет назад

A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

EPSS: Низкий
github логотип

GHSA-2v48-v35g-3vv5

около 4 лет назад

In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy "frame-ancestors' values.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2v48-hmwv-qpj8

8 месяцев назад

Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.19.1.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v4v-84h9-hhvr

YzmCMS v5.2 has admin/role/add.html CSRF.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v4r-w4rj-qv25

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v4r-jr99-4q4h

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v4r-7m2m-5chh

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVSS3: 7.5
87%
Высокий
около 4 лет назад
github логотип
GHSA-2v4q-7r62-3cvj

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, directory traversal vulnerabilities exist in undisclosed iControl REST endpoints and TMOS Shell (tmsh) commands in F5 BIG-IP Guided Configuration, which may allow an authenticated attacker with at least resource administrator role privileges to read arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 4.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2v4p-65pc-4gv4

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

CVSS3: 7.5
0%
Низкий
3 дня назад
github логотип
GHSA-2v4m-jrfw-pm9p

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4243, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2v4m-fw6c-g78f

GeoNetwork has reflected XSS through client-side template injection

CVSS3: 7.1
около 1 месяца назад
github логотип
GHSA-2v4m-8pv2-3frg

Cross-site scripting (XSS) vulnerability in the Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter in a new entry, as demonstrated by a CSS property in the STYLE attribute of a DIV element, a different vulnerability than CVE-2008-1873.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v4j-cxx2-mgp4

Buffer overflow in Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v4h-c2w7-48pw

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing attackers with authenticated access to inject malicious scripts that will be executed in other users' browsers when they view the affected content.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2v4h-4vvv-j9ph

An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2v4g-w3qw-prh4

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v4g-65gf-w58f

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2v4f-h7wf-hprx

Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2v4c-p54v-w3r7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tobias Spiess TS Comfort DB allows Reflected XSS.This issue affects TS Comfort DB: from n/a through 2.0.7.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v49-56rv-5c2h

Multiple cross-site scripting (XSS) vulnerabilities in Arbor Networks Peakflow SP 3.5.1 before patch 14, and 3.6.1 before patch 5, when scope accounts are enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving GET or POST requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v49-2q3c-3x2g

A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v48-v35g-3vv5

In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy "frame-ancestors' values.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v48-hmwv-qpj8

Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.19.1.

CVSS3: 7.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу