Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2v3v-3whp-953h

около 1 года назад

starcitizentools/citizen-skin allows stored XSS in user registration date message

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v3r-wf43-c9gh

около 4 лет назад

The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."

EPSS: Средний
github логотип

GHSA-2v3r-qqr5-3x33

около 4 лет назад

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.

EPSS: Низкий
github логотип

GHSA-2v3r-gvq5-qqgh

больше 1 года назад

Dolibarr Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-2v3r-g46p-c64j

около 4 лет назад

Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2v3r-26j9-rjqh

почти 2 года назад

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2v3q-89pj-mhxh

около 4 лет назад

system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective password lengths to eight characters, which makes it easier for context-dependent attackers to successfully conduct brute-force password attacks.

EPSS: Низкий
github логотип

GHSA-2v3m-xrw2-48mj

около 4 лет назад

Buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.0.0.1569 allows remote attackers to execute arbitrary code via a crafted raw_data_frame field in an AAC file.

EPSS: Низкий
github логотип

GHSA-2v3m-p433-pwh8

больше 1 года назад

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2v3m-7w5q-rg4r

около 4 лет назад

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2822, CVE-2014-2823, and CVE-2014-4057.

EPSS: Средний
github логотип

GHSA-2v3m-6ccx-2995

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2v3j-xqf9-rv5m

больше 1 года назад

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v3j-rxgh-w4rr

около 4 лет назад

In keyguard, there is a possible escalation of privilege due to improper permission checks. This could lead to a local bypass of the keyguard under limited circumstances, with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-119322269

EPSS: Низкий
github логотип

GHSA-2v3j-p6jh-fc8g

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v3j-gjfq-5ccx

около 4 лет назад

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2v3j-g7x7-59j7

больше 1 года назад

Trimble SketchUp Pro SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23885.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2v3h-p724-x392

около 4 лет назад

Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect confidentiality via vectors related to JSON.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2v3g-7257-hfv5

больше 4 лет назад

Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."

EPSS: Средний
github логотип

GHSA-2v3g-4chr-x8h3

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v3f-mxwm-3xrj

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will show the data incorrectly (because it starts at the wrong packet), and clearing the packet list will result in a NULL pointer dereference.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v3v-3whp-953h

starcitizentools/citizen-skin allows stored XSS in user registration date message

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2v3r-wf43-c9gh

The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."

59%
Средний
около 4 лет назад
github логотип
GHSA-2v3r-qqr5-3x33

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v3r-gvq5-qqgh

Dolibarr Cross-site Scripting vulnerability

1%
Низкий
больше 1 года назад
github логотип
GHSA-2v3r-g46p-c64j

Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename).

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v3r-26j9-rjqh

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2v3q-89pj-mhxh

system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective password lengths to eight characters, which makes it easier for context-dependent attackers to successfully conduct brute-force password attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v3m-xrw2-48mj

Buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.0.0.1569 allows remote attackers to execute arbitrary code via a crafted raw_data_frame field in an AAC file.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2v3m-p433-pwh8

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v3m-7w5q-rg4r

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2822, CVE-2014-2823, and CVE-2014-4057.

16%
Средний
около 4 лет назад
github логотип
GHSA-2v3m-6ccx-2995

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0.

CVSS3: 8.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2v3j-xqf9-rv5m

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v3j-rxgh-w4rr

In keyguard, there is a possible escalation of privilege due to improper permission checks. This could lead to a local bypass of the keyguard under limited circumstances, with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-119322269

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v3j-p6jh-fc8g

Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v3j-gjfq-5ccx

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVSS3: 9.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v3j-g7x7-59j7

Trimble SketchUp Pro SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23885.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v3h-p724-x392

Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect confidentiality via vectors related to JSON.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v3g-7257-hfv5

Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."

12%
Средний
больше 4 лет назад
github логотип
GHSA-2v3g-4chr-x8h3

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2v3f-mxwm-3xrj

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will show the data incorrectly (because it starts at the wrong packet), and clearing the packet list will result in a NULL pointer dereference.

CVSS3: 5.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу