Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2v2h-p3pv-rrr5

больше 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.

EPSS: Низкий
github логотип

GHSA-2v2g-rr8c-cpwh

около 4 лет назад

NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

EPSS: Низкий
github логотип

GHSA-2v2g-7jx3-jq4g

больше 4 лет назад

Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.

EPSS: Средний
github логотип

GHSA-2v2f-rp8w-vrxh

около 4 лет назад

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2v2f-mvfg-ph56

21 день назад

meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2v2c-wv9c-g6cm

около 2 лет назад

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v2c-pqx4-qvqc

около 3 лет назад

TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v29-2pv7-f546

4 месяца назад

A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes server-side request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.0 is capable of addressing this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2v28-q9qp-f3gx

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v28-fx5v-7xvj

около 4 лет назад

Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v26-h6g3-vrgj

почти 2 года назад

Information disclosure while sending implicit broadcast containing APP launch information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v26-7fm5-rmj8

больше 1 года назад

Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v26-28rg-whvc

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers) Also lm75[] does not serve a purpose anymore after switching to devm_i2c_new_dummy_device() in w83791d_detect_subclients(). The patch fixes possible NULL pointer dereference by removing lm75[]. Found by Linux Driver Verification project (linuxtesting.org). [groeck: Dropped unnecessary continuation lines, fixed multipline alignment]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2v24-xp2p-2gfc

больше 4 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v24-jcvm-2w9j

около 4 лет назад

In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480

EPSS: Низкий
github логотип

GHSA-2v23-4x7f-rh2c

около 4 лет назад

In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v22-8745-vp75

больше 2 лет назад

SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v22-4548-2w5h

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Cross Site Request Forgery.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rxx-5c8g-m33r

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.

EPSS: Низкий
github логотип

GHSA-2rxv-434v-p63q

около 4 лет назад

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v2h-p3pv-rrr5

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v2g-rr8c-cpwh

NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v2g-7jx3-jq4g

Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.

10%
Средний
больше 4 лет назад
github логотип
GHSA-2v2f-rp8w-vrxh

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

CVSS3: 7.5
26%
Средний
около 4 лет назад
github логотип
GHSA-2v2f-mvfg-ph56

meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

CVSS3: 7.4
21 день назад
github логотип
GHSA-2v2c-wv9c-g6cm

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2v2c-pqx4-qvqc

TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2v29-2pv7-f546

A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes server-side request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.0 is capable of addressing this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-2v28-q9qp-f3gx

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2v28-fx5v-7xvj

Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v26-h6g3-vrgj

Information disclosure while sending implicit broadcast containing APP launch information.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2v26-7fm5-rmj8

Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v26-28rg-whvc

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers) Also lm75[] does not serve a purpose anymore after switching to devm_i2c_new_dummy_device() in w83791d_detect_subclients(). The patch fixes possible NULL pointer dereference by removing lm75[]. Found by Linux Driver Verification project (linuxtesting.org). [groeck: Dropped unnecessary continuation lines, fixed multipline alignment]

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2v24-xp2p-2gfc

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v24-jcvm-2w9j

In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v23-4x7f-rh2c

In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v22-8745-vp75

SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2v22-4548-2w5h

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Cross Site Request Forgery.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2rxx-5c8g-m33r

Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rxv-434v-p63q

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.

CVSS3: 7.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу