Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-2qh8-m26v-vcw7

около 4 лет назад

In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qh8-fp5p-2xx2

около 4 лет назад

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2qh8-c5j4-533f

около 4 лет назад

Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via malformed data in a formatted text command.

EPSS: Низкий
github логотип

GHSA-2qh8-6qgx-5jf9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2qh7-289h-fhw7

10 месяцев назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2qh6-hhvv-m2ww

около 4 лет назад

Jenkins HTTP Request Plugin stores HTTP Request passwords unencrypted

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2qh6-98mm-p9vr

больше 1 года назад

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2qh5-xjr3-fwj3

больше 1 года назад

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qh5-69gm-xwrw

около 4 лет назад

Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.

EPSS: Низкий
github логотип

GHSA-2qh4-v69r-w9m5

около 3 лет назад

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read administrator password hash via a web service call. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qh4-8p36-478q

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster noo-jobmonster allows PHP Local File Inclusion.This issue affects Jobmonster: from n/a through <= 4.8.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qh4-728j-5756

около 4 лет назад

cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qh3-fm9g-rf2x

больше 4 лет назад

Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.

EPSS: Низкий
github логотип

GHSA-2qh3-cx4w-cf3x

около 4 лет назад

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: v...

CVSS3: 6.5
EPSS: Высокий
github логотип

GHSA-2qh3-cw4r-2f2r

около 4 лет назад

Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.

EPSS: Низкий
github логотип

GHSA-2qh3-3rmv-x43w

4 месяца назад

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2qh2-hj3f-rhcf

около 4 лет назад

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qgx-m88q-gp35

около 4 лет назад

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2qgx-8w4f-jc5v

больше 3 лет назад

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qgw-p96m-xw4g

6 месяцев назад

PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers can bypass authentication by using '=' 'or' as both username and password to gain unauthorized access to the administrative interface.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qh8-m26v-vcw7

In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qh8-fp5p-2xx2

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

CVSS3: 7.5
31%
Средний
около 4 лет назад
github логотип
GHSA-2qh8-c5j4-533f

Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via malformed data in a formatted text command.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qh8-6qgx-5jf9

Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qh7-289h-fhw7

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2qh6-hhvv-m2ww

Jenkins HTTP Request Plugin stores HTTP Request passwords unencrypted

CVSS3: 3.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qh6-98mm-p9vr

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qh5-xjr3-fwj3

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qh5-69gm-xwrw

Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qh4-v69r-w9m5

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read administrator password hash via a web service call. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2qh4-8p36-478q

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster noo-jobmonster allows PHP Local File Inclusion.This issue affects Jobmonster: from n/a through <= 4.8.2.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2qh4-728j-5756

cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qh3-fm9g-rf2x

Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2qh3-cx4w-cf3x

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: v...

CVSS3: 6.5
79%
Высокий
около 4 лет назад
github логотип
GHSA-2qh3-cw4r-2f2r

Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2qh3-3rmv-x43w

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2qh2-hj3f-rhcf

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.

CVSS3: 6.5
5%
Низкий
около 4 лет назад
github логотип
GHSA-2qgx-m88q-gp35

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2qgx-8w4f-jc5v

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2qgw-p96m-xw4g

PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers can bypass authentication by using '=' 'or' as both username and password to gain unauthorized access to the administrative interface.

CVSS3: 7.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу