Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2pp8-6rm9-qr6v

около 4 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2pp7-rwqg-2gcx

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pp6-ppvw-38pj

2 месяца назад

Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pp6-55c2-pfx4

почти 4 года назад

libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pp6-48h2-93h6

около 4 лет назад

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pp5-qr47-7qv2

около 4 лет назад

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with system privileges.

EPSS: Низкий
github логотип

GHSA-2pp5-c2qh-f9wq

3 месяца назад

A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or guess those basic inputs. The issue arises from improper access control on a sensitive data retrieval function.

EPSS: Низкий
github логотип

GHSA-2pp5-7m97-7f6x

почти 4 года назад

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pp4-x986-8w45

около 4 лет назад

The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.

EPSS: Низкий
github логотип

GHSA-2pp4-fggf-q8fx

6 дней назад

Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pp4-6872-69xx

около 4 лет назад

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pp3-pxpf-p8gg

6 месяцев назад

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2pp3-576m-vhmq

около 4 лет назад

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

EPSS: Низкий
github логотип

GHSA-2pp3-2hr3-936m

больше 1 года назад

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2pp2-5h73-4wxg

больше 4 лет назад

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pmx-6mm6-6v72

около 4 лет назад

Smarty arbitrary PHP code execution

EPSS: Низкий
github логотип

GHSA-2pmw-cvc7-frvh

больше 4 лет назад

SQL injection in MCMS

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pmv-xcrh-rqw5

около 4 лет назад

The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.

EPSS: Низкий
github логотип

GHSA-2pmv-wg6j-gf86

больше 1 года назад

The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cc-mortgage-canada' shortcode in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2pmv-p43r-3vvm

около 4 лет назад

Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pp8-6rm9-qr6v

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pp7-rwqg-2gcx

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2pp6-ppvw-38pj

Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2pp6-55c2-pfx4

libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2pp6-48h2-93h6

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pp5-qr47-7qv2

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with system privileges.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2pp5-c2qh-f9wq

A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or guess those basic inputs. The issue arises from improper access control on a sensitive data retrieval function.

0%
Низкий
3 месяца назад
github логотип
GHSA-2pp5-7m97-7f6x

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2pp4-x986-8w45

The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pp4-fggf-q8fx

Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
6 дней назад
github логотип
GHSA-2pp4-6872-69xx

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2pp3-pxpf-p8gg

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
1%
Низкий
6 месяцев назад
github логотип
GHSA-2pp3-576m-vhmq

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2pp3-2hr3-936m

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

CVSS3: 9.8
25%
Средний
больше 1 года назад
github логотип
GHSA-2pp2-5h73-4wxg

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
7%
Низкий
больше 4 лет назад
github логотип
GHSA-2pmx-6mm6-6v72

Smarty arbitrary PHP code execution

3%
Низкий
около 4 лет назад
github логотип
GHSA-2pmw-cvc7-frvh

SQL injection in MCMS

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2pmv-xcrh-rqw5

The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2pmv-wg6j-gf86

The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cc-mortgage-canada' shortcode in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pmv-p43r-3vvm

Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу