Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2pm8-xgpx-w63v

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HireHive HireHive Job Plugin allows Stored XSS.This issue affects HireHive Job Plugin: from n/a through 2.9.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pm8-794w-p8m4

2 месяца назад

Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2pm7-wcx5-9h5j

около 4 лет назад

Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter to index.php.

EPSS: Низкий
github логотип

GHSA-2pm7-q8pc-xhvq

около 4 лет назад

MantisBT HTML Injection vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2pm7-3m95-7x49

больше 3 лет назад

Repetier Server through 1.4.10 does not have CSRF protection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pm6-rcw9-992f

4 месяца назад

UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-2pm6-hr95-ggxq

12 месяцев назад

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2pm6-9fhx-vvg3

5 месяцев назад

The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pm5-r39v-pr4r

около 4 лет назад

SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2pm5-h4rp-cjq3

больше 4 лет назад

The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack.

EPSS: Низкий
github логотип

GHSA-2pm5-c2hr-7xg4

больше 4 лет назад

Remote Desktop Protocol Remote Code Execution Vulnerability.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2pm5-4pq3-87vj

больше 1 года назад

Missing Authorization vulnerability in Israpil Textmetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Textmetrics: from n/a through 3.6.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pm4-86cq-h56g

около 4 лет назад

ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2pm2-v5jq-cp26

больше 4 лет назад

cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2pm2-h49w-3rj5

больше 3 лет назад

An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pm2-cpjx-462g

больше 2 лет назад

Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2pm2-9wvh-w2w9

почти 2 года назад

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pjx-wvcg-vhr8

больше 1 года назад

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CVSS3: 7
EPSS: Средний
github логотип

GHSA-2pjx-v75h-827m

больше 3 лет назад

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pjx-m5vr-xg6f

больше 4 лет назад

Multiple integer overflows in the (1) dodecrypt and (2) doencrypt functions in cfs_fh.c in cfsd in Matt Blaze Cryptographic File System (CFS) 1.4.1 before Debian GNU/Linux package 1.4.1-17 allow local users to cause a denial of service (daemon crash) by appending data to a file that is larger than 2 Gb.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pm8-xgpx-w63v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HireHive HireHive Job Plugin allows Stored XSS.This issue affects HireHive Job Plugin: from n/a through 2.9.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pm8-794w-p8m4

Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2pm7-wcx5-9h5j

Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter to index.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2pm7-q8pc-xhvq

MantisBT HTML Injection vulnerability

CVSS3: 4.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pm7-3m95-7x49

Repetier Server through 1.4.10 does not have CSRF protection.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pm6-rcw9-992f

UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 4.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2pm6-hr95-ggxq

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-2pm6-9fhx-vvg3

The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-2pm5-r39v-pr4r

SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2pm5-h4rp-cjq3

The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2pm5-c2hr-7xg4

Remote Desktop Protocol Remote Code Execution Vulnerability.

CVSS3: 8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-2pm5-4pq3-87vj

Missing Authorization vulnerability in Israpil Textmetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Textmetrics: from n/a through 3.6.1.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pm4-86cq-h56g

ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2pm2-v5jq-cp26

cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.

CVSS3: 9.8
23%
Средний
больше 4 лет назад
github логотип
GHSA-2pm2-h49w-3rj5

An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2pm2-cpjx-462g

Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2pm2-9wvh-w2w9

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2pjx-wvcg-vhr8

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CVSS3: 7
67%
Средний
больше 1 года назад
github логотип
GHSA-2pjx-v75h-827m

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2pjx-m5vr-xg6f

Multiple integer overflows in the (1) dodecrypt and (2) doencrypt functions in cfs_fh.c in cfsd in Matt Blaze Cryptographic File System (CFS) 1.4.1 before Debian GNU/Linux package 1.4.1-17 allow local users to cause a denial of service (daemon crash) by appending data to a file that is larger than 2 Gb.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу