Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3qhf-px5p-g68q

около 3 лет назад

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qhf-m339-9g5v

около 1 года назад

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

EPSS: Низкий
github логотип

GHSA-3qhf-g8c6-mhph

9 месяцев назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qhf-7635-fhw3

больше 4 лет назад

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qhc-gwx3-vjc7

около 2 месяцев назад

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qhc-99ww-4gq4

больше 4 лет назад

The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

EPSS: Низкий
github логотип

GHSA-3qh8-qhwr-v2j5

2 месяца назад

A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qh8-fcm2-qxpv

12 месяцев назад

The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qh7-qjj4-qhgh

больше 4 лет назад

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

EPSS: Низкий
github логотип

GHSA-3qh7-pv9c-8cxc

больше 2 лет назад

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qh7-hqp3-w27g

больше 4 лет назад

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

EPSS: Средний
github логотип

GHSA-3qh6-c633-q2hf

больше 4 лет назад

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

EPSS: Низкий
github логотип

GHSA-3qh5-qqj2-c78f

около 3 лет назад

Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qh5-q7jr-f3w8

2 месяца назад

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The unauthenticated REST endpoint POST /wp-json/corvuspay/success/ is registered with permission_callback set to __return_true, and although a signature validation step exists it only logs the result without halting execution, meaning an attacker can supply a completely arbitrary signature and have a malicious approval_code stored in the database unchallenged.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3qh5-grgw-6275

больше 4 лет назад

** DISPUTED ** In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qh5-7pwc-f43p

больше 4 лет назад

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qh5-7339-m5xf

больше 4 лет назад

UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).

EPSS: Низкий
github логотип

GHSA-3qh4-r86r-grvm

около 6 лет назад

Arbitrary JavaScript Execution in typed-function

EPSS: Низкий
github логотип

GHSA-3qh4-83p4-2w86

больше 4 лет назад

In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qh3-fx4r-gprg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qhf-px5p-g68q

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3qhf-m339-9g5v

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

7%
Низкий
около 1 года назад
github логотип
GHSA-3qhf-g8c6-mhph

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3qhf-7635-fhw3

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box.

CVSS3: 5.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3qhc-gwx3-vjc7

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3qhc-99ww-4gq4

The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh8-qhwr-v2j5

A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3qh8-fcm2-qxpv

The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-3qh7-qjj4-qhgh

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh7-pv9c-8cxc

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qh7-hqp3-w27g

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

36%
Средний
больше 4 лет назад
github логотип
GHSA-3qh6-c633-q2hf

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh5-qqj2-c78f

Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients

CVSS3: 7.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3qh5-q7jr-f3w8

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The unauthenticated REST endpoint POST /wp-json/corvuspay/success/ is registered with permission_callback set to __return_true, and although a signature validation step exists it only logs the result without halting execution, meaning an attacker can supply a completely arbitrary signature and have a malicious approval_code stored in the database unchallenged.

CVSS3: 7.2
1%
Низкий
2 месяца назад
github логотип
GHSA-3qh5-grgw-6275

** DISPUTED ** In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability.

CVSS3: 6.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh5-7pwc-f43p

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh5-7339-m5xf

UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh4-r86r-grvm

Arbitrary JavaScript Execution in typed-function

2%
Низкий
около 6 лет назад
github логотип
GHSA-3qh4-83p4-2w86

In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qh3-fx4r-gprg

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу