Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 343 108

Количество 343 108

github логотип

GHSA-23vw-j76w-cpcq

больше 1 года назад

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-23vv-v25h-qwqw

около 4 лет назад

Improper Input Validation in Apache Axis2

EPSS: Средний
github логотип

GHSA-23vm-xcmr-85gw

больше 4 лет назад

Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations.

EPSS: Низкий
github логотип

GHSA-23vm-r6m3-8q9g

5 месяцев назад

Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.3.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23vm-fxf4-h89x

около 1 года назад

The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23vm-fc59-7qjv

около 4 лет назад

During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

EPSS: Низкий
github логотип

GHSA-23vj-j6jc-w892

9 месяцев назад

Jenkins Curseforge Publisher Plugin stores API Keys unencrypted in job config.xml files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23vj-5jhc-26rp

около 3 лет назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23vh-hx6h-jwg7

около 4 лет назад

Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDNET).

EPSS: Низкий
github логотип

GHSA-23vg-hxh3-rg5v

около 4 лет назад

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2013-1510.

EPSS: Низкий
github логотип

GHSA-23vg-8xc3-j64m

около 2 лет назад

The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23vf-vjgx-x757

около 4 лет назад

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

EPSS: Низкий
github логотип

GHSA-23vf-m99m-mvr7

8 месяцев назад

SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23vf-7h8p-j4qp

больше 4 лет назад

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.

EPSS: Низкий
github логотип

GHSA-23vf-5g53-hm9q

около 8 лет назад

Directory Traversal in list-n-stream

EPSS: Низкий
github логотип

GHSA-23vc-rx4m-j285

больше 4 лет назад

PHP remote file inclusion vulnerability in cmpro_header.inc.php in Clan Manager Pro (CMPRO) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) cm_ext_server and (2) sitepath parameters.

EPSS: Низкий
github логотип

GHSA-23vc-r48x-wwpp

больше 1 года назад

Missing Authorization vulnerability in RumbleTalk Ltd RumbleTalk Live Group Chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through 6.2.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23v9-8jvm-jh7q

около 4 лет назад

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23v9-73rv-qxqj

больше 2 лет назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-23v8-p364-5gvm

около 4 лет назад

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23vw-j76w-cpcq

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-23vv-v25h-qwqw

Improper Input Validation in Apache Axis2

22%
Средний
около 4 лет назад
github логотип
GHSA-23vm-xcmr-85gw

Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23vm-r6m3-8q9g

Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.3.1.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-23vm-fxf4-h89x

The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-23vm-fc59-7qjv

During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

2%
Низкий
около 4 лет назад
github логотип
GHSA-23vj-j6jc-w892

Jenkins Curseforge Publisher Plugin stores API Keys unencrypted in job config.xml files

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-23vj-5jhc-26rp

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-23vh-hx6h-jwg7

Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDNET).

1%
Низкий
около 4 лет назад
github логотип
GHSA-23vg-hxh3-rg5v

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2013-1510.

2%
Низкий
около 4 лет назад
github логотип
GHSA-23vg-8xc3-j64m

The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-23vf-vjgx-x757

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23vf-m99m-mvr7

SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-23vf-7h8p-j4qp

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-23vf-5g53-hm9q

Directory Traversal in list-n-stream

2%
Низкий
около 8 лет назад
github логотип
GHSA-23vc-rx4m-j285

PHP remote file inclusion vulnerability in cmpro_header.inc.php in Clan Manager Pro (CMPRO) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) cm_ext_server and (2) sitepath parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23vc-r48x-wwpp

Missing Authorization vulnerability in RumbleTalk Ltd RumbleTalk Live Group Chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through 6.2.5.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-23v9-8jvm-jh7q

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-23v9-73rv-qxqj

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later

CVSS3: 3.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23v8-p364-5gvm

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.

3%
Низкий
около 4 лет назад

Уязвимостей на страницу