Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2p37-x8h9-2j2q

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.

EPSS: Низкий
github логотип

GHSA-2p37-pq7q-44mr

около 4 лет назад

Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

EPSS: Низкий
github логотип

GHSA-2p37-96m9-9qq9

больше 2 лет назад

TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p36-4f38-pgr5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p35-56jw-vgq5

больше 2 лет назад

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2p34-ppjg-jr32

около 2 месяцев назад

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p34-6p43-4q34

больше 1 года назад

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2p32-7jx3-9vw2

больше 4 лет назад

The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment. NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.

EPSS: Низкий
github логотип

GHSA-2p32-565h-8qfx

11 месяцев назад

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2p2x-x4c8-xrmc

около 4 лет назад

Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS Security as well as unauthorized update, insert or delete access to some of RDBMS Security accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p2x-wcrm-mwm9

около 1 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2p2x-px9w-6j23

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ceph: fix a buffer leak in __ceph_setxattr() The old_blob in __ceph_setxattr() can store ci->i_xattrs.prealloc_blob value during the retry. However, it is never called the ceph_buffer_put() for the old_blob object. This patch fixes the issue of the buffer leak.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p2x-p7wj-j5h2

больше 2 лет назад

PsiTransfer: File integrity violation

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p2x-mw56-jc98

около 4 лет назад

Spoon Library as used in Fork CMS allows PHP object injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p2x-hpg8-cqp2

6 месяцев назад

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2p2x-5p75-jj56

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cmsMinds Pay with Contact Form 7 allows SQL Injection. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2p2w-h5hm-5h78

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.

EPSS: Низкий
github логотип

GHSA-2p2v-34jr-5xcj

больше 2 лет назад

Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p2q-m5g6-rghx

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p2q-7m86-j6ch

больше 1 года назад

An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p37-x8h9-2j2q

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p37-pq7q-44mr

Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2p37-96m9-9qq9

TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2p36-4f38-pgr5

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p35-56jw-vgq5

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2p34-ppjg-jr32

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2p34-6p43-4q34

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2p32-7jx3-9vw2

The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment. NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2p32-565h-8qfx

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-2p2x-x4c8-xrmc

Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS Security as well as unauthorized update, insert or delete access to some of RDBMS Security accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p2x-wcrm-mwm9

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2p2x-px9w-6j23

In the Linux kernel, the following vulnerability has been resolved: ceph: fix a buffer leak in __ceph_setxattr() The old_blob in __ceph_setxattr() can store ci->i_xattrs.prealloc_blob value during the retry. However, it is never called the ceph_buffer_put() for the old_blob object. This patch fixes the issue of the buffer leak.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2p2x-p7wj-j5h2

PsiTransfer: File integrity violation

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2p2x-mw56-jc98

Spoon Library as used in Fork CMS allows PHP object injection

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2p2x-hpg8-cqp2

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

CVSS3: 7.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-2p2x-5p75-jj56

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cmsMinds Pay with Contact Form 7 allows SQL Injection. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.

CVSS3: 7.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-2p2w-h5hm-5h78

Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2p2v-34jr-5xcj

Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2p2q-m5g6-rghx

Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2p2q-7m86-j6ch

An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

CVSS3: 4.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу