Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mwm-2v2m-5w53

около 4 лет назад

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2mwj-qcpg-4642

больше 4 лет назад

The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.

EPSS: Средний
github логотип

GHSA-2mwj-p2rg-6r6v

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows SQL Injection. This issue affects PDF Invoices for WooCommerce + Drag and Drop Template Builder: from n/a through 5.3.8.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2mwj-jf28-g57f

около 4 лет назад

CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This can for example be used to change the credentials of the administrative webinterface.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mwj-cc94-39wv

около 1 месяца назад

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

EPSS: Низкий
github логотип

GHSA-2mwh-q6h5-vx3r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.

EPSS: Низкий
github логотип

GHSA-2mwh-gp93-cff3

6 месяцев назад

Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpsellWP: from n/a through <= 2.2.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mwh-3gc7-9vvm

больше 4 лет назад

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."

EPSS: Средний
github логотип

GHSA-2mwg-fg86-hrm4

11 месяцев назад

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2mwg-58j6-vmp3

около 4 лет назад

The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2mwg-2rcf-frrv

больше 2 лет назад

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2mwc-h2mg-v6p8

7 месяцев назад

Bagisto has HTML Filter Bypass that Enables Stored XSS

EPSS: Низкий
github логотип

GHSA-2mw9-fq32-5hx4

около 4 лет назад

In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mw9-cpc8-cf9f

около 4 лет назад

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-2mw9-2w9q-w27m

около 4 лет назад

Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mw8-v4w5-29m4

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2mw7-wggm-m6w3

больше 7 лет назад

Denial of Service in ethereumjs-vm

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mw7-f37q-33mg

больше 2 лет назад

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mw7-77qm-cmxc

около 4 лет назад

Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

EPSS: Низкий
github логотип

GHSA-2mw6-86fr-phq8

20 дней назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mwm-2v2m-5w53

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

CVSS3: 7.5
23%
Средний
около 4 лет назад
github логотип
GHSA-2mwj-qcpg-4642

The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.

37%
Средний
больше 4 лет назад
github логотип
GHSA-2mwj-p2rg-6r6v

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows SQL Injection. This issue affects PDF Invoices for WooCommerce + Drag and Drop Template Builder: from n/a through 5.3.8.

CVSS3: 7.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2mwj-jf28-g57f

CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This can for example be used to change the credentials of the administrative webinterface.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mwj-cc94-39wv

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

0%
Низкий
около 1 месяца назад
github логотип
GHSA-2mwh-q6h5-vx3r

Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mwh-gp93-cff3

Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpsellWP: from n/a through <= 2.2.3.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2mwh-3gc7-9vvm

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."

49%
Средний
больше 4 лет назад
github логотип
GHSA-2mwg-fg86-hrm4

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2mwg-58j6-vmp3

The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

CVSS3: 9.8
46%
Средний
около 4 лет назад
github логотип
GHSA-2mwg-2rcf-frrv

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mwc-h2mg-v6p8

Bagisto has HTML Filter Bypass that Enables Stored XSS

1%
Низкий
7 месяцев назад
github логотип
GHSA-2mw9-fq32-5hx4

In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mw9-cpc8-cf9f

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.

CVSS3: 5.5
13%
Средний
около 4 лет назад
github логотип
GHSA-2mw9-2w9q-w27m

Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mw8-v4w5-29m4

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-2mw7-wggm-m6w3

Denial of Service in ethereumjs-vm

CVSS3: 7.5
3%
Низкий
больше 7 лет назад
github логотип
GHSA-2mw7-f37q-33mg

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2mw7-77qm-cmxc

Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

6%
Низкий
около 4 лет назад
github логотип
GHSA-2mw6-86fr-phq8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
20 дней назад

Уязвимостей на страницу