Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p9v-cwqh-2mxm

около 2 месяцев назад

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9v-8h44-8rrr

больше 3 лет назад

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3p9v-2c3q-cf4v

почти 2 года назад

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p9r-x2jj-qm7x

почти 4 года назад

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9r-g8j3-8wq4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

EPSS: Низкий
github логотип

GHSA-3p9r-c4wp-v55p

больше 4 лет назад

** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. NOTE: the vendor does not recognize this issue and will not patch it.

EPSS: Низкий
github логотип

GHSA-3p9r-c4f8-vv7m

около 2 лет назад

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p9r-9j6c-6wxp

больше 4 лет назад

Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.

EPSS: Низкий
github логотип

GHSA-3p9q-h8m3-5629

около 1 месяца назад

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3p9q-7w63-3f8q

больше 1 года назад

Withdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9q-2c9q-vq29

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu allows Cross Site Request Forgery. This issue affects Bubble Menu – circle floating menu: from n/a through 4.0.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p9p-rmqp-8m38

больше 4 лет назад

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p9p-h6x6-85gg

почти 4 года назад

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9p-8j59-v9h3

около 2 месяцев назад

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3p9p-84c4-78r8

больше 4 лет назад

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.

EPSS: Низкий
github логотип

GHSA-3p9p-5vw4-h64q

2 дня назад

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3p9p-59qf-mqwh

около 3 лет назад

Apache InLong has Files or Directories Accessible to External Parties

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p9m-6822-r65w

около 1 года назад

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the file /goform/RP_setBasicAuto. The manipulation of the argument staticIp/staticNetmask leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3p9j-x42f-p86h

больше 2 лет назад

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3p9j-442x-hjp7

больше 4 лет назад

Business Logic Errors in microweber

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p9v-cwqh-2mxm

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3p9v-8h44-8rrr

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9v-2c3q-cf4v

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p9r-x2jj-qm7x

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3p9r-g8j3-8wq4

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9r-c4wp-v55p

** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. NOTE: the vendor does not recognize this issue and will not patch it.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9r-c4f8-vv7m

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3p9r-9j6c-6wxp

Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9q-h8m3-5629

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3p9q-7w63-3f8q

Withdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS3: 6.5
больше 1 года назад
github логотип
GHSA-3p9q-2c9q-vq29

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu allows Cross Site Request Forgery. This issue affects Bubble Menu – circle floating menu: from n/a through 4.0.2.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p9p-rmqp-8m38

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9p-h6x6-85gg

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3p9p-8j59-v9h3

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.

CVSS3: 5.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3p9p-84c4-78r8

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9p-5vw4-h64q

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.4
0%
Низкий
2 дня назад
github логотип
GHSA-3p9p-59qf-mqwh

Apache InLong has Files or Directories Accessible to External Parties

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p9m-6822-r65w

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the file /goform/RP_setBasicAuto. The manipulation of the argument staticIp/staticNetmask leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
8%
Низкий
около 1 года назад
github логотип
GHSA-3p9j-x42f-p86h

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p9j-442x-hjp7

Business Logic Errors in microweber

CVSS3: 5.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу