Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mqv-4j3r-vjvp

больше 4 лет назад

Open redirect in @auth0/nextjs-auth0

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2mqr-75c4-43q9

около 4 лет назад

There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may compromise the normal service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mqq-gv4v-qfqf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email.

EPSS: Низкий
github логотип

GHSA-2mqq-97jw-22rf

4 дня назад

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mqq-6v49-g869

почти 2 года назад

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mqp-wcww-qxh6

около 4 лет назад

aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The component is: filterbank. The attack vector is: pass invalid arguments to new_aubio_filterbank. The fixed version is: after commit eda95c9c22b4f0b466ae94c4708765eaae6e709e.

EPSS: Низкий
github логотип

GHSA-2mqp-pffh-p5w7

около 4 лет назад

The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.

EPSS: Низкий
github логотип

GHSA-2mqp-fv5f-wg38

около 4 лет назад

In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mqp-7gq6-4qc7

больше 4 лет назад

Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2mqm-w9vq-9c5r

больше 4 лет назад

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

EPSS: Низкий
github логотип

GHSA-2mqm-qfgv-7589

больше 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mqm-5rfp-3r89

около 4 лет назад

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mqj-m65w-jghx

больше 2 лет назад

Untrusted search path under some conditions on Windows allows arbitrary code execution

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mqj-cxf5-rfwr

почти 2 года назад

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to call the endpoints and perform unauthorized actions such as updating the plugin's settings and injecting malicious scripts.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2mqj-4wv5-2qm3

больше 4 лет назад

The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mqh-v85q-fq9m

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2mqh-jw97-9h7h

больше 3 лет назад

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/registrations/update_status.php of the component Status Update Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221675.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mqg-9v38-rpr6

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.32.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mqf-crhf-c264

9 месяцев назад

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mqf-694r-32x9

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mqv-4j3r-vjvp

Open redirect in @auth0/nextjs-auth0

CVSS3: 6.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mqr-75c4-43q9

There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may compromise the normal service.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2mqq-gv4v-qfqf

Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mqq-97jw-22rf

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
4 дня назад
github логотип
GHSA-2mqq-6v49-g869

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-2mqp-wcww-qxh6

aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The component is: filterbank. The attack vector is: pass invalid arguments to new_aubio_filterbank. The fixed version is: after commit eda95c9c22b4f0b466ae94c4708765eaae6e709e.

около 4 лет назад
github логотип
GHSA-2mqp-pffh-p5w7

The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mqp-fv5f-wg38

In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mqp-7gq6-4qc7

Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2mqm-w9vq-9c5r

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mqm-qfgv-7589

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mqm-5rfp-3r89

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2mqj-m65w-jghx

Untrusted search path under some conditions on Windows allows arbitrary code execution

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mqj-cxf5-rfwr

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to call the endpoints and perform unauthorized actions such as updating the plugin's settings and injecting malicious scripts.

CVSS3: 7.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mqj-4wv5-2qm3

The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2mqh-v85q-fq9m

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-2mqh-jw97-9h7h

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/registrations/update_status.php of the component Status Update Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221675.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mqg-9v38-rpr6

Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.32.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mqf-crhf-c264

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-2mqf-694r-32x9

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад

Уязвимостей на страницу