Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-xr3q-2xmr-89w4

около 1 месяца назад

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xr3p-gm2p-7rx5

около 4 лет назад

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

EPSS: Низкий
github логотип

GHSA-xr3p-ggh8-8r4x

больше 4 лет назад

OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.

EPSS: Низкий
github логотип

GHSA-xr3m-j4q9-hqr4

больше 3 лет назад

Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr3m-6gq6-22cg

больше 1 года назад

Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xr3j-488h-7hfw

10 месяцев назад

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xr3h-hfcp-qxhf

около 4 лет назад

The x86_assign_hw_event function in arch/x86/kernel/cpu/perf_event.c in the Performance Events subsystem in the Linux kernel before 2.6.39 does not properly calculate counter values, which allows local users to cause a denial of service (panic) via the perf program.

EPSS: Низкий
github логотип

GHSA-xr3h-9vvm-4975

около 4 лет назад

CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xr3g-p5r7-2f27

около 4 лет назад

A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr3g-9fg5-527w

около 4 лет назад

S-A WebSTAR DPC2100 v2.0.2r1256-060303 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr3g-4gg5-w3wq

почти 6 лет назад

Malicious Package in degbu

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xr3f-rxj7-wrwj

больше 4 лет назад

Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.

EPSS: Низкий
github логотип

GHSA-xr3f-rqv7-h627

больше 2 лет назад

D-Link DAP-2622 DDP Change ID Password New Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20062.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr3f-844g-572f

5 месяцев назад

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr3c-w29h-2qr9

больше 1 года назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xr3c-8qvg-wf25

около 4 лет назад

The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted packets.

EPSS: Низкий
github логотип

GHSA-xr3c-3fp9-4fcp

больше 3 лет назад

An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr39-rx56-m285

около 4 лет назад

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143792.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr39-5fqf-fr82

около 4 лет назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr38-w74q-r8jv

больше 4 лет назад

Permissions not properly checked in Invenio-Drafts-Resources

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr3q-2xmr-89w4

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xr3p-gm2p-7rx5

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xr3p-ggh8-8r4x

OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3m-j4q9-hqr4

Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xr3m-6gq6-22cg

Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document

CVSS3: 8.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-xr3j-488h-7hfw

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xr3h-hfcp-qxhf

The x86_assign_hw_event function in arch/x86/kernel/cpu/perf_event.c in the Performance Events subsystem in the Linux kernel before 2.6.39 does not properly calculate counter values, which allows local users to cause a denial of service (panic) via the perf program.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xr3h-9vvm-4975

CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

CVSS3: 4.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr3g-p5r7-2f27

A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr3g-9fg5-527w

S-A WebSTAR DPC2100 v2.0.2r1256-060303 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xr3g-4gg5-w3wq

Malicious Package in degbu

CVSS3: 9.1
почти 6 лет назад
github логотип
GHSA-xr3f-rxj7-wrwj

Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3f-rqv7-h627

D-Link DAP-2622 DDP Change ID Password New Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20062.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr3f-844g-572f

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-xr3c-w29h-2qr9

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xr3c-8qvg-wf25

The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted packets.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xr3c-3fp9-4fcp

An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xr39-rx56-m285

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143792.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr39-5fqf-fr82

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xr38-w74q-r8jv

Permissions not properly checked in Invenio-Drafts-Resources

CVSS3: 6.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу