Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2m4c-5v2r-9p3g

около 4 лет назад

libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2m49-jgww-vg42

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ERA404 CropRefine croprefine allows Reflected XSS.This issue affects CropRefine: from n/a through <= 1.2.1.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2m49-58pm-gx29

около 4 лет назад

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2m48-r7v9-8g4w

больше 4 лет назад

SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.

EPSS: Низкий
github логотип

GHSA-2m48-jx4v-6c4h

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m47-wrp6-46m6

около 2 месяцев назад

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 23.0.3 is sufficient to resolve this issue. The identifier of the patch is f1b2dd6481e22cacb561d29ffdcd3a50b618479d. Upgrading the affected component is advised.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2m47-v5fj-pw7f

больше 2 лет назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2m47-7r27-xh85

больше 2 лет назад

There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2m46-rjm4-w49x

около 2 лет назад

LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. Was ZDI-CAN-19919.

CVSS3: 8.2
EPSS: Высокий
github логотип

GHSA-2m46-g734-85f6

около 4 лет назад

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m45-cxx6-49pg

около 4 лет назад

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2m44-r2x5-4q79

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() From the memory-barriers.txt document regarding memory barrier ordering guarantees: (*) These guarantees do not apply to bitfields, because compilers often generate code to modify these using non-atomic read-modify-write sequences. Do not attempt to use bitfields to synchronize parallel algorithms. (*) Even in cases where bitfields are protected by locks, all fields in a given bitfield must be protected by one lock. If two fields in a given bitfield are protected by different locks, the compiler's non-atomic read-modify-write sequences can cause an update to one field to corrupt the value of an adjacent field. btrfs_space_info has a bitfield sharing an underlying word consisting of the fields full, chunk_alloc, and flush: struct btrfs_space_info { struct btrfs_fs_info * fs_info; /* ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m44-793w-9x5c

почти 2 года назад

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m43-qgqq-69c7

больше 1 года назад

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2m42-3qgm-3769

больше 4 лет назад

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m3x-c3pv-g7qv

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.

EPSS: Низкий
github логотип

GHSA-2m3w-xcjp-43pq

около 4 лет назад

Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), 2018.08(11.51), 2018.11(11.60), 2019.02(11.70), 2019.05(11.80), 2019.08(11.90), 2019.11(11.91), 2020.05(11.92), 2020.10(11.93). The vulnerability could allow remote attackers to execute arbitrary code on affected installations of SiteScope.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m3w-662q-8c6m

почти 4 года назад

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m3v-v2m8-q956

8 месяцев назад

Denial of Service Vulnerability in React Server Components

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2m3v-qx42-rv95

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m4c-5v2r-9p3g

libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2m49-jgww-vg42

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ERA404 CropRefine croprefine allows Reflected XSS.This issue affects CropRefine: from n/a through <= 1.2.1.

CVSS3: 9.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-2m49-58pm-gx29

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

CVSS3: 7.5
57%
Средний
около 4 лет назад
github логотип
GHSA-2m48-r7v9-8g4w

SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2m48-jx4v-6c4h

Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2m47-wrp6-46m6

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 23.0.3 is sufficient to resolve this issue. The identifier of the patch is f1b2dd6481e22cacb561d29ffdcd3a50b618479d. Upgrading the affected component is advised.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2m47-v5fj-pw7f

Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2m47-7r27-xh85

There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2m46-rjm4-w49x

LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. Was ZDI-CAN-19919.

CVSS3: 8.2
84%
Высокий
около 2 лет назад
github логотип
GHSA-2m46-g734-85f6

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

CVSS3: 6.1
4%
Низкий
около 4 лет назад
github логотип
GHSA-2m45-cxx6-49pg

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m44-r2x5-4q79

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() From the memory-barriers.txt document regarding memory barrier ordering guarantees: (*) These guarantees do not apply to bitfields, because compilers often generate code to modify these using non-atomic read-modify-write sequences. Do not attempt to use bitfields to synchronize parallel algorithms. (*) Even in cases where bitfields are protected by locks, all fields in a given bitfield must be protected by one lock. If two fields in a given bitfield are protected by different locks, the compiler's non-atomic read-modify-write sequences can cause an update to one field to corrupt the value of an adjacent field. btrfs_space_info has a bitfield sharing an underlying word consisting of the fields full, chunk_alloc, and flush: struct btrfs_space_info { struct btrfs_fs_info * fs_info; /* ...

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2m44-793w-9x5c

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

CVSS3: 9.8
3%
Низкий
почти 2 года назад
github логотип
GHSA-2m43-qgqq-69c7

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2m42-3qgm-3769

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2m3x-c3pv-g7qv

Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m3w-xcjp-43pq

Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), 2018.08(11.51), 2018.11(11.60), 2019.02(11.70), 2019.05(11.80), 2019.08(11.90), 2019.11(11.91), 2020.05(11.92), 2020.10(11.93). The vulnerability could allow remote attackers to execute arbitrary code on affected installations of SiteScope.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2m3w-662q-8c6m

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2m3v-v2m8-q956

Denial of Service Vulnerability in React Server Components

CVSS3: 7.5
66%
Средний
8 месяцев назад
github логотип
GHSA-2m3v-qx42-rv95

Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу