Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3pm5-qmcr-c546

больше 4 лет назад

Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3pm5-9xjq-m3q6

больше 4 лет назад

Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.

EPSS: Средний
github логотип

GHSA-3pm4-p625-gqmh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote attackers to inject arbitrary web script or HTML via the livezilla parameter in a track action to server.php.

EPSS: Низкий
github логотип

GHSA-3pm4-mcqw-jq89

7 месяцев назад

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before 11.0.5-00; Hitachi Device Manager: from 8.4.1-00 before 8.6.5-00.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-3pm4-j65g-c8hx

больше 1 года назад

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3pm4-hp5q-g8qj

больше 4 лет назад

cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape sequences and execute arbitrary commands or delete arbitrary files via a crafted HTTP request.

EPSS: Низкий
github логотип

GHSA-3pm4-f769-q6pg

больше 4 лет назад

The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unattended workstation.

EPSS: Низкий
github логотип

GHSA-3pm4-cw53-2cg9

15 дней назад

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers without authorization.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3pm4-9c7g-c576

больше 2 лет назад

A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/applicants/index.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257387.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3pm3-vpvc-2wpp

больше 3 лет назад

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3pm3-qxfx-hhfp

больше 4 лет назад

The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pm3-j3ch-958q

больше 4 лет назад

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pm3-fg5f-vgvx

2 месяца назад

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pjx-73rp-9mcr

больше 4 лет назад

The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS."

EPSS: Низкий
github логотип

GHSA-3pjx-2q2j-9q65

больше 2 лет назад

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pjw-h9v6-f5x8

больше 4 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pjw-73gf-8qr5

около 2 месяцев назад

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjv-vr3x-68m5

около 4 лет назад

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3pjv-r7w4-2cf5

больше 2 лет назад

Grails data binding causes JVM crash and/or other denial of service

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjv-fvwf-87jp

больше 4 лет назад

Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pm5-qmcr-c546

Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm5-9xjq-m3q6

Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.

11%
Средний
больше 4 лет назад
github логотип
GHSA-3pm4-p625-gqmh

Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote attackers to inject arbitrary web script or HTML via the livezilla parameter in a track action to server.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm4-mcqw-jq89

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before 11.0.5-00; Hitachi Device Manager: from 8.4.1-00 before 8.6.5-00.

CVSS3: 5.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-3pm4-j65g-c8hx

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pm4-hp5q-g8qj

cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape sequences and execute arbitrary commands or delete arbitrary files via a crafted HTTP request.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm4-f769-q6pg

The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unattended workstation.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm4-cw53-2cg9

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific roles, banned flags, and managed topic identifiers without authorization.

CVSS3: 4.3
0%
Низкий
15 дней назад
github логотип
GHSA-3pm4-9c7g-c576

A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/applicants/index.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257387.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pm3-vpvc-2wpp

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVSS3: 9.8
98%
Критический
больше 3 лет назад
github логотип
GHSA-3pm3-qxfx-hhfp

The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm3-j3ch-958q

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm3-fg5f-vgvx

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.

CVSS3: 8.8
1%
Низкий
2 месяца назад
github логотип
GHSA-3pjx-73rp-9mcr

The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjx-2q2j-9q65

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pjw-h9v6-f5x8

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjw-73gf-8qr5

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3pjv-vr3x-68m5

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3pjv-r7w4-2cf5

Grails data binding causes JVM crash and/or other denial of service

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pjv-fvwf-87jp

Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу