Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3pjr-v8w5-hm42

больше 4 лет назад

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.

EPSS: Низкий
github логотип

GHSA-3pjr-r4gg-jphf

больше 4 лет назад

Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.

EPSS: Низкий
github логотип

GHSA-3pjr-fmjg-gm5p

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjq-c8pr-33gx

больше 3 лет назад

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjq-2qm6-rh2c

больше 4 лет назад

In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169328517

EPSS: Низкий
github логотип

GHSA-3pjp-qf45-hph3

больше 4 лет назад

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pjm-j8pf-453f

больше 4 лет назад

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.

EPSS: Низкий
github логотип

GHSA-3pjm-7wpc-74xc

больше 3 лет назад

Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.7.1. for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pjj-qpw6-5fcm

3 месяца назад

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3pjj-9jv7-w6xw

больше 4 лет назад

The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

EPSS: Низкий
github логотип

GHSA-3pjj-89j6-25qq

больше 4 лет назад

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

EPSS: Низкий
github логотип

GHSA-3pjj-2f8w-vhh5

больше 1 года назад

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3pjh-hjmx-5pvh

больше 4 лет назад

Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-3pjh-8rj7-xm2h

больше 4 лет назад

In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.

EPSS: Низкий
github логотип

GHSA-3pjh-4p3m-3gfm

больше 2 лет назад

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pjg-h7vp-42p9

11 месяцев назад

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3pjg-4x3p-x3mq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter.

EPSS: Низкий
github логотип

GHSA-3pjg-2wrm-q2x2

больше 4 лет назад

A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.

EPSS: Низкий
github логотип

GHSA-3pjf-v2wg-p54r

больше 4 лет назад

chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption.

EPSS: Низкий
github логотип

GHSA-3pjf-h669-775r

6 месяцев назад

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pjr-v8w5-hm42

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjr-r4gg-jphf

Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjr-fmjg-gm5p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pjq-c8pr-33gx

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pjq-2qm6-rh2c

In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169328517

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjp-qf45-hph3

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjm-j8pf-453f

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjm-7wpc-74xc

Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.7.1. for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pjj-qpw6-5fcm

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

CVSS3: 7.6
0%
Низкий
3 месяца назад
github логотип
GHSA-3pjj-9jv7-w6xw

The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjj-89j6-25qq

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjj-2f8w-vhh5

The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pjh-hjmx-5pvh

Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."

31%
Средний
больше 4 лет назад
github логотип
GHSA-3pjh-8rj7-xm2h

In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjh-4p3m-3gfm

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3pjg-h7vp-42p9

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3pjg-4x3p-x3mq

Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjg-2wrm-q2x2

A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjf-v2wg-p54r

chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjf-h669-775r

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

CVSS3: 8.8
1%
Низкий
6 месяцев назад

Уязвимостей на страницу