Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2jv5-xv66-fhx8

около 2 лет назад

A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2jv5-wvvg-c9hj

около 4 лет назад

Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2jv5-mm7g-6r3r

около 4 лет назад

SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jv5-h643-m9jp

около 4 лет назад

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.

EPSS: Низкий
github логотип

GHSA-2jv5-9r88-3w3p

больше 2 лет назад

python-multipart vulnerable to Content-Type Header ReDoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jv5-59rp-vmgj

около 2 лет назад

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2jv5-2qvr-82qr

18 дней назад

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jv4-vc4g-7mp7

около 4 лет назад

Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.

EPSS: Низкий
github логотип

GHSA-2jv4-g2j5-gcgx

около 1 года назад

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2jv4-86qg-m23h

больше 1 года назад

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2jv4-596w-g9hj

8 месяцев назад

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jv4-4qp4-gcjc

около 4 лет назад

Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2jv3-v37p-65w3

почти 4 года назад

CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2jv3-mh5v-j4w2

около 4 лет назад

Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.

EPSS: Низкий
github логотип

GHSA-2jv3-8jp8-xgcm

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2jv2-97wr-gpc9

около 4 лет назад

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jrx-vp4g-6wgj

около 1 года назад

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jrx-hm6v-q9c6

больше 4 лет назад

SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.

EPSS: Низкий
github логотип

GHSA-2jrx-fmqr-7h3v

больше 1 года назад

Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2jrw-c95w-h43g

около 1 месяца назад

Mautic has an Authorization Bypass in API v2 Endpoints

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jv5-xv66-fhx8

A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.

CVSS3: 4.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-2jv5-wvvg-c9hj

Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2jv5-mm7g-6r3r

SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jv5-h643-m9jp

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jv5-9r88-3w3p

python-multipart vulnerable to Content-Type Header ReDoS

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2jv5-59rp-vmgj

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2jv5-2qvr-82qr

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
18 дней назад
github логотип
GHSA-2jv4-vc4g-7mp7

Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2jv4-g2j5-gcgx

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2jv4-86qg-m23h

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 2.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-2jv4-596w-g9hj

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jv4-4qp4-gcjc

Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

6%
Низкий
около 4 лет назад
github логотип
GHSA-2jv3-v37p-65w3

CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-2jv3-mh5v-j4w2

Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2jv3-8jp8-xgcm

Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jv2-97wr-gpc9

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2jrx-vp4g-6wgj

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2jrx-hm6v-q9c6

SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2jrx-fmqr-7h3v

Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jrw-c95w-h43g

Mautic has an Authorization Bypass in API v2 Endpoints

CVSS3: 7.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу