Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2jmf-ff5x-92qw

около 4 лет назад

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

EPSS: Низкий
github логотип

GHSA-2jmf-7qjf-v556

около 4 лет назад

Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jmc-8g4c-98px

больше 1 года назад

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jm7-77px-69qh

около 4 лет назад

Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jm6-v38h-g4f5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: this issue exists because of an incomplete fix for CVE-2008-1168.

EPSS: Низкий
github логотип

GHSA-2jm6-mf4v-38fj

3 месяца назад

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2jm5-p544-m6xw

около 4 лет назад

Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arbitrary code via a crafted VP6 (1) video file or (2) video stream.

EPSS: Низкий
github логотип

GHSA-2jm5-gphf-c739

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in FrescoChat Live Chat allows Stored XSS. This issue affects FrescoChat Live Chat: from n/a through 3.2.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2jm5-2cqf-6vw9

почти 6 лет назад

Malicious Package in baes-x

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2jm4-pp6h-mpwx

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes EcoGrow ecogrow allows PHP Local File Inclusion.This issue affects EcoGrow: from n/a through <= 1.7.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2jm4-m62p-325r

почти 2 года назад

A privilege escalation vulnerability exists in the Veertu Anka Build 1.42.0. The vulnerability occurs during Anka node agent update. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jm4-cm7h-hghg

больше 4 лет назад

Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

EPSS: Низкий
github логотип

GHSA-2jm4-4x2h-4g5p

12 месяцев назад

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2jm3-gfcg-hh57

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2jm3-4crv-w9ff

больше 1 года назад

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within a project and injecting malicious JavaScript into the "memo" field. The memo field has a hover over action that will display a Microsoft Tool Tip which a user can use to quickly view the memo associated with the slide and execute the JavaScript.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2jm2-q946-gq54

больше 3 лет назад

An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jm2-2p35-rp3j

8 месяцев назад

OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jjw-vxxv-7gqg

почти 2 года назад

The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2jjv-qf24-vfm4

10 месяцев назад

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

EPSS: Низкий
github логотип

GHSA-2jjr-f7gv-3rc9

2 месяца назад

Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jmf-ff5x-92qw

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jmf-7qjf-v556

Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2jmc-8g4c-98px

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jm7-77px-69qh

Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2jm6-v38h-g4f5

Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: this issue exists because of an incomplete fix for CVE-2008-1168.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jm6-mf4v-38fj

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2jm5-p544-m6xw

Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arbitrary code via a crafted VP6 (1) video file or (2) video stream.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2jm5-gphf-c739

Cross-Site Request Forgery (CSRF) vulnerability in FrescoChat Live Chat allows Stored XSS. This issue affects FrescoChat Live Chat: from n/a through 3.2.6.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jm5-2cqf-6vw9

Malicious Package in baes-x

CVSS3: 9.1
почти 6 лет назад
github логотип
GHSA-2jm4-pp6h-mpwx

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes EcoGrow ecogrow allows PHP Local File Inclusion.This issue affects EcoGrow: from n/a through <= 1.7.

CVSS3: 8.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jm4-m62p-325r

A privilege escalation vulnerability exists in the Veertu Anka Build 1.42.0. The vulnerability occurs during Anka node agent update. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jm4-cm7h-hghg

Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2jm4-4x2h-4g5p

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-2jm3-gfcg-hh57

Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jm3-4crv-w9ff

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within a project and injecting malicious JavaScript into the "memo" field. The memo field has a hover over action that will display a Microsoft Tool Tip which a user can use to quickly view the memo associated with the slide and execute the JavaScript.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jm2-q946-gq54

An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jm2-2p35-rp3j

OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jjw-vxxv-7gqg

The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jjv-qf24-vfm4

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

0%
Низкий
10 месяцев назад
github логотип
GHSA-2jjr-f7gv-3rc9

Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу