Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-3pm3-vpvc-2wpp

больше 3 лет назад

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3pm3-qxfx-hhfp

больше 4 лет назад

The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pm3-j3ch-958q

больше 4 лет назад

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pm3-fg5f-vgvx

2 месяца назад

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pjx-73rp-9mcr

больше 4 лет назад

The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS."

EPSS: Низкий
github логотип

GHSA-3pjx-2q2j-9q65

больше 2 лет назад

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pjw-h9v6-f5x8

больше 4 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pjw-73gf-8qr5

2 месяца назад

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjv-vr3x-68m5

около 4 лет назад

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3pjv-r7w4-2cf5

почти 3 года назад

Grails data binding causes JVM crash and/or other denial of service

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjv-fvwf-87jp

больше 4 лет назад

Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pjr-v8w5-hm42

больше 4 лет назад

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.

EPSS: Низкий
github логотип

GHSA-3pjr-r4gg-jphf

больше 4 лет назад

Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.

EPSS: Низкий
github логотип

GHSA-3pjr-fmjg-gm5p

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjq-c8pr-33gx

больше 3 лет назад

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pjq-2qm6-rh2c

больше 4 лет назад

In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169328517

EPSS: Низкий
github логотип

GHSA-3pjp-qf45-hph3

больше 4 лет назад

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pjm-j8pf-453f

больше 4 лет назад

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.

EPSS: Низкий
github логотип

GHSA-3pjm-7wpc-74xc

больше 3 лет назад

Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.7.1. for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pjj-qpw6-5fcm

3 месяца назад

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pm3-vpvc-2wpp

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVSS3: 9.8
98%
Критический
больше 3 лет назад
github логотип
GHSA-3pm3-qxfx-hhfp

The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm3-j3ch-958q

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pm3-fg5f-vgvx

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.

CVSS3: 8.8
1%
Низкий
2 месяца назад
github логотип
GHSA-3pjx-73rp-9mcr

The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjx-2q2j-9q65

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pjw-h9v6-f5x8

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjw-73gf-8qr5

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3pjv-vr3x-68m5

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3pjv-r7w4-2cf5

Grails data binding causes JVM crash and/or other denial of service

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3pjv-fvwf-87jp

Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjr-v8w5-hm42

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjr-r4gg-jphf

Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjr-fmjg-gm5p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows DOM-Based XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.8.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pjq-c8pr-33gx

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pjq-2qm6-rh2c

In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169328517

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjp-qf45-hph3

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjm-j8pf-453f

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3pjm-7wpc-74xc

Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.7.1. for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pjj-qpw6-5fcm

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

CVSS3: 7.6
0%
Низкий
3 месяца назад

Уязвимостей на страницу