Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 345 180

Количество 345 180

github логотип

GHSA-245h-pqqx-gc7r

около 4 лет назад

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."

EPSS: Средний
github логотип

GHSA-245h-h68p-v4jq

около 2 лет назад

crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-245h-cphj-6cq7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.

EPSS: Низкий
github логотип

GHSA-245h-2vpj-f5xp

около 4 лет назад

Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

EPSS: Низкий
github логотип

GHSA-245g-gjxh-59c2

около 4 лет назад

Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.

EPSS: Низкий
github логотип

GHSA-245g-9f78-5jxc

почти 3 года назад

There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-245c-q43g-42cq

около 4 лет назад

Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.

EPSS: Низкий
github логотип

GHSA-245c-fpfx-q2mm

около 2 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.3.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2459-9w34-v79g

больше 3 лет назад

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2458-wgmh-qq6g

около 4 лет назад

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2458-q378-h4hg

больше 4 лет назад

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

EPSS: Низкий
github логотип

GHSA-2457-vhh5-pcc4

около 4 лет назад

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

EPSS: Низкий
github логотип

GHSA-2457-jhx6-82v4

около 4 лет назад

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2457-j253-9gg8

около 2 лет назад

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2457-gqr3-47vq

около 3 лет назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2457-2263-mm9f

больше 4 лет назад

Memory leak in micronaut-core

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2456-wh5h-jwph

2 месяца назад

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2456-m625-hcj6

почти 3 года назад

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2456-4748-m2m2

7 месяцев назад

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2455-m68h-qwxv

около 1 месяца назад

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-245h-pqqx-gc7r

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."

22%
Средний
около 4 лет назад
github логотип
GHSA-245h-h68p-v4jq

crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-245h-cphj-6cq7

Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.

1%
Низкий
около 4 лет назад
github логотип
GHSA-245h-2vpj-f5xp

Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

5%
Низкий
около 4 лет назад
github логотип
GHSA-245g-gjxh-59c2

Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.

2%
Низкий
около 4 лет назад
github логотип
GHSA-245g-9f78-5jxc

There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.

CVSS3: 8.6
1%
Низкий
почти 3 года назад
github логотип
GHSA-245c-q43g-42cq

Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.

7%
Низкий
около 4 лет назад
github логотип
GHSA-245c-fpfx-q2mm

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.3.7.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-2459-9w34-v79g

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2458-wgmh-qq6g

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2458-q378-h4hg

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2457-vhh5-pcc4

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2457-jhx6-82v4

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
3%
Низкий
около 4 лет назад
github логотип
GHSA-2457-j253-9gg8

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2457-gqr3-47vq

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2457-2263-mm9f

Memory leak in micronaut-core

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2456-wh5h-jwph

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-2456-m625-hcj6

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2456-4748-m2m2

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2455-m68h-qwxv

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу