Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2hhw-p8mg-jrm6

больше 7 лет назад

Path Traversal in http-live-simulator

EPSS: Низкий
github логотип

GHSA-2hhv-wp8q-p8vm

больше 4 лет назад

gri before 2.12.18 generates temporary files in an insecure way.

EPSS: Низкий
github логотип

GHSA-2hhv-v3hc-2xgx

около 4 лет назад

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2hhr-r74q-p8fq

около 4 лет назад

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.

EPSS: Низкий
github логотип

GHSA-2hhr-933m-5jmg

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2hhq-c99x-492r

около 1 месяца назад

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2hhq-96pp-rf56

около 4 лет назад

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

EPSS: Низкий
github логотип

GHSA-2hhp-wrh5-g527

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2hhp-r87h-qvgj

больше 4 лет назад

Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

EPSS: Низкий
github логотип

GHSA-2hhp-373f-h757

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi.

EPSS: Низкий
github логотип

GHSA-2hhm-rw5g-m2vq

7 дней назад

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hhm-gh43-f53h

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2hhm-535h-jfpf

больше 1 года назад

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2hhh-gxpg-w8vr

около 4 лет назад

The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-2hhg-c3w2-vgr6

больше 4 лет назад

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

EPSS: Низкий
github логотип

GHSA-2hhg-24wg-6mmv

больше 1 года назад

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hhf-q463-9hv4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

EPSS: Низкий
github логотип

GHSA-2hhf-gxff-r59q

почти 3 года назад

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hhf-9f74-3jqg

8 месяцев назад

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hhc-f86x-x74f

около 4 лет назад

Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hhw-p8mg-jrm6

Path Traversal in http-live-simulator

3%
Низкий
больше 7 лет назад
github логотип
GHSA-2hhv-wp8q-p8vm

gri before 2.12.18 generates temporary files in an insecure way.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hhv-v3hc-2xgx

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.

CVSS3: 7.5
69%
Средний
около 4 лет назад
github логотип
GHSA-2hhr-r74q-p8fq

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2hhr-933m-5jmg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-2hhq-c99x-492r

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2hhq-96pp-rf56

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hhp-wrh5-g527

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-2hhp-r87h-qvgj

Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2hhp-373f-h757

Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hhm-rw5g-m2vq

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-2hhm-gh43-f53h

Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hhm-535h-jfpf

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hhh-gxpg-w8vr

The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."

23%
Средний
около 4 лет назад
github логотип
GHSA-2hhg-c3w2-vgr6

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2hhg-24wg-6mmv

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hhf-q463-9hv4

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hhf-gxff-r59q

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-2hhf-9f74-3jqg

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2hhc-f86x-x74f

Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin

CVSS3: 6.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу