Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2h8j-vgqm-q655

около 4 лет назад

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h8j-8r9p-849f

11 месяцев назад

@digitalocean/do-markdownit has Type Confusion vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h8j-6588-5qvp

больше 4 лет назад

Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.

EPSS: Низкий
github логотип

GHSA-2h8j-5vrm-5737

около 4 лет назад

The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2h8h-h9vg-9cr4

около 4 лет назад

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h8h-53wp-5m9q

больше 1 года назад

The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h8g-h9q5-4vvx

больше 2 лет назад

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h8g-7g68-jc42

около 4 лет назад

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2h8f-c5j4-6pq8

больше 4 лет назад

The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.

EPSS: Низкий
github логотип

GHSA-2h8f-5758-wfx8

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h8c-cmrc-4q5c

около 1 месяца назад

ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateWar method. The issue results from an incorrect implementation of cryptographic signature verification. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-28590.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2h88-qxq3-v97j

около 3 лет назад

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h87-x45x-cx46

больше 4 лет назад

LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

EPSS: Низкий
github логотип

GHSA-2h87-mx3g-www9

около 4 лет назад

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h87-4q2w-v4hf

больше 3 лет назад

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-2h87-2x7p-9fjq

около 4 лет назад

An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h86-2qr7-fr73

около 4 лет назад

Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2h85-gg66-hccv

больше 1 года назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2h85-c54w-28vc

больше 4 лет назад

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2h84-xh8m-6c6r

больше 1 года назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer to cause Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, when BGP rib-sharding and update-threading are configured, and a BGP peer flap is done with specific timing, rpd crashes and restarts. Continuous peer flapping at specific time intervals will result in a sustained Denial of Service (DoS) condition. This issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations. This issue requires a remote attacker to have at least one established BGP session. The issue can occur with or without logical-systems enabled. This issue affects: Junos OS: * All versions before 20.4R3-S8, * 21.2 versions before 21.2R3-S6, * 21.3 versions before 21.3R3-S5, * 21.4 versions before 21.4R3-S4, * 22.1 versions before 22.1R3-S3, * 22.2 versions...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h8j-vgqm-q655

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h8j-8r9p-849f

@digitalocean/do-markdownit has Type Confusion vulnerability

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2h8j-6588-5qvp

Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2h8j-5vrm-5737

The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.

CVSS3: 4.7
7%
Низкий
около 4 лет назад
github логотип
GHSA-2h8h-h9vg-9cr4

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-2h8h-53wp-5m9q

The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h8g-h9q5-4vvx

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2h8g-7g68-jc42

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

CVSS3: 3.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h8f-c5j4-6pq8

The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2h8f-5758-wfx8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h8c-cmrc-4q5c

ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateWar method. The issue results from an incorrect implementation of cryptographic signature verification. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-28590.

CVSS3: 7.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2h88-qxq3-v97j

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-2h87-x45x-cx46

LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2h87-mx3g-www9

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2h87-4q2w-v4hf

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

CVSS3: 10
77%
Высокий
больше 3 лет назад
github логотип
GHSA-2h87-2x7p-9fjq

An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h86-2qr7-fr73

Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.

CVSS3: 7.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-2h85-gg66-hccv

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVSS3: 4.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-2h85-c54w-28vc

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-2h84-xh8m-6c6r

An Improper Check for Unusual or Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer to cause Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, when BGP rib-sharding and update-threading are configured, and a BGP peer flap is done with specific timing, rpd crashes and restarts. Continuous peer flapping at specific time intervals will result in a sustained Denial of Service (DoS) condition. This issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations. This issue requires a remote attacker to have at least one established BGP session. The issue can occur with or without logical-systems enabled. This issue affects: Junos OS: * All versions before 20.4R3-S8, * 21.2 versions before 21.2R3-S6, * 21.3 versions before 21.3R3-S5, * 21.4 versions before 21.4R3-S4, * 22.1 versions before 22.1R3-S3, * 22.2 versions...

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу