Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2gw7-672m-m38x

около 4 лет назад

The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gw6-v2h7-g6vm

больше 4 лет назад

A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

EPSS: Низкий
github логотип

GHSA-2gw6-73wc-x88f

около 4 лет назад

Apache Geode information disclosure vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gw5-9px7-vp56

почти 3 года назад

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2gw3-mxrj-jwhh

около 4 лет назад

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gw2-qgjg-xh6p

больше 1 года назад

Namada-apps allows Post-Genesis Validator Bypass

EPSS: Низкий
github логотип

GHSA-2gw2-8q9w-cw8p

почти 8 лет назад

Ruby-ffi has a DLL loading issue

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gvx-rx63-w97c

около 4 лет назад

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.

EPSS: Низкий
github логотип

GHSA-2gvx-cpxc-42hj

около 4 лет назад

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gvx-5frj-6px5

больше 2 лет назад

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gvx-55m9-gpjj

3 месяца назад

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, including privileged users such as administrators. This allows unauthorized access/read to sensitive data stored within the application.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gvw-w6fj-7m3c

больше 2 лет назад

Argo CD's API server does not enforce project sourceNamespaces

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2gvw-rh95-856r

2 дня назад

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

EPSS: Низкий
github логотип

GHSA-2gvw-r9m5-r3m7

около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-2gvw-95cm-ffm9

около 4 лет назад

provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.

EPSS: Низкий
github логотип

GHSA-2gvv-xcmg-4m9m

около 4 лет назад

OX App Suite through 7.10.2 has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-2gvv-fwhv-83hw

около 4 лет назад

An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gvv-8pww-2c2x

около 4 лет назад

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gvv-5vxj-jrw7

около 4 лет назад

A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

EPSS: Низкий
github логотип

GHSA-2gvr-pmm6-8pmw

около 4 лет назад

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gw7-672m-m38x

The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2gw6-v2h7-g6vm

A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw6-73wc-x88f

Apache Geode information disclosure vulnerability

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2gw5-9px7-vp56

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS3: 7.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-2gw3-mxrj-jwhh

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gw2-qgjg-xh6p

Namada-apps allows Post-Genesis Validator Bypass

больше 1 года назад
github логотип
GHSA-2gw2-8q9w-cw8p

Ruby-ffi has a DLL loading issue

CVSS3: 7.8
1%
Низкий
почти 8 лет назад
github логотип
GHSA-2gvx-rx63-w97c

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2gvx-cpxc-42hj

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2gvx-5frj-6px5

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2gvx-55m9-gpjj

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, including privileged users such as administrators. This allows unauthorized access/read to sensitive data stored within the application.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2gvw-w6fj-7m3c

Argo CD's API server does not enforce project sourceNamespaces

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2gvw-rh95-856r

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

0%
Низкий
2 дня назад
github логотип
GHSA-2gvw-r9m5-r3m7

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

около 2 лет назад
github логотип
GHSA-2gvw-95cm-ffm9

provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2gvv-xcmg-4m9m

OX App Suite through 7.10.2 has Incorrect Access Control.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2gvv-fwhv-83hw

An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gvv-8pww-2c2x

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2gvv-5vxj-jrw7

A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2gvr-pmm6-8pmw

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051.

17%
Средний
около 4 лет назад

Уязвимостей на страницу