Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2gj9-425g-wxfr

около 1 месяца назад

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURemovableMedia JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27632.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gj8-f8hj-pwwh

3 месяца назад

Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2gj8-24rx-v734

около 4 лет назад

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gj7-v6cw-hpq6

около 4 лет назад

Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.

EPSS: Низкий
github логотип

GHSA-2gj6-qx93-qj58

около 4 лет назад

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

EPSS: Средний
github логотип

GHSA-2gj6-9mmj-r597

4 месяца назад

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gj6-9934-w9r6

больше 1 года назад

Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service. This vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gj6-8x44-7f5c

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2gj6-558v-rq2w

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gj6-4m7m-3c82

около 4 лет назад

Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which may allow an attacker to execute a malicious macro by having a user to download, import, and open a specially crafted file in the local environment.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gj6-3jhw-wm56

около 4 лет назад

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:21:23.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gj5-wp37-4727

больше 4 лет назад

The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2gj5-g2gq-97mp

12 месяцев назад

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

EPSS: Низкий
github логотип

GHSA-2gj5-2jfx-vcmc

больше 4 лет назад

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

EPSS: Низкий
github логотип

GHSA-2gj3-xrpr-w23r

около 4 лет назад

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

EPSS: Низкий
github логотип

GHSA-2gj2-vj98-j2qq

больше 3 лет назад

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2gj2-5v4g-j7xv

около 4 лет назад

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2ghx-mx8m-8w49

около 1 года назад

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2ghv-58hc-7529

около 4 лет назад

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ghr-522h-prhx

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gj9-425g-wxfr

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURemovableMedia JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-27632.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-2gj8-f8hj-pwwh

Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2gj8-24rx-v734

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gj7-v6cw-hpq6

Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2gj6-qx93-qj58

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

66%
Средний
около 4 лет назад
github логотип
GHSA-2gj6-9mmj-r597

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2gj6-9934-w9r6

Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service. This vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2gj6-8x44-7f5c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster Plus for WooCommerce allows Reflected XSS.This issue affects Booster Plus for WooCommerce: from n/a through 7.2.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2gj6-558v-rq2w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gj6-4m7m-3c82

Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which may allow an attacker to execute a malicious macro by having a user to download, import, and open a specially crafted file in the local environment.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gj6-3jhw-wm56

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in color.c:21:23.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2gj5-wp37-4727

The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2gj5-g2gq-97mp

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

1%
Низкий
12 месяцев назад
github логотип
GHSA-2gj5-2jfx-vcmc

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2gj3-xrpr-w23r

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2gj2-vj98-j2qq

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gj2-5v4g-j7xv

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVSS3: 6.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2ghx-mx8m-8w49

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2ghv-58hc-7529

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2ghr-522h-prhx

Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу