Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-29p5-jqph-prvj

около 4 лет назад

Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-29p5-chfq-8h6j

почти 4 года назад

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29p4-j6wv-3g22

больше 4 лет назад

Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.

EPSS: Низкий
github логотип

GHSA-29p4-76cr-8wvw

5 месяцев назад

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from its sanitization whitelist, combined with an overly permissive wp_kses() filter at output time that allows onclick attributes on anchor tags. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the lead entries in the WordPress dashboard.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-29p4-5443-x453

3 месяца назад

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29p3-gxfx-6jvv

около 4 лет назад

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.

EPSS: Низкий
github логотип

GHSA-29p3-gqrh-c7mr

около 4 лет назад

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.

EPSS: Низкий
github логотип

GHSA-29p2-vxjx-v5jw

около 1 месяца назад

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29p2-p4jq-qf4p

около 4 лет назад

An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29p2-mh35-x8wh

около 4 лет назад

Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

EPSS: Низкий
github логотип

GHSA-29p2-7jvf-2jvf

больше 2 лет назад

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'roll_no' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29mx-mxf7-74q4

около 1 месяца назад

Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29mx-jm4m-v9x5

около 4 лет назад

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29mx-gmwr-vhpf

около 4 лет назад

Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."

EPSS: Низкий
github логотип

GHSA-29mx-8r38-hfxq

почти 3 года назад

** UNSUPPORTED WHEN ASSIGNED ** Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29mx-4gvm-rgfp

почти 3 года назад

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29mw-wpgm-hmr9

больше 4 лет назад

Regular Expression Denial of Service (ReDoS) in lodash

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29mw-v354-5gg5

3 месяца назад

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-29mw-f55p-xcww

11 месяцев назад

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-29mv-jj69-j88c

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29p5-jqph-prvj

Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

2%
Низкий
около 4 лет назад
github логотип
GHSA-29p5-chfq-8h6j

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-29p4-j6wv-3g22

Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-29p4-76cr-8wvw

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from its sanitization whitelist, combined with an overly permissive wp_kses() filter at output time that allows onclick attributes on anchor tags. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the lead entries in the WordPress dashboard.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-29p4-5443-x453

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-29p3-gxfx-6jvv

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.

2%
Низкий
около 4 лет назад
github логотип
GHSA-29p3-gqrh-c7mr

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.

0%
Низкий
около 4 лет назад
github логотип
GHSA-29p2-vxjx-v5jw

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-29p2-p4jq-qf4p

An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-29p2-mh35-x8wh

Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

1%
Низкий
около 4 лет назад
github логотип
GHSA-29p2-7jvf-2jvf

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'roll_no' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-29mx-mxf7-74q4

Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-29mx-jm4m-v9x5

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-29mx-gmwr-vhpf

Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."

1%
Низкий
около 4 лет назад
github логотип
GHSA-29mx-8r38-hfxq

** UNSUPPORTED WHEN ASSIGNED ** Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-29mx-4gvm-rgfp

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-29mw-wpgm-hmr9

Regular Expression Denial of Service (ReDoS) in lodash

CVSS3: 5.3
7%
Низкий
больше 4 лет назад
github логотип
GHSA-29mw-v354-5gg5

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-29mw-f55p-xcww

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-29mv-jj69-j88c

Rejected reason: Not used

7 месяцев назад

Уязвимостей на страницу