Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-297g-gfvh-fg6g

8 месяцев назад

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-297g-cjpm-qw2x

больше 1 года назад

Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-297g-9xq6-v8vj

больше 3 лет назад

Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-297g-9658-43jh

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.

EPSS: Низкий
github логотип

GHSA-297g-672r-7mgh

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-297g-44c7-436q

больше 4 лет назад

Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.

EPSS: Средний
github логотип

GHSA-297f-r9w7-w492

почти 4 года назад

Magento Improper input validation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-297f-24c2-wwfv

9 месяцев назад

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-297c-p9xm-3rhf

больше 1 года назад

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-297c-8rmr-xrxf

около 4 лет назад

Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.

EPSS: Низкий
github логотип

GHSA-297c-34f3-r565

около 4 лет назад

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.

EPSS: Низкий
github логотип

GHSA-2979-3fv7-8r3w

7 месяцев назад

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2978-89p5-cxgh

около 4 лет назад

An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2978-6549-pf4r

около 4 лет назад

SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.

EPSS: Низкий
github логотип

GHSA-2977-w3fj-rc33

больше 2 лет назад

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2977-ph22-g7f6

около 4 лет назад

The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2977-c3c9-wqxf

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2977-6mrh-4c63

больше 1 года назад

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2977-5php-6789

около 1 года назад

Erxes Path Traversal vulnerability

EPSS: Низкий
github логотип

GHSA-2976-mg74-v97h

почти 3 года назад

Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-297g-gfvh-fg6g

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.

CVSS3: 4.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-297g-cjpm-qw2x

Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-297g-9xq6-v8vj

Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-297g-9658-43jh

Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.

2%
Низкий
около 4 лет назад
github логотип
GHSA-297g-672r-7mgh

Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-297g-44c7-436q

Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.

10%
Средний
больше 4 лет назад
github логотип
GHSA-297f-r9w7-w492

Magento Improper input validation vulnerability

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-297f-24c2-wwfv

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-297c-p9xm-3rhf

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-297c-8rmr-xrxf

Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.

0%
Низкий
около 4 лет назад
github логотип
GHSA-297c-34f3-r565

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2979-3fv7-8r3w

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2978-89p5-cxgh

An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2978-6549-pf4r

SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2977-w3fj-rc33

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2977-ph22-g7f6

The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2977-c3c9-wqxf

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2977-6mrh-4c63

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2977-5php-6789

Erxes Path Traversal vulnerability

0%
Низкий
около 1 года назад
github логотип
GHSA-2976-mg74-v97h

Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу