Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2935-2wfm-hhpv

больше 1 года назад

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2934-h34j-g33x

больше 2 лет назад

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2934-gw32-fqg4

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2933-vwp4-xpm8

10 месяцев назад

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2933-q333-qg83

около 1 месяца назад

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2933-mrxr-9gj9

около 4 лет назад

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2932-f892-c8hc

больше 4 лет назад

nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.

EPSS: Низкий
github логотип

GHSA-2932-63p2-x63x

больше 1 года назад

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-292x-hjr8-226f

около 4 лет назад

Cloud Foundry UAA Privilege Escalation

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-292x-9cr3-pgc3

около 4 лет назад

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data as well as unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-292x-89v7-pcq6

около 4 лет назад

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

EPSS: Низкий
github логотип

GHSA-292w-467q-qfj8

больше 4 лет назад

xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

EPSS: Низкий
github логотип

GHSA-292w-2m2h-rw25

больше 1 года назад

Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-292v-wgjp-vm43

около 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-292v-q449-fgpm

больше 2 лет назад

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-292r-c8r5-h2g9

больше 3 лет назад

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-292r-44qm-39gx

около 4 лет назад

Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the File command.

EPSS: Низкий
github логотип

GHSA-292q-v67v-f66g

6 месяцев назад

A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service (DoS) by sending a specially crafted HTTP POST request containing non-existing language parameter. This renders the server unable to serve correct lang.js file, which causes administrator panel to not work, resulting in DoS until the language settings is reverted to a correct value. The Denial of Service affects only the administrator panel and does not affect other router functionalities. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

EPSS: Низкий
github логотип

GHSA-292q-rvhx-63rq

больше 2 лет назад

Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-292q-3p6w-47gj

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebGeniusLab iRecco Core irecco-core allows PHP Local File Inclusion.This issue affects iRecco Core: from n/a through <= 1.3.6.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2935-2wfm-hhpv

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

CVSS3: 4.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-2934-h34j-g33x

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2934-gw32-fqg4

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2933-vwp4-xpm8

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2933-q333-qg83

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2933-mrxr-9gj9

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2932-f892-c8hc

nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2932-63p2-x63x

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-292x-hjr8-226f

Cloud Foundry UAA Privilege Escalation

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-292x-9cr3-pgc3

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data as well as unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-292x-89v7-pcq6

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

9%
Низкий
около 4 лет назад
github логотип
GHSA-292w-467q-qfj8

xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-292w-2m2h-rw25

Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.

CVSS3: 4.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-292v-wgjp-vm43

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVSS3: 9.9
1%
Низкий
около 1 года назад
github логотип
GHSA-292v-q449-fgpm

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-292r-c8r5-h2g9

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-292r-44qm-39gx

Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the File command.

3%
Низкий
около 4 лет назад
github логотип
GHSA-292q-v67v-f66g

A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service (DoS) by sending a specially crafted HTTP POST request containing non-existing language parameter. This renders the server unable to serve correct lang.js file, which causes administrator panel to not work, resulting in DoS until the language settings is reverted to a correct value. The Denial of Service affects only the administrator panel and does not affect other router functionalities. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version V108_108 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

1%
Низкий
6 месяцев назад
github логотип
GHSA-292q-rvhx-63rq

Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-292q-3p6w-47gj

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebGeniusLab iRecco Core irecco-core allows PHP Local File Inclusion.This issue affects iRecco Core: from n/a through <= 1.3.6.

CVSS3: 8.2
0%
Низкий
6 месяцев назад

Уязвимостей на страницу