Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-287g-7jjx-c8p9

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-287g-6pcr-gxf9

около 4 лет назад

Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: Низкий
github логотип

GHSA-287f-5vcq-p94w

около 4 лет назад

Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

EPSS: Низкий
github логотип

GHSA-287f-46j7-j4wh

больше 2 лет назад

Umbraco Workflow's Backoffice users can execute arbitrary SQL

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-287c-fxr7-3w6c

3 месяца назад

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-287c-cc7v-7v95

больше 2 лет назад

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated attackers to update the folder position of categories as well as update the metadata of other taxonomies via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2879-m9hj-g3rq

около 4 лет назад

Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.

EPSS: Низкий
github логотип

GHSA-2879-m464-5wm3

около 4 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. While the vulnerability is in Oracle Outside In Technology, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received ...

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2879-hr6w-p3mx

около 4 лет назад

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."

EPSS: Средний
github логотип

GHSA-2879-fhf4-rjj6

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' Commit 176cda0619b6 ("powerpc/perf: Add perf interface to expose vpa counters") introduced 'vpa_pmu' to expose Book3s-HV nested APIv2 provided L1<->L2 context switch latency counters to L1 user-space via perf-events. However the newly introduced PMU named 'vpa_pmu' doesn't assign ownership of the PMU to the module 'vpa_pmu'. Consequently the module 'vpa_pmu' can be unloaded while one of the perf-events are still active, which can lead to kernel oops and panic of the form below on a Pseries-LPAR: BUG: Kernel NULL pointer dereference on read at 0x00000058 <snip> NIP [c000000000506cb8] event_sched_out+0x40/0x258 LR [c00000000050e8a4] __perf_remove_from_context+0x7c/0x2b0 Call Trace: [c00000025fc3fc30] [c00000025f8457a8] 0xc00000025f8457a8 (unreliable) [c00000025fc3fc80] [fffffffffffffee0] 0xfffffffffffffee0 [c00000025fc3fcd0] [c000000000501e70] event_function...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2879-8cxh-4cm7

около 4 лет назад

In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2878-rf7x-qjqp

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2877-693q-pj33

больше 4 лет назад

OS Command Injection in GenieACS

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2877-5pv6-3w5q

около 4 лет назад

Bradford CampusManager Network Control Application Server 3.1(6) allows remote attackers to obtain sensitive information (backup, log, and configuration files) via direct request for certain files in (1) /runTime/ or (2) /remediationReports/.

EPSS: Низкий
github логотип

GHSA-2876-qmcj-r79h

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dolcino dolcino allows PHP Local File Inclusion.This issue affects Dolcino: from n/a through <= 1.6.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2876-5r6w-63mx

около 2 месяцев назад

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2875-w7f9-pcqc

около 4 лет назад

The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2875-28w4-4vqx

17 дней назад

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2874-f7gx-365p

около 2 лет назад

Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2874-9wc2-224f

около 4 лет назад

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-287g-7jjx-c8p9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4.

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-287g-6pcr-gxf9

Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.

3%
Низкий
около 4 лет назад
github логотип
GHSA-287f-5vcq-p94w

Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-287f-46j7-j4wh

Umbraco Workflow's Backoffice users can execute arbitrary SQL

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-287c-fxr7-3w6c

Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-287c-cc7v-7v95

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated attackers to update the folder position of categories as well as update the metadata of other taxonomies via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2879-m9hj-g3rq

Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2879-m464-5wm3

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. While the vulnerability is in Oracle Outside In Technology, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received ...

CVSS3: 7.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-2879-hr6w-p3mx

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."

14%
Средний
около 4 лет назад
github логотип
GHSA-2879-fhf4-rjj6

In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' Commit 176cda0619b6 ("powerpc/perf: Add perf interface to expose vpa counters") introduced 'vpa_pmu' to expose Book3s-HV nested APIv2 provided L1<->L2 context switch latency counters to L1 user-space via perf-events. However the newly introduced PMU named 'vpa_pmu' doesn't assign ownership of the PMU to the module 'vpa_pmu'. Consequently the module 'vpa_pmu' can be unloaded while one of the perf-events are still active, which can lead to kernel oops and panic of the form below on a Pseries-LPAR: BUG: Kernel NULL pointer dereference on read at 0x00000058 <snip> NIP [c000000000506cb8] event_sched_out+0x40/0x258 LR [c00000000050e8a4] __perf_remove_from_context+0x7c/0x2b0 Call Trace: [c00000025fc3fc30] [c00000025f8457a8] 0xc00000025f8457a8 (unreliable) [c00000025fc3fc80] [fffffffffffffee0] 0xfffffffffffffee0 [c00000025fc3fcd0] [c000000000501e70] event_function...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2879-8cxh-4cm7

In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.

CVSS3: 7
0%
Низкий
около 4 лет назад
github логотип
GHSA-2878-rf7x-qjqp

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-2877-693q-pj33

OS Command Injection in GenieACS

CVSS3: 9.8
22%
Средний
больше 4 лет назад
github логотип
GHSA-2877-5pv6-3w5q

Bradford CampusManager Network Control Application Server 3.1(6) allows remote attackers to obtain sensitive information (backup, log, and configuration files) via direct request for certain files in (1) /runTime/ or (2) /remediationReports/.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2876-qmcj-r79h

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dolcino dolcino allows PHP Local File Inclusion.This issue affects Dolcino: from n/a through <= 1.6.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
github логотип
GHSA-2876-5r6w-63mx

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2875-w7f9-pcqc

The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.

CVSS3: 9.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-2875-28w4-4vqx

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVSS3: 6.5
1%
Низкий
17 дней назад
github логотип
GHSA-2874-f7gx-365p

Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2874-9wc2-224f

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 7.8
0%
Низкий
около 4 лет назад

Уязвимостей на страницу