Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-269g-rg4h-9rr5

10 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-269g-pwp5-87pp

почти 6 лет назад

TemporaryFolder on unix-like systems does not limit access to created files

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-269g-6r83-cfhc

около 4 лет назад

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-269f-h4cx-j3fr

около 2 лет назад

An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-269f-c6h8-6gv2

больше 3 лет назад

A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-269f-8j25-5mp2

около 4 лет назад

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-269f-8844-8wj6

8 месяцев назад

The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger a full site reset, dropping all database tables except users/usermeta and re-running wp_install(), which also assigns the Administrator role to the attacking subscriber account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-269c-5w5q-frxq

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-269c-4g57-c9vg

около 2 лет назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2699-8r69-fq67

больше 3 лет назад

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2698-gwhq-x693

около 4 лет назад

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2697-j9w4-39rc

больше 3 лет назад

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2697-96mv-3gfm

больше 1 года назад

TeamPass does not properly check whether a folder is in a user's allowed folders list

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2697-5v76-cfvp

около 4 лет назад

Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability".

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2697-3jf6-rpjg

около 4 лет назад

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2696-m9wq-rxcm

около 4 лет назад

Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.

EPSS: Средний
github логотип

GHSA-2696-454c-76j5

около 4 лет назад

Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2694-c6mx-8fhj

больше 4 лет назад

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

EPSS: Низкий
github логотип

GHSA-2694-5vc6-j2c3

9 месяцев назад

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback => '__return_true') and the AJAX delete_item handler (which only checks nonce validity without verifying object-level authorization). This makes it possible for unauthenticated attackers to disclose wishlist tokens for any user and subsequently delete wishlist items by chaining the REST API authorization bypass with the exposed delete_item nonce on shared wishlist pages and the AJAX handler's missing object-level authorization check.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-268x-v6f6-3gr5

около 4 лет назад

Multiple SQL injection vulnerabilities in Sharetronix 3.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) fb_user_id or (2) tw_user_id parameter to signup.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-269g-rg4h-9rr5

Rejected reason: Not used

10 месяцев назад
github логотип
GHSA-269g-pwp5-87pp

TemporaryFolder on unix-like systems does not limit access to created files

CVSS3: 4.4
2%
Низкий
почти 6 лет назад
github логотип
GHSA-269g-6r83-cfhc

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-269f-h4cx-j3fr

An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-269f-c6h8-6gv2

A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-269f-8j25-5mp2

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-269f-8844-8wj6

The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger a full site reset, dropping all database tables except users/usermeta and re-running wp_install(), which also assigns the Administrator role to the attacking subscriber account.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-269c-5w5q-frxq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-269c-4g57-c9vg

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2699-8r69-fq67

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2698-gwhq-x693

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2697-j9w4-39rc

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2697-96mv-3gfm

TeamPass does not properly check whether a folder is in a user's allowed folders list

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2697-5v76-cfvp

Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability".

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2697-3jf6-rpjg

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

CVSS3: 7.8
10%
Низкий
около 4 лет назад
github логотип
GHSA-2696-m9wq-rxcm

Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.

22%
Средний
около 4 лет назад
github логотип
GHSA-2696-454c-76j5

Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2694-c6mx-8fhj

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2694-5vc6-j2c3

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback => '__return_true') and the AJAX delete_item handler (which only checks nonce validity without verifying object-level authorization). This makes it possible for unauthenticated attackers to disclose wishlist tokens for any user and subsequently delete wishlist items by chaining the REST API authorization bypass with the exposed delete_item nonce on shared wishlist pages and the AJAX handler's missing object-level authorization check.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-268x-v6f6-3gr5

Multiple SQL injection vulnerabilities in Sharetronix 3.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) fb_user_id or (2) tw_user_id parameter to signup.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу