Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2623-7ghf-34hg

больше 2 лет назад

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2622-7mvw-7jrg

5 месяцев назад

Missing Authorization vulnerability in raratheme Business One Page business-one-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business One Page: from n/a through <= 1.3.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25xx-rcpp-w7mf

около 4 лет назад

Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

EPSS: Низкий
github логотип

GHSA-25xx-qj5q-8gm9

около 4 лет назад

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xw-cf43-5ccv

17 дней назад

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25xv-g2pj-97p3

около 4 лет назад

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.

EPSS: Низкий
github логотип

GHSA-25xv-9777-w8wm

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.

EPSS: Низкий
github логотип

GHSA-25xr-qqmw-vc8p

около 4 лет назад

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26960931.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-25xr-qj8w-c4vf

около 1 года назад

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xq-f8xm-q632

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25xp-q574-q8mf

около 4 лет назад

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-25xp-mg6j-wcwf

2 месяца назад

The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in the iwr_tooltip() shortcode handler — the `title` attribute is concatenated directly into an HTML attribute without esc_attr() or any other escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-25xp-grv3-xwjh

около 4 лет назад

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25xm-wxrx-cgw8

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year parameter in a calendar announce action.

EPSS: Низкий
github логотип

GHSA-25xm-hr59-7c27

около 5 лет назад

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xj-934p-cf7v

около 4 лет назад

IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.

EPSS: Низкий
github логотип

GHSA-25xj-89g5-fm6h

около 5 лет назад

Information Disclosure in HashiCorp Vault

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xh-49vg-48xq

около 4 лет назад

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187873.

EPSS: Низкий
github логотип

GHSA-25xg-m67p-ppc3

8 месяцев назад

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25xg-52c8-p9q8

4 месяца назад

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2623-7ghf-34hg

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2622-7mvw-7jrg

Missing Authorization vulnerability in raratheme Business One Page business-one-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business One Page: from n/a through <= 1.3.2.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-25xx-rcpp-w7mf

Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25xx-qj5q-8gm9

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-25xw-cf43-5ccv

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
0%
Низкий
17 дней назад
github логотип
GHSA-25xv-g2pj-97p3

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.

4%
Низкий
около 4 лет назад
github логотип
GHSA-25xv-9777-w8wm

Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-25xr-qqmw-vc8p

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26960931.

CVSS3: 8.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-25xr-qj8w-c4vf

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
2%
Низкий
около 1 года назад
github логотип
GHSA-25xq-f8xm-q632

Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-25xp-q574-q8mf

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-25xp-mg6j-wcwf

The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in the iwr_tooltip() shortcode handler — the `title` attribute is concatenated directly into an HTML attribute without esc_attr() or any other escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
2 месяца назад
github логотип
GHSA-25xp-grv3-xwjh

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

CVSS3: 7.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-25xm-wxrx-cgw8

Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year parameter in a calendar announce action.

4%
Низкий
около 4 лет назад
github логотип
GHSA-25xm-hr59-7c27

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-25xj-934p-cf7v

IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25xj-89g5-fm6h

Information Disclosure in HashiCorp Vault

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-25xh-49vg-48xq

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187873.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25xg-m67p-ppc3

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-25xg-52c8-p9q8

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

CVSS3: 8.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу