Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-25p4-xq52-q9pw

почти 2 года назад

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25p4-f7jc-m83q

около 4 лет назад

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

EPSS: Низкий
github логотип

GHSA-25p3-wx48-c43f

10 месяцев назад

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection. This issue affects Awesome Support: from n/a through 6.3.4.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-25p3-r4j6-7wqc

больше 3 лет назад

The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-25p3-j54h-933p

около 4 лет назад

VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25p3-2r5q-956q

около 4 лет назад

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

EPSS: Низкий
github логотип

GHSA-25mx-w28c-mcm6

около 4 лет назад

SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.

EPSS: Низкий
github логотип

GHSA-25mx-8f3v-8wh7

около 3 лет назад

sequoia-openpgp vulnerable to out-of-bounds array access leading to panic

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-25mx-7q4c-hfgq

больше 3 лет назад

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25mx-2mxm-6343

больше 3 лет назад

@keystone-6/core's NODE_ENV defaults to development with esbuild

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25mw-r645-vhvc

около 4 лет назад

The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.

EPSS: Низкий
github логотип

GHSA-25mw-fj8x-6qq5

больше 2 лет назад

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-25mw-359m-f6rj

около 2 месяцев назад

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-25mv-x9rj-47v2

около 4 лет назад

The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.

EPSS: Низкий
github логотип

GHSA-25mv-vrj7-2v89

около 4 лет назад

An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.

EPSS: Низкий
github логотип

GHSA-25mr-w95m-82v7

около 3 лет назад

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable length/size. No publicly available exploits are known.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25mr-v3vc-44xm

около 4 лет назад

There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25mr-3m57-5v4r

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[0] and (2) sig[1] parameters.

EPSS: Низкий
github логотип

GHSA-25mq-v84q-4j7r

около 4 лет назад

CURLOPT_HTTPAUTH option not cleared on change of origin

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-25mp-g6fv-mqxx

больше 4 лет назад

Unexpected server crash in Next.js.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25p4-xq52-q9pw

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

CVSS3: 9.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-25p4-f7jc-m83q

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

0%
Низкий
около 4 лет назад
github логотип
GHSA-25p3-wx48-c43f

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection. This issue affects Awesome Support: from n/a through 6.3.4.

CVSS3: 7.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-25p3-r4j6-7wqc

The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25p3-j54h-933p

VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-25p3-2r5q-956q

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25mx-w28c-mcm6

SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25mx-8f3v-8wh7

sequoia-openpgp vulnerable to out-of-bounds array access leading to panic

CVSS3: 2.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-25mx-7q4c-hfgq

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25mx-2mxm-6343

@keystone-6/core's NODE_ENV defaults to development with esbuild

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25mw-r645-vhvc

The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25mw-fj8x-6qq5

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227

CVSS3: 8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-25mw-359m-f6rj

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
94%
Критический
около 2 месяцев назад
github логотип
GHSA-25mv-x9rj-47v2

The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25mv-vrj7-2v89

An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25mr-w95m-82v7

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable length/size. No publicly available exploits are known.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-25mr-v3vc-44xm

There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-25mr-3m57-5v4r

Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[0] and (2) sig[1] parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25mq-v84q-4j7r

CURLOPT_HTTPAUTH option not cleared on change of origin

CVSS3: 7.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-25mp-g6fv-mqxx

Unexpected server crash in Next.js.

CVSS3: 7.5
45%
Средний
больше 4 лет назад

Уязвимостей на страницу