Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-393w-r2ww-5878

больше 1 года назад

The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or incorrect nonce validation on the 'shipworks-wordpress' page. This makes it possible for unauthenticated attackers to update the services username and password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-393w-9x6h-8gc7

около 1 года назад

Pingora update for MadeYouReset HTTP/2 vulnerability

EPSS: Низкий
github логотип

GHSA-393w-9353-grv2

больше 4 лет назад

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the publicly accessible link.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-393w-2929-cxcg

почти 3 года назад

Named Pipe File System Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-393v-jrvh-g25v

около 4 лет назад

PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-393v-j9q3-p63r

больше 1 года назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet forwarding engine) of Juniper Networks Junos OS on MX Series causes a port within a pool to be blocked leading to Denial of Service (DoS). In a DS-Lite (Dual-Stack Lite) and NAT (Network Address Translation) scenario, when crafted IPv6 traffic is received and prefix-length is set to 56, the ports assigned to the user will not be freed.  Eventually, users cannot establish new connections. Affected FPC/PIC need to be manually restarted to recover. Following is the command to identify the issue:      user@host> show services nat source port-block      Host_IP                     External_IP                   Port_Block      Ports_Used/       Block_State/                                                               Range           Ports_Total       Left_Time(s)     2001::                    �...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-393v-ghcr-3x2m

больше 4 лет назад

Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-393r-r9mq-g9jv

больше 4 лет назад

Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-393r-2hjv-4h5f

около 3 лет назад

SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-393q-7g3p-mp9v

больше 4 лет назад

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

EPSS: Низкий
github логотип

GHSA-393q-6xw4-wfg2

больше 3 лет назад

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-393q-2jgx-p9ph

больше 4 лет назад

OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

EPSS: Низкий
github логотип

GHSA-393p-mc4h-j8g2

около 4 лет назад

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption - On Hover' value associated with images in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-393m-vg99-2x36

больше 4 лет назад

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.

CVSS3: 2.1
EPSS: Низкий
github логотип

GHSA-393j-fpg3-h6c9

почти 3 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-393j-8xcq-h729

больше 4 лет назад

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

EPSS: Низкий
github логотип

GHSA-393h-j526-4h79

больше 4 лет назад

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a result, an attacker may modify almost all of the device's settings and view various configuration settings.

EPSS: Низкий
github логотип

GHSA-393g-7274-4jmv

больше 4 лет назад

Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

EPSS: Низкий
github логотип

GHSA-393f-4662-497f

больше 4 лет назад

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-393f-2jr3-cp69

больше 5 лет назад

CHECK-fail in DrawBoundingBoxes

CVSS3: 2.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-393w-r2ww-5878

The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or incorrect nonce validation on the 'shipworks-wordpress' page. This makes it possible for unauthenticated attackers to update the services username and password via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-393w-9x6h-8gc7

Pingora update for MadeYouReset HTTP/2 vulnerability

около 1 года назад
github логотип
GHSA-393w-9353-grv2

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the publicly accessible link.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-393w-2929-cxcg

Named Pipe File System Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-393v-jrvh-g25v

PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-393v-j9q3-p63r

An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet forwarding engine) of Juniper Networks Junos OS on MX Series causes a port within a pool to be blocked leading to Denial of Service (DoS). In a DS-Lite (Dual-Stack Lite) and NAT (Network Address Translation) scenario, when crafted IPv6 traffic is received and prefix-length is set to 56, the ports assigned to the user will not be freed.  Eventually, users cannot establish new connections. Affected FPC/PIC need to be manually restarted to recover. Following is the command to identify the issue:      user@host> show services nat source port-block      Host_IP                     External_IP                   Port_Block      Ports_Used/       Block_State/                                                               Range           Ports_Total       Left_Time(s)     2001::                    �...

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-393v-ghcr-3x2m

Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".

CVSS3: 6.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-393r-r9mq-g9jv

Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-393r-2hjv-4h5f

SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-393q-7g3p-mp9v

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-393q-6xw4-wfg2

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-393q-2jgx-p9ph

OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-393p-mc4h-j8g2

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption - On Hover' value associated with images in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-393m-vg99-2x36

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.

CVSS3: 2.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-393j-fpg3-h6c9

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-393j-8xcq-h729

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-393h-j526-4h79

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a result, an attacker may modify almost all of the device's settings and view various configuration settings.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-393g-7274-4jmv

Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-393f-4662-497f

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-393f-2jr3-cp69

CHECK-fail in DrawBoundingBoxes

CVSS3: 2.5
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу