Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-24r7-x8mx-hc2h

больше 4 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r7-c5r6-xxmj

около 4 лет назад

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-24r6-29j2-hrjv

больше 4 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

EPSS: Низкий
github логотип

GHSA-24r5-xw2j-9h9x

больше 2 лет назад

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24r3-rx3r-wgvw

около 2 лет назад

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24r3-qrv6-6jx6

около 4 лет назад

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-24r3-p3x6-cqvx

около 1 месяца назад

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-24r2-2rf2-whfq

около 1 года назад

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24qx-w28j-9m6p

3 месяца назад

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)

EPSS: Низкий
github логотип

GHSA-24qx-986r-jvf4

около 4 лет назад

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qw-g5w5-55fm

около 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-24qw-797r-8hmj

около 4 лет назад

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24qv-pghr-gg8x

около 4 лет назад

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

EPSS: Низкий
github логотип

GHSA-24qv-j57w-wmcf

около 1 года назад

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-24qv-68gq-r7hr

около 4 лет назад

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

EPSS: Низкий
github логотип

GHSA-24qv-6795-29jh

около 4 лет назад

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24qq-8vc9-wp3m

около 2 лет назад

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
EPSS: Средний
github логотип

GHSA-24qq-7528-p6pc

4 месяца назад

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management interface to click a crafted link. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device to an attacker-controlled server. The attacker could then execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qp-pvw9-442x

около 4 лет назад

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

EPSS: Низкий
github логотип

GHSA-24qp-4xx8-3jvj

больше 1 года назад

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

CVSS3: 3.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24r7-x8mx-hc2h

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
42%
Средний
больше 4 лет назад
github логотип
GHSA-24r7-c5r6-xxmj

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

6%
Низкий
около 4 лет назад
github логотип
GHSA-24r6-29j2-hrjv

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

5%
Низкий
больше 4 лет назад
github логотип
GHSA-24r5-xw2j-9h9x

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24r3-rx3r-wgvw

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-24r3-qrv6-6jx6

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

10%
Средний
около 4 лет назад
github логотип
GHSA-24r3-p3x6-cqvx

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
1%
Низкий
около 1 месяца назад
github логотип
GHSA-24r2-2rf2-whfq

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-24qx-w28j-9m6p

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)

0%
Низкий
3 месяца назад
github логотип
GHSA-24qx-986r-jvf4

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-24qw-g5w5-55fm

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
13%
Средний
около 4 лет назад
github логотип
GHSA-24qw-797r-8hmj

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-24qv-pghr-gg8x

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

6%
Низкий
около 4 лет назад
github логотип
GHSA-24qv-j57w-wmcf

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-24qv-68gq-r7hr

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

0%
Низкий
около 4 лет назад
github логотип
GHSA-24qv-6795-29jh

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-24qq-8vc9-wp3m

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
21%
Средний
около 2 лет назад
github логотип
GHSA-24qq-7528-p6pc

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management interface to click a crafted link. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device to an attacker-controlled server. The attacker could then execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-24qp-pvw9-442x

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

5%
Низкий
около 4 лет назад
github логотип
GHSA-24qp-4xx8-3jvj

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

CVSS3: 3.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу