Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-389c-cf87-qmwj

больше 2 лет назад

Cross-site Scripting in livewire/livewire

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3899-g6fw-rr82

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence allows Stored XSS. This issue affects Useinfluence: from n/a through 1.0.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3899-4f66-wx7p

больше 4 лет назад

An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

EPSS: Низкий
github логотип

GHSA-3898-wjpq-fj5f

больше 2 лет назад

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3897-x777-pgxc

больше 4 лет назад

The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

EPSS: Низкий
github логотип

GHSA-3897-p5g5-4jjj

больше 4 лет назад

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.

EPSS: Средний
github логотип

GHSA-3897-7ph5-mf8c

больше 4 лет назад

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

EPSS: Низкий
github логотип

GHSA-3897-2crh-vgmr

3 месяца назад

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3896-rgxr-mxjp

больше 4 лет назад

An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3896-fhmw-qp2v

больше 4 лет назад

ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.

EPSS: Средний
github логотип

GHSA-3896-29g2-49jx

6 месяцев назад

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3895-r4rf-j249

больше 4 лет назад

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 174408.

EPSS: Низкий
github логотип

GHSA-3895-33gv-76p5

почти 3 года назад

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3894-wcv8-w35r

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.

EPSS: Низкий
github логотип

GHSA-3893-j6q6-whq8

больше 4 лет назад

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3893-7mx9-f68m

больше 4 лет назад

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3892-r6vc-28jh

больше 4 лет назад

Use-after-free vulnerability in the RangeData implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3892-qqv6-h2qm

больше 4 лет назад

Stored XSS vulnerability in Jenkins S3 Publisher Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3892-fhf4-9jgg

больше 4 лет назад

Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.

EPSS: Низкий
github логотип

GHSA-3892-f347-5r3f

больше 4 лет назад

The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-389c-cf87-qmwj

Cross-site Scripting in livewire/livewire

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3899-g6fw-rr82

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence allows Stored XSS. This issue affects Useinfluence: from n/a through 1.0.8.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3899-4f66-wx7p

An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3898-wjpq-fj5f

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3897-x777-pgxc

The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3897-p5g5-4jjj

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. j&#x41;vascript.

19%
Средний
больше 4 лет назад
github логотип
GHSA-3897-7ph5-mf8c

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3897-2crh-vgmr

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).

CVSS3: 10
0%
Низкий
3 месяца назад
github логотип
GHSA-3896-rgxr-mxjp

An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3896-fhmw-qp2v

ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.

21%
Средний
больше 4 лет назад
github логотип
GHSA-3896-29g2-49jx

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3895-r4rf-j249

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 174408.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3895-33gv-76p5

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3894-wcv8-w35r

Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3893-j6q6-whq8

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.

CVSS3: 8.8
20%
Средний
больше 4 лет назад
github логотип
GHSA-3893-7mx9-f68m

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-r6vc-28jh

Use-after-free vulnerability in the RangeData implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-qqv6-h2qm

Stored XSS vulnerability in Jenkins S3 Publisher Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-fhf4-9jgg

Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-f347-5r3f

The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу