Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3892-2r52-p65m

больше 5 лет назад

HTTP Request Smuggling in goliath

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-388x-h72v-g58j

больше 4 лет назад

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.

EPSS: Низкий
github логотип

GHSA-388x-f5qm-fvjg

больше 4 лет назад

Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-388x-5h6x-87xj

больше 4 лет назад

Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-388v-j5gj-fhhc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

EPSS: Низкий
github логотип

GHSA-388v-hgcc-fmvm

больше 4 лет назад

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-388v-c5f8-j95v

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability on Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-388v-6f9f-263v

больше 4 лет назад

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

EPSS: Средний
github логотип

GHSA-388r-w9fg-m2x5

8 месяцев назад

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-388r-rxw2-v9f9

больше 3 лет назад

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-388r-hw74-wm79

больше 4 лет назад

FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

EPSS: Низкий
github логотип

GHSA-388q-gvg4-w5x2

больше 4 лет назад

Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-388p-p6mh-7f4g

больше 4 лет назад

The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-388p-85c7-wr6g

больше 3 лет назад

A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-388m-42jq-jjrp

больше 4 лет назад

RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.

CVSS3: 7.1
EPSS: Средний
github логотип

GHSA-388j-jw77-hhcj

больше 1 года назад

The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-388j-hgw2-75wf

больше 4 лет назад

Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

EPSS: Низкий
github логотип

GHSA-388j-3575-x477

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-388j-24wv-pfqq

больше 1 года назад

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-388h-jxj2-x3jp

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3892-2r52-p65m

HTTP Request Smuggling in goliath

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
github логотип
GHSA-388x-h72v-g58j

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-388x-f5qm-fvjg

Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-388x-5h6x-87xj

Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-j5gj-fhhc

Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-hgcc-fmvm

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-c5f8-j95v

Cross-site request forgery (CSRF) vulnerability on Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS3: 8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-6f9f-263v

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

47%
Средний
больше 4 лет назад
github логотип
GHSA-388r-w9fg-m2x5

IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-388r-rxw2-v9f9

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-388r-hw74-wm79

FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-388q-gvg4-w5x2

Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-388p-p6mh-7f4g

The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-388p-85c7-wr6g

A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-388m-42jq-jjrp

RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.

CVSS3: 7.1
20%
Средний
больше 4 лет назад
github логотип
GHSA-388j-jw77-hhcj

The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-388j-hgw2-75wf

Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-388j-3575-x477

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-388j-24wv-pfqq

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-388h-jxj2-x3jp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.

CVSS3: 6.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу