Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2497-vx3h-24wc

около 4 лет назад

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

EPSS: Средний
github логотип

GHSA-2497-mh3q-frq7

больше 4 лет назад

Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

EPSS: Низкий
github логотип

GHSA-2497-m587-h6c8

почти 2 года назад

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2497-gp99-2m74

6 месяцев назад

Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2497-6pwj-pwg7

около 1 месяца назад

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2495-6v7r-rmx4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.

EPSS: Низкий
github логотип

GHSA-2494-q7mq-75f7

больше 4 лет назад

PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

EPSS: Низкий
github логотип

GHSA-2493-x4rf-23h9

около 4 лет назад

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

EPSS: Низкий
github логотип

GHSA-2493-frc2-g6pr

12 месяцев назад

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2493-c7mq-cpj4

около 3 лет назад

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2493-92j5-5vh6

около 2 месяцев назад

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2493-8gg5-974x

больше 4 лет назад

Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2493-7x32-c5p8

около 4 лет назад

Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2492-xxqf-6h78

больше 2 лет назад

Cross Site Request Forgery in SwiftyEdit

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2492-95q9-ghpv

около 4 лет назад

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-248x-4c3j-hcg7

около 4 лет назад

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-248v-wwj6-r5j3

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-248v-73qf-wh7x

больше 4 лет назад

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.

EPSS: Низкий
github логотип

GHSA-248v-346w-9cwc

около 2 лет назад

Certifi removes GLOBALTRUST root certificate

EPSS: Низкий
github логотип

GHSA-248r-f975-ppfj

около 4 лет назад

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2497-vx3h-24wc

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

15%
Средний
около 4 лет назад
github логотип
GHSA-2497-mh3q-frq7

Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2497-m587-h6c8

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-2497-gp99-2m74

Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2497-6pwj-pwg7

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2495-6v7r-rmx4

Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2494-q7mq-75f7

PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2493-x4rf-23h9

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2493-frc2-g6pr

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.

CVSS3: 9.8
2%
Низкий
12 месяцев назад
github логотип
GHSA-2493-c7mq-cpj4

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2493-92j5-5vh6

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2493-8gg5-974x

Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2493-7x32-c5p8

Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2492-xxqf-6h78

Cross Site Request Forgery in SwiftyEdit

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2492-95q9-ghpv

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-248x-4c3j-hcg7

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-248v-wwj6-r5j3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-248v-73qf-wh7x

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1%
Низкий
около 2 лет назад
github логотип
GHSA-248r-f975-ppfj

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу