Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-2rr2-57v3-7cvx

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order allows Stored XSS, Cross-Site Scripting (XSS), Exploit Script-Based APIs, XSS Through HTTP Headers.This issue affects Veribase Order: before v4.010.3.

EPSS: Низкий
github логотип

GHSA-2rqx-pq8v-wx7j

больше 1 года назад

The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2rqx-6v8j-7xmq

9 месяцев назад

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rqw-x4fp-36cv

больше 4 лет назад

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

EPSS: Низкий
github логотип

GHSA-2rqw-vx2c-xfgw

больше 4 лет назад

Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rqw-v265-jf8c

около 5 лет назад

Open Redirect in ActionPack

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rqw-mg55-mp69

больше 4 лет назад

An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

EPSS: Низкий
github логотип

GHSA-2rqw-cvq5-cpcc

больше 3 лет назад

Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2rqw-cfhc-35fh

около 2 лет назад

CKAN may leak Solr credentials via error message in package_search action

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rqw-4rc9-x55v

больше 4 лет назад

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rqv-6w76-hjxv

больше 4 лет назад

SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-2rqr-64j8-q8px

больше 4 лет назад

In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2rqq-wmcv-3phw

больше 4 лет назад

The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rqq-v9v7-f3mq

больше 1 года назад

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rqq-j7w9-23vp

3 месяца назад

A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed locally. The pull request to fix this issue awaits acceptance.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rqq-cg89-vq87

больше 4 лет назад

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rqp-mqvp-96gv

больше 2 лет назад

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2rqp-7mg5-p5j7

больше 4 лет назад

The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted OpenType font.

EPSS: Низкий
github логотип

GHSA-2rqp-6r59-hpfg

больше 3 лет назад

Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2rqj-7x75-2684

6 месяцев назад

A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 7.21 will fix this issue. The patch is named 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rr2-57v3-7cvx

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order allows Stored XSS, Cross-Site Scripting (XSS), Exploit Script-Based APIs, XSS Through HTTP Headers.This issue affects Veribase Order: before v4.010.3.

0%
Низкий
около 2 лет назад
github логотип
GHSA-2rqx-pq8v-wx7j

The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2rqx-6v8j-7xmq

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2rqw-x4fp-36cv

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqw-vx2c-xfgw

Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqw-v265-jf8c

Open Redirect in ActionPack

CVSS3: 6.1
2%
Низкий
около 5 лет назад
github логотип
GHSA-2rqw-mg55-mp69

An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqw-cvq5-cpcc

Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rqw-cfhc-35fh

CKAN may leak Solr credentials via error message in package_search action

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rqw-4rc9-x55v

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 5.3
7%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqv-6w76-hjxv

SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqr-64j8-q8px

In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqq-wmcv-3phw

The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqq-v9v7-f3mq

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rqq-j7w9-23vp

A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed locally. The pull request to fix this issue awaits acceptance.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2rqq-cg89-vq87

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqp-mqvp-96gv

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2rqp-7mg5-p5j7

The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted OpenType font.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2rqp-6r59-hpfg

Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rqj-7x75-2684

A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 7.21 will fix this issue. The patch is named 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 5.6
1%
Низкий
6 месяцев назад

Уязвимостей на страницу