Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2459-9w34-v79g

больше 3 лет назад

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2458-wgmh-qq6g

около 4 лет назад

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2458-q378-h4hg

больше 4 лет назад

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

EPSS: Низкий
github логотип

GHSA-2457-vhh5-pcc4

около 4 лет назад

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

EPSS: Низкий
github логотип

GHSA-2457-jhx6-82v4

около 4 лет назад

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2457-j253-9gg8

около 2 лет назад

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2457-gqr3-47vq

около 3 лет назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2457-2263-mm9f

больше 4 лет назад

Memory leak in micronaut-core

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2456-wh5h-jwph

2 месяца назад

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2456-m625-hcj6

почти 3 года назад

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2456-4748-m2m2

7 месяцев назад

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2455-m68h-qwxv

около 1 месяца назад

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2455-5p2g-hrg7

больше 3 лет назад

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2454-7cjj-wj2v

около 4 лет назад

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

EPSS: Низкий
github логотип

GHSA-2454-558w-967q

около 4 лет назад

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

EPSS: Низкий
github логотип

GHSA-2454-3wfw-h893

около 4 лет назад

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2454-2h9h-6wx6

12 месяцев назад

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2453-p5w4-2rh4

больше 1 года назад

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2453-mppf-46cj

6 месяцев назад

Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`

EPSS: Низкий
github логотип

GHSA-2452-xqvj-2c63

почти 4 года назад

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2459-9w34-v79g

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2458-wgmh-qq6g

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2458-q378-h4hg

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2457-vhh5-pcc4

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2457-jhx6-82v4

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
3%
Низкий
около 4 лет назад
github логотип
GHSA-2457-j253-9gg8

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2457-gqr3-47vq

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2457-2263-mm9f

Memory leak in micronaut-core

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2456-wh5h-jwph

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-2456-m625-hcj6

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2456-4748-m2m2

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2455-m68h-qwxv

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2455-5p2g-hrg7

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2454-7cjj-wj2v

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2454-558w-967q

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2454-3wfw-h893

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVSS3: 5.5
7%
Низкий
около 4 лет назад
github логотип
GHSA-2454-2h9h-6wx6

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2453-p5w4-2rh4

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2453-mppf-46cj

Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`

1%
Низкий
6 месяцев назад
github логотип
GHSA-2452-xqvj-2c63

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

CVSS3: 5.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу