Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-23m2-3g75-jvc8

4 месяца назад

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled key in the Stripe SCA confirmation AJAX endpoint. This makes it possible for unauthenticated attackers to modify payment status of targeted pending submissions (for example, setting the status to "failed").

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23m2-2fch-phwm

больше 4 лет назад

IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23jx-rf54-6q5g

10 месяцев назад

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23jx-5f8q-pgw9

больше 4 лет назад

The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23jx-58r9-pwv6

11 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23jx-3fx9-64w9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-23jw-wj29-xjcv

7 месяцев назад

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23jw-vpm7-7386

больше 2 лет назад

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-247899.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23jw-jg3f-6352

6 месяцев назад

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23jv-v6qj-3fhh

около 5 лет назад

Denial of Service (DoS) in HashiCorp Consul

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23jv-8gf4-7r88

около 2 месяцев назад

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23jr-m8gx-r5hh

больше 2 лет назад

Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23jq-mpmp-prmf

около 4 лет назад

strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23jq-44mr-vjqc

около 4 лет назад

Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.

EPSS: Низкий
github логотип

GHSA-23jp-p842-vg87

около 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23jp-25jg-2qj5

около 3 лет назад

Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23jm-rv8w-pvxf

около 4 лет назад

A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.

EPSS: Низкий
github логотип

GHSA-23jj-xc4c-c6gr

больше 1 года назад

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-23jg-h2c6-qxwq

около 4 лет назад

The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.

EPSS: Низкий
github логотип

GHSA-23jg-5f8m-gw8c

4 месяца назад

PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23m2-3g75-jvc8

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled key in the Stripe SCA confirmation AJAX endpoint. This makes it possible for unauthenticated attackers to modify payment status of targeted pending submissions (for example, setting the status to "failed").

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-23m2-2fch-phwm

IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23jx-rf54-6q5g

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-23jx-5f8q-pgw9

The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-23jx-58r9-pwv6

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.

CVSS3: 8.8
0%
Низкий
11 дней назад
github логотип
GHSA-23jx-3fx9-64w9

Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-23jw-wj29-xjcv

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-23jw-vpm7-7386

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-247899.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23jw-jg3f-6352

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

CVSS3: 9.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-23jv-v6qj-3fhh

Denial of Service (DoS) in HashiCorp Consul

CVSS3: 7.5
2%
Низкий
около 5 лет назад
github логотип
GHSA-23jv-8gf4-7r88

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-23jr-m8gx-r5hh

Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23jq-mpmp-prmf

strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.

CVSS3: 9.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-23jq-44mr-vjqc

Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.

2%
Низкий
около 4 лет назад
github логотип
GHSA-23jp-p842-vg87

An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-23jp-25jg-2qj5

Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-23jm-rv8w-pvxf

A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23jj-xc4c-c6gr

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-23jg-h2c6-qxwq

The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23jg-5f8m-gw8c

PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py

CVSS3: 6.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу