Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-3757-h85m-r4vw

7 месяцев назад

UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3757-h5gm-6pj5

8 месяцев назад

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3756-mp7r-crrp

больше 4 лет назад

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3756-hwhv-qw58

больше 4 лет назад

Cross site scripting in francoisjacquet/rosariosis

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3754-x86m-fj9m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

EPSS: Низкий
github логотип

GHSA-3754-wv73-4cjw

больше 2 лет назад

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3754-c64r-8c26

6 месяцев назад

The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3754-735c-c4rm

больше 4 лет назад

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3754-5x4h-p35m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.

EPSS: Низкий
github логотип

GHSA-3753-r5q9-x6fx

почти 2 года назад

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS) condition. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.   This vulnerability is due to improper validation of user input that is in incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3753-m2x2-q623

3 дня назад

File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3753-fcfq-39h2

6 дней назад

Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

EPSS: Низкий
github логотип

GHSA-3753-7733-qrv7

11 месяцев назад

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3753-237w-wx4r

больше 4 лет назад

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

EPSS: Низкий
github логотип

GHSA-3753-236x-jr2j

24 дня назад

Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3752-8v88-868j

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.

EPSS: Низкий
github логотип

GHSA-374x-rhrg-qpf2

12 дней назад

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-374x-f6v3-7m9h

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-374x-c55q-x732

больше 4 лет назад

The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.

EPSS: Низкий
github логотип

GHSA-374w-gwqr-fmxg

больше 4 лет назад

brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3757-h85m-r4vw

UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.

CVSS3: 6.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-3757-h5gm-6pj5

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3756-mp7r-crrp

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3756-hwhv-qw58

Cross site scripting in francoisjacquet/rosariosis

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3754-x86m-fj9m

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3754-wv73-4cjw

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3754-c64r-8c26

The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3754-735c-c4rm

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3754-5x4h-p35m

Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3753-r5q9-x6fx

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS) condition. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.   This vulnerability is due to improper validation of user input that is in incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3753-m2x2-q623

File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

CVSS3: 8.2
0%
Низкий
3 дня назад
github логотип
GHSA-3753-fcfq-39h2

Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

0%
Низкий
6 дней назад
github логотип
GHSA-3753-7733-qrv7

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

CVSS3: 7.2
1%
Низкий
11 месяцев назад
github логотип
GHSA-3753-237w-wx4r

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3753-236x-jr2j

Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 9.1
0%
Низкий
24 дня назад
github логотип
GHSA-3752-8v88-868j

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-374x-rhrg-qpf2

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

CVSS3: 4.4
0%
Низкий
12 дней назад
github логотип
GHSA-374x-f6v3-7m9h

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-374x-c55q-x732

The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-374w-gwqr-fmxg

brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS

CVSS3: 5.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу