Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36pc-999x-cvpg

12 месяцев назад

The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-36pc-5vqw-g5vm

больше 3 лет назад

The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoint before storing it and outputting it back in the page, leading to a Stored Cross-Site Scripting vulnerability which could be used against high-privilege users such as admin, furthermore lack of csrf protection means an attacker can trick a logged in admin to perform the attack by submitting a hidden form.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36p9-wgqq-whgv

21 день назад

A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-36p9-w333-jhg3

больше 4 лет назад

A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36p9-4jqp-qvg9

около 1 года назад

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36p9-3c3r-22pp

почти 2 года назад

Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36p8-mvp6-cv38

8 месяцев назад

Wrangler affected by OS Command Injection in `wrangler pages deploy`

EPSS: Низкий
github логотип

GHSA-36p8-9jxx-p4v9

почти 2 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in LUBUS WP Query Console allows Code Injection.This issue affects WP Query Console: from n/a through 1.0.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-36p8-6qw9-45qf

около 2 месяцев назад

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36p7-xjw8-h6f2

около 8 лет назад

Ruby-saml allows attackers to perform XML signature wrapping attacks

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36p7-vc44-83pf

3 месяца назад

ChromaDB has a code injection vulnerability

EPSS: Низкий
github логотип

GHSA-36p7-pvq8-jjmx

около 1 года назад

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight allows Object Injection. This issue affects Employee Spotlight: from n/a through 5.1.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-36p7-jqv6-r5mj

почти 4 года назад

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36p7-fgf7-w6rh

больше 4 лет назад

Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Banking Payments accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36p6-h78p-cx2w

7 месяцев назад

Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity

EPSS: Низкий
github логотип

GHSA-36p4-cjjg-rccj

больше 2 лет назад

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36p3-wjmg-h94x

больше 4 лет назад

Remote Code Execution in Spring Framework

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-36p3-m272-rwxj

7 месяцев назад

The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-36p3-j543-mpj6

больше 4 лет назад

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36p3-8r74-q5hh

около 1 месяца назад

Rejected reason: This CVE ID has been rejected.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36pc-999x-cvpg

The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-36pc-5vqw-g5vm

The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoint before storing it and outputting it back in the page, leading to a Stored Cross-Site Scripting vulnerability which could be used against high-privilege users such as admin, furthermore lack of csrf protection means an attacker can trick a logged in admin to perform the attack by submitting a hidden form.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36p9-wgqq-whgv

A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
21 день назад
github логотип
GHSA-36p9-w333-jhg3

A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36p9-4jqp-qvg9

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-36p9-3c3r-22pp

Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-36p8-mvp6-cv38

Wrangler affected by OS Command Injection in `wrangler pages deploy`

2%
Низкий
8 месяцев назад
github логотип
GHSA-36p8-9jxx-p4v9

Improper Control of Generation of Code ('Code Injection') vulnerability in LUBUS WP Query Console allows Code Injection.This issue affects WP Query Console: from n/a through 1.0.

CVSS3: 10
53%
Средний
почти 2 года назад
github логотип
GHSA-36p8-6qw9-45qf

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-36p7-xjw8-h6f2

Ruby-saml allows attackers to perform XML signature wrapping attacks

CVSS3: 7.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-36p7-vc44-83pf

ChromaDB has a code injection vulnerability

0%
Низкий
3 месяца назад
github логотип
GHSA-36p7-pvq8-jjmx

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight allows Object Injection. This issue affects Employee Spotlight: from n/a through 5.1.1.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-36p7-jqv6-r5mj

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-36p7-fgf7-w6rh

Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Banking Payments accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36p6-h78p-cx2w

Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity

0%
Низкий
7 месяцев назад
github логотип
GHSA-36p4-cjjg-rccj

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-36p3-wjmg-h94x

Remote Code Execution in Spring Framework

CVSS3: 9.8
100%
Критический
больше 4 лет назад
github логотип
GHSA-36p3-m272-rwxj

The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-36p3-j543-mpj6

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36p3-8r74-q5hh

Rejected reason: This CVE ID has been rejected.

около 1 месяца назад

Уязвимостей на страницу