Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36j9-fp7f-7f7m

больше 1 года назад

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-36j9-2v33-g5mg

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group Currently, mtk_iommu calls during probe iommu_device_register before the hw_list from driver data is initialized. Since iommu probing issue fix, it leads to NULL pointer dereference in mtk_iommu_device_group when hw_list is accessed with list_first_entry (not null safe). So, change the call order to ensure iommu_device_register is called after the driver data are initialized.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36j8-p24p-6p6q

почти 4 года назад

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36j8-f33j-vjwq

около 4 лет назад

Passwords stored in plain text by Jenkins hpe-network-virtualization plugin

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-36j8-893c-jhgw

больше 4 лет назад

Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document.

EPSS: Низкий
github логотип

GHSA-36j6-7qfp-m37f

больше 4 лет назад

Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36j5-qc55-8r3p

больше 4 лет назад

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36j5-fm62-h365

больше 3 лет назад

Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36j5-c4mc-2jx6

больше 4 лет назад

Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.

EPSS: Низкий
github логотип

GHSA-36j4-jjhr-3m5r

около 2 лет назад

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-36j3-xxf7-4pqg

почти 6 лет назад

Android WebView Universal Cross-site Scripting

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36j3-r3wc-mhg7

6 месяцев назад

An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36j3-pwc5-6487

больше 4 лет назад

Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.

EPSS: Низкий
github логотип

GHSA-36j3-2772-j983

больше 2 лет назад

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-36hw-x3cc-m258

больше 1 года назад

Magento Improper Access Control vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-36hw-mpc9-fw23

2 месяца назад

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-36hw-4hmf-h6cg

больше 4 лет назад

SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php.

EPSS: Низкий
github логотип

GHSA-36hv-fqvj-3wq3

больше 4 лет назад

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

EPSS: Низкий
github логотип

GHSA-36hv-f25w-387h

больше 4 лет назад

The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

EPSS: Низкий
github логотип

GHSA-36hv-3xjg-vwph

больше 1 года назад

A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36j9-fp7f-7f7m

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

CVSS3: 6.1
29%
Средний
больше 1 года назад
github логотип
GHSA-36j9-2v33-g5mg

In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group Currently, mtk_iommu calls during probe iommu_device_register before the hw_list from driver data is initialized. Since iommu probing issue fix, it leads to NULL pointer dereference in mtk_iommu_device_group when hw_list is accessed with list_first_entry (not null safe). So, change the call order to ensure iommu_device_register is called after the driver data are initialized.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-36j8-p24p-6p6q

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-36j8-f33j-vjwq

Passwords stored in plain text by Jenkins hpe-network-virtualization plugin

CVSS3: 3.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-36j8-893c-jhgw

Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36j6-7qfp-m37f

Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36j5-qc55-8r3p

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36j5-fm62-h365

Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36j5-c4mc-2jx6

Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36j4-jjhr-3m5r

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

CVSS3: 6
0%
Низкий
около 2 лет назад
github логотип
GHSA-36j3-xxf7-4pqg

Android WebView Universal Cross-site Scripting

CVSS3: 6.5
4%
Низкий
почти 6 лет назад
github логотип
GHSA-36j3-r3wc-mhg7

An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14.

CVSS3: 9.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-36j3-pwc5-6487

Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36j3-2772-j983

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36hw-x3cc-m258

Magento Improper Access Control vulnerability

CVSS3: 8.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-36hw-mpc9-fw23

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

CVSS3: 4.8
0%
Низкий
2 месяца назад
github логотип
GHSA-36hw-4hmf-h6cg

SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36hv-fqvj-3wq3

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36hv-f25w-387h

The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36hv-3xjg-vwph

A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
1%
Низкий
больше 1 года назад

Уязвимостей на страницу