Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36g3-5c2m-mrqx

почти 2 года назад

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-36g2-h6pw-2fpg

больше 4 лет назад

The “Clever Addons for Elementor� WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

EPSS: Низкий
github логотип

GHSA-36fx-x9hq-pvcq

больше 4 лет назад

Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.

EPSS: Низкий
github логотип

GHSA-36fx-rf6c-vc8x

больше 4 лет назад

Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.

EPSS: Низкий
github логотип

GHSA-36fw-cxfr-92fm

больше 4 лет назад

In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709

EPSS: Низкий
github логотип

GHSA-36fw-7hg5-xv5p

больше 4 лет назад

A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.

EPSS: Средний
github логотип

GHSA-36fw-723j-3pvw

больше 4 лет назад

muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file.

EPSS: Низкий
github логотип

GHSA-36fv-g9xp-84xv

8 месяцев назад

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36fv-7fxv-xr4g

больше 4 лет назад

Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.

EPSS: Средний
github логотип

GHSA-36fv-6vjc-jf92

больше 1 года назад

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-36fr-xc4j-fmhw

больше 4 лет назад

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.

EPSS: Низкий
github логотип

GHSA-36fr-w5h7-5f28

больше 4 лет назад

Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.

EPSS: Низкий
github логотип

GHSA-36fr-3wg8-q5v8

почти 3 года назад

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-36fr-2gcj-778v

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36fq-jgmw-4r9c

около 1 года назад

Keras is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-36fq-6c6v-89gr

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-36fq-3276-7898

около 2 лет назад

A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-36fp-xj79-95mx

больше 4 лет назад

Links may not be rewritten according to policy in some specially formatted emails.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36fm-v9wv-56jf

больше 5 лет назад

Cross-site Scripting in OpenCart

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36fm-j33w-c25f

больше 3 лет назад

Privilege escalation (PR)/RCE from account through class sheet

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36g3-5c2m-mrqx

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-36g2-h6pw-2fpg

The “Clever Addons for Elementor� WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36fx-x9hq-pvcq

Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36fx-rf6c-vc8x

Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36fw-cxfr-92fm

In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709

0%
Низкий
больше 4 лет назад
github логотип
GHSA-36fw-7hg5-xv5p

A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.

35%
Средний
больше 4 лет назад
github логотип
GHSA-36fw-723j-3pvw

muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-36fv-g9xp-84xv

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-36fv-7fxv-xr4g

Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.

16%
Средний
больше 4 лет назад
github логотип
GHSA-36fv-6vjc-jf92

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

CVSS3: 6.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-36fr-xc4j-fmhw

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-36fr-w5h7-5f28

Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-36fr-3wg8-q5v8

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 3.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-36fr-2gcj-778v

A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36fq-jgmw-4r9c

Keras is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-36fq-6c6v-89gr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36fq-3276-7898

A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-36fp-xj79-95mx

Links may not be rewritten according to policy in some specially formatted emails.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36fm-v9wv-56jf

Cross-site Scripting in OpenCart

CVSS3: 5.4
3%
Низкий
больше 5 лет назад
github логотип
GHSA-36fm-j33w-c25f

Privilege escalation (PR)/RCE from account through class sheet

CVSS3: 9.9
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу