Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-3693-57g2-4j5q

около 2 лет назад

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3692-hqvq-62f5

больше 4 лет назад

Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.

EPSS: Низкий
github логотип

GHSA-368x-wmmg-hq5c

больше 3 лет назад

Apollo has potential access control security issue in eureka

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-368x-vqh8-wg8x

почти 3 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-368x-rx64-j3wc

8 месяцев назад

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-368x-g6j7-2g8q

больше 4 лет назад

Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

EPSS: Низкий
github логотип

GHSA-368w-vm6r-8gm2

больше 4 лет назад

Buffer overflow in the expandtabs function in 2fax 3.04 allows remote attackers to execute arbitrary code via a text file that is converted to TIFF.

EPSS: Низкий
github логотип

GHSA-368v-m4p5-vmm4

больше 4 лет назад

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.

EPSS: Низкий
github логотип

GHSA-368v-7v32-52fx

почти 4 года назад

Overflow in `ResizeNearestNeighborGrad`

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-368v-5x4r-9cfg

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-368v-5vcp-j279

почти 2 года назад

Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-368r-9597-529x

больше 2 лет назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-368q-3gfm-fh6f

почти 2 года назад

Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and the Length argument for RtlCopyMemory, both independently dereference their value from the user supplied input buffer inside the EpdlpSetUsbAction function, known as a double-fetch. If this length value grows to a higher value in between these two calls, it will result in the RtlCopyMemory call copying user-supplied memory contents outside the range of the allocated buffer, resulting in a heap overflow. A malicious attacker will need admin privileges to exploit the issue. This issue affects Endpoint DLP version below R119.

EPSS: Низкий
github логотип

GHSA-368q-2rmx-wg7f

больше 4 лет назад

Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file.

EPSS: Низкий
github логотип

GHSA-368p-hj7r-f6v7

больше 4 лет назад

A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.

EPSS: Низкий
github логотип

GHSA-368p-45pv-mjr9

больше 4 лет назад

Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."

EPSS: Высокий
github логотип

GHSA-368p-325h-g73p

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Denishua Comment Reply Notification plugin <= 1.4 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-368m-gh85-cq79

23 дня назад

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-368j-g93f-6hjp

больше 3 лет назад

Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-368j-92cq-wrg5

больше 4 лет назад

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3693-57g2-4j5q

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3692-hqvq-62f5

Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-368x-wmmg-hq5c

Apollo has potential access control security issue in eureka

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-368x-vqh8-wg8x

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.

CVSS3: 8.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-368x-rx64-j3wc

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.

CVSS3: 8.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-368x-g6j7-2g8q

Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-368w-vm6r-8gm2

Buffer overflow in the expandtabs function in 2fax 3.04 allows remote attackers to execute arbitrary code via a text file that is converted to TIFF.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-368v-m4p5-vmm4

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-368v-7v32-52fx

Overflow in `ResizeNearestNeighborGrad`

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-368v-5x4r-9cfg

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-368v-5vcp-j279

Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-368r-9597-529x

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-368q-3gfm-fh6f

Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and the Length argument for RtlCopyMemory, both independently dereference their value from the user supplied input buffer inside the EpdlpSetUsbAction function, known as a double-fetch. If this length value grows to a higher value in between these two calls, it will result in the RtlCopyMemory call copying user-supplied memory contents outside the range of the allocated buffer, resulting in a heap overflow. A malicious attacker will need admin privileges to exploit the issue. This issue affects Endpoint DLP version below R119.

0%
Низкий
почти 2 года назад
github логотип
GHSA-368q-2rmx-wg7f

Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-368p-hj7r-f6v7

A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-368p-45pv-mjr9

Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."

83%
Высокий
больше 4 лет назад
github логотип
GHSA-368p-325h-g73p

Cross-Site Request Forgery (CSRF) vulnerability in Denishua Comment Reply Notification plugin <= 1.4 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-368m-gh85-cq79

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

CVSS3: 4.7
0%
Низкий
23 дня назад
github логотип
GHSA-368j-g93f-6hjp

Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request

CVSS3: 8.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-368j-92cq-wrg5

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу