Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-363f-hg5g-qwpf

больше 1 года назад

A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-363f-897q-jph9

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-363f-7q84-2cr6

больше 4 лет назад

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with.

EPSS: Низкий
github логотип

GHSA-363c-mcgp-pjjx

почти 2 года назад

Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-363c-jmr6-7wrh

около 1 месяца назад

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/create-alerts/create-scheduled-alerts), Set up alert actions (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/configure-alert-actions/set-up-alert-actions), Define roles on the Splunk platform with capabilities (https://help....

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-363c-g524-mqxp

больше 4 лет назад

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

EPSS: Низкий
github логотип

GHSA-363c-9594-6hgr

почти 4 года назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-363c-7592-r2hx

почти 4 года назад

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-363c-4wch-3x5h

около 2 месяцев назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-3639-g9xw-jjg7

больше 4 лет назад

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

EPSS: Низкий
github логотип

GHSA-3639-c3mm-hf33

больше 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3639-77vf-hx6g

около 3 лет назад

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3638-r263-v9hp

почти 2 года назад

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3638-j9p9-fvfc

больше 2 лет назад

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3638-4f56-qcf5

больше 4 лет назад

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3637-v6vq-xqqw

около 4 лет назад

Harbor fails to validate the user permissions when updating tag retention policies

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3637-fm63-jqpr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3636-v8hq-c8g3

почти 3 года назад

The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3636-p8mw-vf54

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3636-hx62-pv26

почти 2 года назад

Zenario allows authenticated admin users to upload PDF files containing malicious code

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-363f-hg5g-qwpf

A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-363f-897q-jph9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-363f-7q84-2cr6

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-363c-mcgp-pjjx

Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-363c-jmr6-7wrh

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/create-alerts/create-scheduled-alerts), Set up alert actions (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/configure-alert-actions/set-up-alert-actions), Define roles on the Splunk platform with capabilities (https://help....

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-363c-g524-mqxp

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-363c-9594-6hgr

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-363c-7592-r2hx

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-363c-4wch-3x5h

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

около 2 месяцев назад
github логотип
GHSA-3639-g9xw-jjg7

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3639-c3mm-hf33

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3639-77vf-hx6g

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

CVSS3: 7.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-3638-r263-v9hp

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3638-j9p9-fvfc

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3638-4f56-qcf5

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3637-v6vq-xqqw

Harbor fails to validate the user permissions when updating tag retention policies

CVSS3: 7.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-3637-fm63-jqpr

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3636-v8hq-c8g3

The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3636-p8mw-vf54

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-3636-hx62-pv26

Zenario allows authenticated admin users to upload PDF files containing malicious code

CVSS3: 4.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу