Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-33gv-rvgq-gpxp

больше 3 лет назад

Withdrawn Advisory: HTML injections in BTCPayServer

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33gv-fc78-qgf5

5 месяцев назад

YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-33gr-vm8m-gj5m

больше 4 лет назад

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a denial of service (NULL pointer dereference, and device hang or reboot) via a crafted media file, aka internal bug 29770686.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33gr-gjg6-c627

10 месяцев назад

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33gq-q699-4w29

больше 1 года назад

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-33gq-cgfx-f6m6

больше 4 лет назад

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

EPSS: Низкий
github логотип

GHSA-33gp-xwq2-f742

5 месяцев назад

An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33gp-gmg3-hfpq

около 2 лет назад

XWiki Platform vulnerable to document deletion and overwrite from edit

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gm-x234-gjx5

больше 3 лет назад

File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33gm-hf2j-r258

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

EPSS: Низкий
github логотип

GHSA-33gj-cgfq-5j2j

больше 2 лет назад

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gh-f3xq-j9hx

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33gg-5m74-52cv

больше 4 лет назад

A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-33gg-4g7f-39f7

3 месяца назад

Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and apps, and determine permission levels, significantly increasing the actionability of compromised credentials.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33gg-2298-wmfp

больше 4 лет назад

Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-33gf-mr65-87rw

почти 2 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through 3.1.3.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-33gc-wq56-g94m

больше 4 лет назад

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

EPSS: Низкий
github логотип

GHSA-33gc-vmgr-56fc

больше 3 лет назад

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-33gc-p3fc-rqq7

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

EPSS: Низкий
github логотип

GHSA-33gc-f8v9-v8hm

около 6 лет назад

Malicious Package in ladder-text-js

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33gv-rvgq-gpxp

Withdrawn Advisory: HTML injections in BTCPayServer

CVSS3: 8.8
8%
Низкий
больше 3 лет назад
github логотип
GHSA-33gv-fc78-qgf5

YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-33gr-vm8m-gj5m

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a denial of service (NULL pointer dereference, and device hang or reboot) via a crafted media file, aka internal bug 29770686.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-33gr-gjg6-c627

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-33gq-q699-4w29

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

CVSS3: 7.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-33gq-cgfx-f6m6

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-33gp-xwq2-f742

An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-33gp-gmg3-hfpq

XWiki Platform vulnerable to document deletion and overwrite from edit

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-33gm-x234-gjx5

File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33gm-hf2j-r258

Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-33gj-cgfq-5j2j

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33gh-f3xq-j9hx

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-33gg-5m74-52cv

A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-33gg-4g7f-39f7

Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and apps, and determine permission levels, significantly increasing the actionability of compromised credentials.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-33gg-2298-wmfp

Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-33gf-mr65-87rw

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through 3.1.3.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-33gc-wq56-g94m

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33gc-vmgr-56fc

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33gc-p3fc-rqq7

Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33gc-f8v9-v8hm

Malicious Package in ladder-text-js

CVSS3: 9.8
около 6 лет назад

Уязвимостей на страницу