Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-236h-r3w7-c85c

больше 4 лет назад

Cross-site Scripting in Apache Atlas

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-236h-5c6c-jrfx

около 4 лет назад

userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-236g-v823-mwh3

около 2 лет назад

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236g-r9c7-hmw7

около 4 лет назад

Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-236g-7xc8-897f

больше 4 лет назад

Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."

EPSS: Низкий
github логотип

GHSA-236g-4rjq-c23m

12 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-236f-wx7r-xqwv

больше 4 лет назад

eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.

EPSS: Низкий
github логотип

GHSA-236f-m6gm-vp93

больше 1 года назад

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-236f-jwrv-vrp5

больше 3 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd_generic.lua plugin for the xupnpd service, which listens on TCP port 4044 by default. When parsing the feed parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15906.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236f-3q2h-xcw5

около 2 месяцев назад

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236c-vhj4-gfxg

около 4 лет назад

Duplicate Advisory: Embedded malware in ua-parser-js

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236c-rp7g-fqf2

около 4 лет назад

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

EPSS: Низкий
github логотип

GHSA-236c-jvm7-g9g6

больше 4 лет назад

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-236c-586c-7q48

около 1 года назад

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2369-w664-2vw7

больше 4 лет назад

Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2369-v4cc-9249

больше 4 лет назад

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run...

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2369-78ph-422f

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2369-45jq-xgc9

5 месяцев назад

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2368-j9pf-v6jc

около 4 лет назад

Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly severe," (3) "moderately severe," and (4) "less severe" issues.

EPSS: Низкий
github логотип

GHSA-2367-xw5p-w8h5

2 месяца назад

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-236h-r3w7-c85c

Cross-site Scripting in Apache Atlas

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-236h-5c6c-jrfx

userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-236g-v823-mwh3

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-236g-r9c7-hmw7

Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-236g-7xc8-897f

Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-236g-4rjq-c23m

Rejected reason: Not used

12 месяцев назад
github логотип
GHSA-236f-wx7r-xqwv

eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-236f-m6gm-vp93

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-236f-jwrv-vrp5

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd_generic.lua plugin for the xupnpd service, which listens on TCP port 4044 by default. When parsing the feed parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15906.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-236f-3q2h-xcw5

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-236c-vhj4-gfxg

Duplicate Advisory: Embedded malware in ua-parser-js

CVSS3: 8.8
около 4 лет назад
github логотип
GHSA-236c-rp7g-fqf2

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

1%
Низкий
около 4 лет назад
github логотип
GHSA-236c-jvm7-g9g6

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
github логотип
GHSA-236c-586c-7q48

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2369-w664-2vw7

Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2369-v4cc-9249

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run...

CVSS3: 9.6
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2369-78ph-422f

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

CVSS3: 9.3
1%
Низкий
2 месяца назад
github логотип
GHSA-2369-45jq-xgc9

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-2368-j9pf-v6jc

Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly severe," (3) "moderately severe," and (4) "less severe" issues.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2367-xw5p-w8h5

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу