Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-xr4j-2qp3-r4xc

больше 1 года назад

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xr4h-xg4j-4v8c

больше 3 лет назад

Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xr4h-93hj-62q2

около 2 лет назад

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr4g-wmqx-7w9w

больше 4 лет назад

The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr4g-93qp-pf58

больше 4 лет назад

Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

EPSS: Низкий
github логотип

GHSA-xr4f-pqj2-jwc5

больше 4 лет назад

Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.

EPSS: Низкий
github логотип

GHSA-xr4f-mjxj-w6w5

3 месяца назад

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xr4f-cr86-pfhv

больше 4 лет назад

Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xr4f-2rrr-cm48

почти 3 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr4c-xrjh-v47v

5 месяцев назад

Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xr4c-mmrv-3h6c

около 2 лет назад

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xr4c-88wp-frr7

больше 4 лет назад

Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."

EPSS: Низкий
github логотип

GHSA-xr49-qh48-cff9

больше 2 лет назад

Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xr49-pr22-vxc8

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.

EPSS: Низкий
github логотип

GHSA-xr49-f4rh-qcjf

5 месяцев назад

AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization

EPSS: Низкий
github логотип

GHSA-xr49-8593-rwjh

около 1 месяца назад

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr49-7fhc-h2jh

почти 4 года назад

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr48-rvqv-pwjm

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr47-pcmx-fq2m

больше 2 лет назад

Certain sequence of payloads may lead to remote code execution

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xr47-8jmm-28wq

больше 2 лет назад

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr4j-2qp3-r4xc

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr4h-xg4j-4v8c

Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xr4h-93hj-62q2

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-xr4g-wmqx-7w9w

The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr4g-93qp-pf58

Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr4f-pqj2-jwc5

Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr4f-mjxj-w6w5

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

CVSS3: 8.3
3 месяца назад
github логотип
GHSA-xr4f-cr86-pfhv

Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr4f-2rrr-cm48

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xr4c-xrjh-v47v

Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-xr4c-mmrv-3h6c

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr4c-88wp-frr7

Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xr49-qh48-cff9

Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr49-pr22-vxc8

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr49-f4rh-qcjf

AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization

0%
Низкий
5 месяцев назад
github логотип
GHSA-xr49-8593-rwjh

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xr49-7fhc-h2jh

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xr48-rvqv-pwjm

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xr47-pcmx-fq2m

Certain sequence of payloads may lead to remote code execution

CVSS3: 8.1
3%
Низкий
больше 2 лет назад
github логотип
GHSA-xr47-8jmm-28wq

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу