Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-xr47-4wf6-2gmw

больше 4 лет назад

Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-xr46-9c78-g7pg

больше 4 лет назад

Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful attack).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr45-qc77-mx25

10 месяцев назад

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable and subsequently passed to require_once. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server via the `[code_snippet]` shortcode using PHP filter chains granted they can trick an administrator into enabling the "Enable file-based execution" setting and creating at least one active Content snippet.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xr45-m2xg-h479

больше 4 лет назад

Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr45-72jm-wpcw

больше 1 года назад

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr45-42h9-q5rf

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.

EPSS: Низкий
github логотип

GHSA-xr44-v6xx-f99r

больше 4 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.

EPSS: Низкий
github логотип

GHSA-xr44-9893-8w63

почти 3 года назад

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xr44-7hqv-mrgr

10 месяцев назад

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr44-2pv4-gw8r

больше 2 лет назад

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xr43-rqjg-v94q

больше 4 лет назад

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.

EPSS: Низкий
github логотип

GHSA-xr43-cwp6-p6wf

около 2 лет назад

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xr42-c3pw-f2v5

20 дней назад

A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the component WebApp Sign-In. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xr42-288c-hwmj

больше 4 лет назад

WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.

EPSS: Низкий
github логотип

GHSA-xr3x-xv96-4f83

почти 3 года назад

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr3x-pg7w-4w2p

больше 4 лет назад

Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.

EPSS: Низкий
github логотип

GHSA-xr3x-fw3p-85fp

больше 4 лет назад

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr3x-62qw-vc4w

больше 4 лет назад

Grafana stored XSS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr3x-3m9h-jg3r

11 месяцев назад

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr3w-rmvj-f6m7

11 месяцев назад

Mattermost has an Observable Timing Discrepancy vulnerability

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr47-4wf6-2gmw

Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.

19%
Средний
больше 4 лет назад
github логотип
GHSA-xr46-9c78-g7pg

Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful attack).

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr45-qc77-mx25

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable and subsequently passed to require_once. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server via the `[code_snippet]` shortcode using PHP filter chains granted they can trick an administrator into enabling the "Enable file-based execution" setting and creating at least one active Content snippet.

CVSS3: 8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xr45-m2xg-h479

Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr45-72jm-wpcw

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr45-42h9-q5rf

PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr44-v6xx-f99r

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr44-9893-8w63

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 6.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xr44-7hqv-mrgr

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-xr44-2pv4-gw8r

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xr43-rqjg-v94q

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr43-cwp6-p6wf

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-xr42-c3pw-f2v5

A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the component WebApp Sign-In. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
20 дней назад
github логотип
GHSA-xr42-288c-hwmj

WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3x-xv96-4f83

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

CVSS3: 8.8
3%
Низкий
почти 3 года назад
github логотип
GHSA-xr3x-pg7w-4w2p

Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3x-fw3p-85fp

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3x-62qw-vc4w

Grafana stored XSS

CVSS3: 5.4
10%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3x-3m9h-jg3r

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xr3w-rmvj-f6m7

Mattermost has an Observable Timing Discrepancy vulnerability

CVSS3: 3.1
0%
Низкий
11 месяцев назад

Уязвимостей на страницу