Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-24rc-w3ff-pw6w

5 месяцев назад

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-24r9-p447-gxg2

больше 4 лет назад

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

EPSS: Низкий
github логотип

GHSA-24r9-8wx9-6g9f

около 2 лет назад

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r8-w5p9-r798

19 дней назад

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24r8-jmfh-r268

больше 3 лет назад

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24r8-fm9r-cpj2

почти 7 лет назад

Low severity vulnerability that affects com.linecorp.armeria:armeria

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-24r7-x8mx-hc2h

больше 4 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r7-c5r6-xxmj

больше 4 лет назад

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-24r6-29j2-hrjv

больше 4 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

EPSS: Низкий
github логотип

GHSA-24r5-xw2j-9h9x

больше 2 лет назад

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24r5-pqg8-wx72

17 дней назад

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 before 3.5.5.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24r3-rx3r-wgvw

больше 2 лет назад

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24r3-qrv6-6jx6

больше 4 лет назад

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-24r3-p3x6-cqvx

3 месяца назад

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-24r2-2rf2-whfq

больше 1 года назад

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24qx-w28j-9m6p

4 месяца назад

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

EPSS: Низкий
github логотип

GHSA-24qx-986r-jvf4

больше 4 лет назад

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qw-g5w5-55fm

больше 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-24qw-797r-8hmj

больше 4 лет назад

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24qw-5j5f-29wm

1 день назад

In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager: register regulators before exposing sysfs charger_manager_remove() and the err_reg_extcon probe error path free each charger regulator with regulator_put() before tearing down the power_supply sysfs entries (power_supply_unregister()). charger_manager_remove() also calls try_charger_enable(cm, false) after the regulator_put() loop. A concurrent write to a charger's externally_control sysfs attribute that lands between regulator_put() and power_supply_unregister() can run charger_externally_control_store() and call try_charger_enable(), which, when charging is enabled, dereferences the already-freed consumer handle. When charging is enabled, try_charger_enable(cm, false) in .remove() also dereferences the freed handles directly. Both leave use-after-free windows. Symmetrically, probe registers the sysfs entries (power_supply_register) before acquiring the regulators (regulator_get, i...

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24rc-w3ff-pw6w

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.

CVSS3: 5.3
1%
Низкий
5 месяцев назад
github логотип
GHSA-24r9-p447-gxg2

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-24r9-8wx9-6g9f

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVSS3: 9.8
10%
Средний
около 2 лет назад
github логотип
GHSA-24r8-w5p9-r798

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS3: 9.8
19 дней назад
github логотип
GHSA-24r8-jmfh-r268

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24r8-fm9r-cpj2

Low severity vulnerability that affects com.linecorp.armeria:armeria

CVSS3: 4.8
1%
Низкий
почти 7 лет назад
github логотип
GHSA-24r7-x8mx-hc2h

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
42%
Средний
больше 4 лет назад
github логотип
GHSA-24r7-c5r6-xxmj

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-24r6-29j2-hrjv

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

5%
Низкий
больше 4 лет назад
github логотип
GHSA-24r5-xw2j-9h9x

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24r5-pqg8-wx72

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 before 3.5.5.

CVSS3: 7.5
0%
Низкий
17 дней назад
github логотип
GHSA-24r3-rx3r-wgvw

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24r3-qrv6-6jx6

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

10%
Средний
больше 4 лет назад
github логотип
GHSA-24r3-p3x6-cqvx

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
1%
Низкий
3 месяца назад
github логотип
GHSA-24r2-2rf2-whfq

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-24qx-w28j-9m6p

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

0%
Низкий
4 месяца назад
github логотип
GHSA-24qx-986r-jvf4

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24qw-g5w5-55fm

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
13%
Средний
больше 4 лет назад
github логотип
GHSA-24qw-797r-8hmj

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24qw-5j5f-29wm

In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager: register regulators before exposing sysfs charger_manager_remove() and the err_reg_extcon probe error path free each charger regulator with regulator_put() before tearing down the power_supply sysfs entries (power_supply_unregister()). charger_manager_remove() also calls try_charger_enable(cm, false) after the regulator_put() loop. A concurrent write to a charger's externally_control sysfs attribute that lands between regulator_put() and power_supply_unregister() can run charger_externally_control_store() and call try_charger_enable(), which, when charging is enabled, dereferences the already-freed consumer handle. When charging is enabled, try_charger_enable(cm, false) in .remove() also dereferences the freed handles directly. Both leave use-after-free windows. Symmetrically, probe registers the sysfs entries (power_supply_register) before acquiring the regulators (regulator_get, i...

1 день назад

Уязвимостей на страницу