Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-25pc-xfh3-2798

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

EPSS: Низкий
github логотип

GHSA-25pc-rchr-295v

13 дней назад

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25pc-cjwg-288w

9 месяцев назад

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25pc-85qf-6j69

около 7 лет назад

Deserialization of Untrusted Data in Apache Storm

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25p9-h7xj-6xhv

3 месяца назад

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-25p8-9wv3-j93j

около 2 лет назад

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25p7-w4h8-7rrx

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd sn_sx, at 0x9d014f28, the value for the `cmd3` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25p6-jmrr-3hj2

больше 4 лет назад

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-25p5-wc7c-qrrg

больше 4 лет назад

Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25p4-xq52-q9pw

почти 2 года назад

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25p4-f7jc-m83q

больше 4 лет назад

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

EPSS: Низкий
github логотип

GHSA-25p3-wx48-c43f

12 месяцев назад

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection. This issue affects Awesome Support: from n/a through 6.3.4.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-25p3-r4j6-7wqc

больше 3 лет назад

The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-25p3-j54h-933p

больше 4 лет назад

VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25p3-2r5q-956q

больше 4 лет назад

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

EPSS: Низкий
github логотип

GHSA-25mx-w28c-mcm6

больше 4 лет назад

SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.

EPSS: Низкий
github логотип

GHSA-25mx-8f3v-8wh7

больше 3 лет назад

sequoia-openpgp vulnerable to out-of-bounds array access leading to panic

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-25mx-7q4c-hfgq

больше 3 лет назад

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25mx-2mxm-6343

почти 4 года назад

@keystone-6/core's NODE_ENV defaults to development with esbuild

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25mw-r645-vhvc

больше 4 лет назад

The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25pc-xfh3-2798

Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-25pc-rchr-295v

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 5.5
0%
Низкий
13 дней назад
github логотип
GHSA-25pc-cjwg-288w

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.

CVSS3: 7.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-25pc-85qf-6j69

Deserialization of Untrusted Data in Apache Storm

CVSS3: 9.8
3%
Низкий
около 7 лет назад
github логотип
GHSA-25p9-h7xj-6xhv

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

CVSS3: 8.5
0%
Низкий
3 месяца назад
github логотип
GHSA-25p8-9wv3-j93j

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-25p7-w4h8-7rrx

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd sn_sx, at 0x9d014f28, the value for the `cmd3` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25p6-jmrr-3hj2

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

CVSS3: 5.3
49%
Средний
больше 4 лет назад
github логотип
GHSA-25p5-wc7c-qrrg

Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25p4-xq52-q9pw

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.

CVSS3: 9.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-25p4-f7jc-m83q

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-25p3-wx48-c43f

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection. This issue affects Awesome Support: from n/a through 6.3.4.

CVSS3: 7.2
0%
Низкий
12 месяцев назад
github логотип
GHSA-25p3-r4j6-7wqc

The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25p3-j54h-933p

VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-25p3-2r5q-956q

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-25mx-w28c-mcm6

SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-25mx-8f3v-8wh7

sequoia-openpgp vulnerable to out-of-bounds array access leading to panic

CVSS3: 2.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25mx-7q4c-hfgq

A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25mx-2mxm-6343

@keystone-6/core's NODE_ENV defaults to development with esbuild

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-25mw-r645-vhvc

The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу