Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-254w-f98v-hx59

24 дня назад

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.

EPSS: Низкий
github логотип

GHSA-254v-xjfq-x8gj

больше 4 лет назад

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

EPSS: Низкий
github логотип

GHSA-254v-c952-g64w

больше 1 года назад

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254v-3mjq-6mjm

больше 4 лет назад

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

EPSS: Низкий
github логотип

GHSA-254r-xffm-9c3g

больше 1 года назад

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-254r-9mcw-9755

10 дней назад

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-254r-9226-v29v

больше 4 лет назад

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254q-rqmw-vx45

больше 4 лет назад

Missing Authorization in librenms/librenms

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-254q-rp36-v2m8

больше 4 лет назад

Missing XML Validation in Apache CXF

EPSS: Средний
github логотип

GHSA-254q-r25r-fwm9

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-254p-hhvc-rr9q

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-254p-9j5r-3fvc

больше 4 лет назад

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

EPSS: Низкий
github логотип

GHSA-254m-79rf-mxh7

больше 4 лет назад

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

EPSS: Низкий
github логотип

GHSA-254m-3cq9-8624

больше 4 лет назад

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-254j-mmc5-qhpx

больше 4 лет назад

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-254j-3m2w-23xr

больше 4 лет назад

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

EPSS: Низкий
github логотип

GHSA-254h-gvgq-x2xg

около 2 лет назад

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-254g-wcpq-w26f

6 месяцев назад

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-254g-h6q6-4fxv

больше 4 лет назад

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

EPSS: Низкий
github логотип

GHSA-254f-jwvx-j47x

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-254w-f98v-hx59

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.

0%
Низкий
24 дня назад
github логотип
GHSA-254v-xjfq-x8gj

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-254v-c952-g64w

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-254v-3mjq-6mjm

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-254r-xffm-9c3g

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-254r-9mcw-9755

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
10 дней назад
github логотип
GHSA-254r-9226-v29v

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-254q-rqmw-vx45

Missing Authorization in librenms/librenms

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-254q-rp36-v2m8

Missing XML Validation in Apache CXF

32%
Средний
больше 4 лет назад
github логотип
GHSA-254q-r25r-fwm9

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-254p-hhvc-rr9q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-254p-9j5r-3fvc

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-254m-79rf-mxh7

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-254m-3cq9-8624

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-254j-mmc5-qhpx

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-254j-3m2w-23xr

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-254h-gvgq-x2xg

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-254g-wcpq-w26f

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.

CVSS3: 2.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-254g-h6q6-4fxv

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-254f-jwvx-j47x

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу