Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-245h-cphj-6cq7

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.

EPSS: Низкий
github логотип

GHSA-245h-2vpj-f5xp

больше 4 лет назад

Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

EPSS: Низкий
github логотип

GHSA-245g-gjxh-59c2

больше 4 лет назад

Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.

EPSS: Низкий
github логотип

GHSA-245g-9f78-5jxc

около 3 лет назад

There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-245c-q43g-42cq

больше 4 лет назад

Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.

EPSS: Низкий
github логотип

GHSA-245c-fpfx-q2mm

около 2 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.3.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2459-9w34-v79g

больше 3 лет назад

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2458-wgmh-qq6g

больше 4 лет назад

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2458-q378-h4hg

больше 4 лет назад

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

EPSS: Низкий
github логотип

GHSA-2457-vhh5-pcc4

больше 4 лет назад

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

EPSS: Низкий
github логотип

GHSA-2457-jhx6-82v4

больше 4 лет назад

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2457-j253-9gg8

больше 2 лет назад

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2457-gqr3-47vq

около 3 лет назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2457-2263-mm9f

больше 4 лет назад

Memory leak in micronaut-core

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2456-wh5h-jwph

4 месяца назад

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2456-m625-hcj6

почти 3 года назад

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2456-4748-m2m2

9 месяцев назад

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2455-m68h-qwxv

3 месяца назад

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2455-5p2g-hrg7

больше 3 лет назад

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2454-7cjj-wj2v

больше 4 лет назад

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-245h-cphj-6cq7

Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-245h-2vpj-f5xp

Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-245g-gjxh-59c2

Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-245g-9f78-5jxc

There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.

CVSS3: 8.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-245c-q43g-42cq

Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-245c-fpfx-q2mm

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.3.7.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-2459-9w34-v79g

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2458-wgmh-qq6g

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2458-q378-h4hg

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2457-vhh5-pcc4

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2457-jhx6-82v4

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2457-j253-9gg8

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2457-gqr3-47vq

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2457-2263-mm9f

Memory leak in micronaut-core

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2456-wh5h-jwph

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-2456-m625-hcj6

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2456-4748-m2m2

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2455-m68h-qwxv

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-2455-5p2g-hrg7

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2454-7cjj-wj2v

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу