Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 632

Количество 325 632

github логотип

GHSA-xpxf-4p9g-j69p

почти 4 года назад

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpxc-7j8q-3794

почти 4 года назад

Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xpx9-f724-2jfc

больше 1 года назад

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpx9-9jmc-8j4w

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpx8-wp93-8pmf

почти 4 года назад

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.

EPSS: Низкий
github логотип

GHSA-xpx8-32xv-57gm

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eugenio Petullà imaGenius allows Stored XSS.This issue affects imaGenius: from n/a through 1.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpx7-q2q3-379g

почти 4 года назад

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpx7-hxr3-j5f5

почти 4 года назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpx7-g688-hrvx

9 месяцев назад

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26242.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpx7-9mqm-5g6h

почти 4 года назад

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xpx7-7hf6-5722

больше 3 лет назад

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpx7-5x44-3fqq

почти 4 года назад

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpx7-27p8-r55q

почти 4 года назад

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

EPSS: Низкий
github логотип

GHSA-xpx6-hwxg-rj79

почти 4 года назад

The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xpx5-8gpf-9924

5 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpx4-57h5-9v98

5 месяцев назад

A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpx2-vc3f-pg29

почти 4 года назад

SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

EPSS: Низкий
github логотип

GHSA-xpww-g9jx-hp8r

почти 4 года назад

Miscomputed sha2 results when using AVX2 backend

EPSS: Низкий
github логотип

GHSA-xpwv-rp39-7pr7

почти 4 года назад

Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpwv-gcc7-5gwp

около 2 лет назад

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpxf-4p9g-j69p

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpxc-7j8q-3794

Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".

CVSS3: 7.5
26%
Средний
почти 4 года назад
github логотип
GHSA-xpx9-f724-2jfc

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpx9-9jmc-8j4w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xpx8-wp93-8pmf

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpx8-32xv-57gm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eugenio Petullà imaGenius allows Stored XSS.This issue affects imaGenius: from n/a through 1.7.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xpx7-q2q3-379g

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpx7-hxr3-j5f5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

CVSS3: 7.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-xpx7-g688-hrvx

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26242.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xpx7-9mqm-5g6h

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpx7-7hf6-5722

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xpx7-5x44-3fqq

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 8.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpx7-27p8-r55q

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpx6-hwxg-rj79

The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpx5-8gpf-9924

Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xpx4-57h5-9v98

A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xpx2-vc3f-pg29

SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpww-g9jx-hp8r

Miscomputed sha2 results when using AVX2 backend

почти 4 года назад
github логотип
GHSA-xpwv-rp39-7pr7

Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpwv-gcc7-5gwp

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу