Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-xxww-wjfc-r8m2

около 1 месяца назад

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxww-hv47-2ppx

больше 4 лет назад

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

EPSS: Низкий
github логотип

GHSA-xxww-73xw-x3fj

больше 3 лет назад

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxwv-v223-5w4w

больше 4 лет назад

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

EPSS: Низкий
github логотип

GHSA-xxwr-xc7w-gxgv

почти 2 года назад

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxwr-wv9g-7jw3

больше 1 года назад

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxwr-whmf-f56p

больше 4 лет назад

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxwr-v6hc-32hm

около 3 лет назад

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxwq-xf8c-v665

больше 4 лет назад

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxwq-5h7x-mm4x

около 2 лет назад

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxwm-xq6m-jwjx

больше 4 лет назад

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

EPSS: Низкий
github логотип

GHSA-xxwm-rvgr-f38w

больше 4 лет назад

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxwj-xx57-672q

5 месяцев назад

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xxwj-cpv6-f4hc

больше 4 лет назад

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

EPSS: Низкий
github логотип

GHSA-xxwh-m96h-p4c6

больше 4 лет назад

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

EPSS: Низкий
github логотип

GHSA-xxwg-wfjg-vgjp

больше 4 лет назад

In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

EPSS: Низкий
github логотип

GHSA-xxwg-crgx-46fg

больше 4 лет назад

Unspecified vulnerability in the Oracle COREid Access component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to WebGate - WebServer plugin.

EPSS: Низкий
github логотип

GHSA-xxwf-mr27-9j8v

больше 4 лет назад

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

EPSS: Низкий
github логотип

GHSA-xxwf-86w4-2rh3

больше 4 лет назад

Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxwc-wcp3-hfp4

больше 4 лет назад

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxww-wjfc-r8m2

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxww-hv47-2ppx

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxww-73xw-x3fj

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwv-v223-5w4w

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwr-xc7w-gxgv

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxwr-wv9g-7jw3

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxwr-whmf-f56p

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwr-v6hc-32hm

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxwq-xf8c-v665

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwq-5h7x-mm4x

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxwm-xq6m-jwjx

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwm-rvgr-f38w

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwj-xx57-672q

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.

CVSS3: 2.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxwj-cpv6-f4hc

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwh-m96h-p4c6

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwg-wfjg-vgjp

In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwg-crgx-46fg

Unspecified vulnerability in the Oracle COREid Access component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to WebGate - WebServer plugin.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwf-mr27-9j8v

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwf-86w4-2rh3

Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwc-wcp3-hfp4

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу