Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-xxwv-v223-5w4w

больше 4 лет назад

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

EPSS: Низкий
github логотип

GHSA-xxwr-xc7w-gxgv

больше 1 года назад

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxwr-wv9g-7jw3

около 1 года назад

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxwr-whmf-f56p

больше 4 лет назад

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxwr-v6hc-32hm

почти 3 года назад

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxwq-xf8c-v665

больше 4 лет назад

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxwq-5h7x-mm4x

около 2 лет назад

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxwm-xq6m-jwjx

больше 4 лет назад

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

EPSS: Низкий
github логотип

GHSA-xxwm-rvgr-f38w

около 4 лет назад

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxwj-xx57-672q

4 месяца назад

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xxwj-cpv6-f4hc

около 4 лет назад

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

EPSS: Низкий
github логотип

GHSA-xxwh-m96h-p4c6

около 4 лет назад

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

EPSS: Низкий
github логотип

GHSA-xxwg-wfjg-vgjp

около 4 лет назад

In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

EPSS: Низкий
github логотип

GHSA-xxwg-crgx-46fg

около 4 лет назад

Unspecified vulnerability in the Oracle COREid Access component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to WebGate - WebServer plugin.

EPSS: Низкий
github логотип

GHSA-xxwf-mr27-9j8v

около 4 лет назад

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

EPSS: Низкий
github логотип

GHSA-xxwf-86w4-2rh3

около 4 лет назад

Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxwc-wcp3-hfp4

больше 4 лет назад

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

EPSS: Низкий
github логотип

GHSA-xxwc-hg26-q85m

11 месяцев назад

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore and policies. An attacker with local access to the system running the Agent can access these files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxwc-8p4f-87mq

около 4 лет назад

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS: Низкий
github логотип

GHSA-xxwc-76rq-3m55

около 4 лет назад

The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxwv-v223-5w4w

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwr-xc7w-gxgv

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxwr-wv9g-7jw3

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xxwr-whmf-f56p

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwr-v6hc-32hm

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxwq-xf8c-v665

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwq-5h7x-mm4x

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxwm-xq6m-jwjx

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwm-rvgr-f38w

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxwj-xx57-672q

SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.

CVSS3: 2.7
0%
Низкий
4 месяца назад
github логотип
GHSA-xxwj-cpv6-f4hc

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xxwh-m96h-p4c6

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xxwg-wfjg-vgjp

In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxwg-crgx-46fg

Unspecified vulnerability in the Oracle COREid Access component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to WebGate - WebServer plugin.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxwf-mr27-9j8v

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxwf-86w4-2rh3

Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xxwc-wcp3-hfp4

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxwc-hg26-q85m

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore and policies. An attacker with local access to the system running the Agent can access these files.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxwc-8p4f-87mq

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xxwc-76rq-3m55

The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу