Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-xpvj-w7p2-65fm

почти 4 года назад

Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.

EPSS: Низкий
github логотип

GHSA-xpvj-vm4g-wmjm

больше 2 лет назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Nicola Modugno Smart Cookie Kit plugin <= 2.3.1 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpvh-pm8h-2p8g

около 2 лет назад

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpvg-vmj8-f29g

около 3 лет назад

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpvg-6vx6-vc72

почти 4 года назад

In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpvf-6qcc-9jqc

25 дней назад

Mattermost fails to validate team-specific upload_file permissions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpvc-gvmh-mpmj

почти 4 года назад

Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-xpv9-9vrq-v7c4

около 2 месяцев назад

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpv8-fw7f-p7c6

почти 4 года назад

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

EPSS: Низкий
github логотип

GHSA-xpv8-33xp-mjf2

почти 4 года назад

Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpv7-p5h9-8rgm

около 4 лет назад

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpv7-93cm-4mxv

почти 4 года назад

img_auth.php may leak private extension images into the public cache

EPSS: Низкий
github логотип

GHSA-xpv7-5pmx-7r5h

11 месяцев назад

Missing Authorization vulnerability in Etsy360 Embed and Integrate Etsy Shop allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embed and Integrate Etsy Shop: from n/a through 1.0.4.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpv6-mc85-j28m

около 1 года назад

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpv6-88fr-wq7p

почти 4 года назад

An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpv5-92cc-8f65

около 1 года назад

musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpv3-x3xh-h28r

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of symlink creations don't give more information than telling that something goes wrong, since the usual code path is a lregister callback from each control element creation. More badly, the use of WARN() rather confuses fuzzer as if it were serious issues. This patch downgrades the warning messages to use the normal dev_err() instead of WARN(). For making it clearer, add the function name to the prefix, too.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpv3-wh3r-49xg

почти 4 года назад

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpv2-wfwf-r6xf

7 месяцев назад

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the uss_setting_page function when processing the uss_set form type. This makes it possible for unauthenticated attackers to modify critical Upyun cloud storage settings including bucket name, operator credentials, upload paths, and image processing parameters via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpv2-c6wv-9xg2

почти 4 года назад

AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpvj-w7p2-65fm

Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpvj-vm4g-wmjm

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Nicola Modugno Smart Cookie Kit plugin <= 2.3.1 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpvh-pm8h-2p8g

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xpvg-vmj8-f29g

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xpvg-6vx6-vc72

In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpvf-6qcc-9jqc

Mattermost fails to validate team-specific upload_file permissions

CVSS3: 4.3
0%
Низкий
25 дней назад
github логотип
GHSA-xpvc-gvmh-mpmj

Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via unknown attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpv9-9vrq-v7c4

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpv8-fw7f-p7c6

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpv8-33xp-mjf2

Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpv7-p5h9-8rgm

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.

CVSS3: 8.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-xpv7-93cm-4mxv

img_auth.php may leak private extension images into the public cache

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpv7-5pmx-7r5h

Missing Authorization vulnerability in Etsy360 Embed and Integrate Etsy Shop allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embed and Integrate Etsy Shop: from n/a through 1.0.4.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xpv6-mc85-j28m

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xpv6-88fr-wq7p

An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpv5-92cc-8f65

musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xpv3-x3xh-h28r

In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of symlink creations don't give more information than telling that something goes wrong, since the usual code path is a lregister callback from each control element creation. More badly, the use of WARN() rather confuses fuzzer as if it were serious issues. This patch downgrades the warning messages to use the normal dev_err() instead of WARN(). For making it clearer, add the function name to the prefix, too.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpv3-wh3r-49xg

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpv2-wfwf-r6xf

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the uss_setting_page function when processing the uss_set form type. This makes it possible for unauthenticated attackers to modify critical Upyun cloud storage settings including bucket name, operator credentials, upload paths, and image processing parameters via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xpv2-c6wv-9xg2

AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.

2%
Низкий
почти 4 года назад

Уязвимостей на страницу