Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq4g-5hpc-wfcx

больше 2 лет назад

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq4f-rq5v-998c

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

EPSS: Низкий
github логотип

GHSA-xq4f-j8wj-pf7x

около 4 лет назад

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4f-f2vc-9hxr

около 4 лет назад

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq4f-cq2m-g7xp

больше 1 года назад

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq4f-9xp4-279p

около 2 лет назад

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xq4f-3jxp-qv6m

11 месяцев назад

csvjson vulnerable to prototype injection

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq4c-v44m-4gw8

около 4 лет назад

Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xq4c-q7v4-538j

около 4 лет назад

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4c-4fcc-74mp

больше 4 лет назад

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

EPSS: Низкий
github логотип

GHSA-xq49-p575-q243

больше 4 лет назад

Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.

EPSS: Низкий
github логотип

GHSA-xq48-v3hh-p87r

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xq48-pc3g-f75m

больше 4 лет назад

PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter.

EPSS: Низкий
github логотип

GHSA-xq47-rgwp-c6c5

11 месяцев назад

NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information disclosure and denial of service on the network interface.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq47-m665-g822

около 4 лет назад

SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq47-3w7m-hfjp

около 4 лет назад

An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.

EPSS: Низкий
github логотип

GHSA-xq46-mjg4-6pcj

почти 4 года назад

Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq46-j345-hjrw

больше 3 лет назад

A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq46-c84j-2v2w

больше 3 лет назад

An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq46-6333-gp73

12 месяцев назад

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq4g-5hpc-wfcx

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xq4f-rq5v-998c

Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xq4f-j8wj-pf7x

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq4f-f2vc-9hxr

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq4f-cq2m-g7xp

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4f-9xp4-279p

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xq4f-3jxp-qv6m

csvjson vulnerable to prototype injection

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xq4c-v44m-4gw8

Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.

CVSS3: 7.5
12%
Средний
около 4 лет назад
github логотип
GHSA-xq4c-q7v4-538j

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq4c-4fcc-74mp

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq49-p575-q243

Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq48-v3hh-p87r

Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq48-pc3g-f75m

PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq47-rgwp-c6c5

NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information disclosure and denial of service on the network interface.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xq47-m665-g822

SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq47-3w7m-hfjp

An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq46-mjg4-6pcj

Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq46-j345-hjrw

A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq46-c84j-2v2w

An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq46-6333-gp73

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
12 месяцев назад

Уязвимостей на страницу