Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-xxg7-9g5c-hjq7

больше 2 лет назад

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xxg7-747h-w72j

10 месяцев назад

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxg6-wvf8-73xv

больше 3 лет назад

A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is 2606983c20f6ea3430ac4b36b3d2e88aafef45da. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216168.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxg6-fj84-6x42

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xxg5-rxch-5cr5

около 4 лет назад

Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1754.

EPSS: Низкий
github логотип

GHSA-xxg5-6c43-cq68

около 4 лет назад

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxg4-wh8m-4g6r

около 4 лет назад

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Heap Corruption starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxg3-955j-2rj3

около 1 года назад

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxg3-6996-vw43

около 4 лет назад

A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxg2-xvp8-vqm5

5 месяцев назад

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxfx-w2rw-gh63

больше 3 лет назад

csaf-poc/csaf_distribution Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxfx-h76g-4vhr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."

EPSS: Средний
github логотип

GHSA-xxfv-6x75-qv66

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Green Thumb greenthumb allows PHP Local File Inclusion.This issue affects Green Thumb: from n/a through <= 1.1.12.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xxfv-6426-45jv

около 4 лет назад

There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

EPSS: Низкий
github логотип

GHSA-xxfv-4p77-f27m

около 4 лет назад

A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

EPSS: Низкий
github логотип

GHSA-xxfr-xhcv-m89f

больше 4 лет назад

XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.

EPSS: Низкий
github логотип

GHSA-xxfr-jrgh-x392

почти 5 лет назад

Remote code execution in ChakraCore

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxfr-gfjr-h844

около 4 лет назад

slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xxfr-7v35-gvhr

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xxfq-g4g6-2pwg

3 дня назад

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxg7-9g5c-hjq7

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxg7-747h-w72j

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxg6-wvf8-73xv

A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is 2606983c20f6ea3430ac4b36b3d2e88aafef45da. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216168.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxg6-fj84-6x42

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-xxg5-rxch-5cr5

Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1754.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxg5-6c43-cq68

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxg4-wh8m-4g6r

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Heap Corruption starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxg3-955j-2rj3

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
около 1 года назад
github логотип
GHSA-xxg3-6996-vw43

A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxg2-xvp8-vqm5

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxfx-w2rw-gh63

csaf-poc/csaf_distribution Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxfx-h76g-4vhr

Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."

23%
Средний
больше 4 лет назад
github логотип
GHSA-xxfv-6x75-qv66

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Green Thumb greenthumb allows PHP Local File Inclusion.This issue affects Green Thumb: from n/a through <= 1.1.12.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxfv-6426-45jv

There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xxfv-4p77-f27m

A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxfr-xhcv-m89f

XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxfr-jrgh-x392

Remote code execution in ChakraCore

CVSS3: 7.5
2%
Низкий
почти 5 лет назад
github логотип
GHSA-xxfr-gfjr-h844

slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.

CVSS3: 4.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxfr-7v35-gvhr

Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxfq-g4g6-2pwg

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
0%
Низкий
3 дня назад

Уязвимостей на страницу