Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-xx8w-4q6h-66xg

около 1 года назад

DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xx8v-jwch-cjrx

почти 4 года назад

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.

EPSS: Низкий
github логотип

GHSA-xx8v-9cvf-fc7h

больше 3 лет назад

Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

EPSS: Низкий
github логотип

GHSA-xx8r-qhq8-fw6r

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter) plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

EPSS: Низкий
github логотип

GHSA-xx8r-qcqq-3fgj

больше 3 лет назад

In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx8r-jj29-vw5j

около 1 месяца назад

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx8r-j779-rrrw

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx8r-cffm-j9h6

больше 3 лет назад

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx8r-3wgj-j632

около 1 года назад

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xx8q-m9qm-7fm9

2 месяца назад

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx8q-8jxm-3v8c

около 3 лет назад

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx8f-qf9f-5fgw

больше 4 лет назад

Remote code execution in zendframework and laminas-http

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xx8c-x7pm-mwj6

почти 4 года назад

Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx8c-v55p-48rc

больше 3 лет назад

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx8c-rpq7-pg6p

больше 3 лет назад

A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.

EPSS: Низкий
github логотип

GHSA-xx8c-m748-xr4j

почти 4 года назад

Access Restriction Bypass in kubernetes

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xx89-xmcq-2q77

почти 4 года назад

IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).

EPSS: Низкий
github логотип

GHSA-xx89-v728-cjjc

больше 3 лет назад

The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via an NTFS junction attack.

EPSS: Низкий
github логотип

GHSA-xx88-rwrm-3468

больше 3 лет назад

Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx88-38jg-963j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx8w-4q6h-66xg

DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xx8v-jwch-cjrx

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xx8v-9cvf-fc7h

Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx8r-qhq8-fw6r

Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter) plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx8r-qcqq-3fgj

In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx8r-jj29-vw5j

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xx8r-j779-rrrw

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xx8r-cffm-j9h6

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx8r-3wgj-j632

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xx8q-m9qm-7fm9

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xx8q-8jxm-3v8c

The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx8f-qf9f-5fgw

Remote code execution in zendframework and laminas-http

CVSS3: 9.8
92%
Критический
больше 4 лет назад
github логотип
GHSA-xx8c-x7pm-mwj6

Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx8c-v55p-48rc

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx8c-rpq7-pg6p

A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx8c-m748-xr4j

Access Restriction Bypass in kubernetes

CVSS3: 7.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx89-xmcq-2q77

IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx89-v728-cjjc

The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via an NTFS junction attack.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-xx88-rwrm-3468

Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx88-38jg-963j

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.

больше 1 года назад

Уязвимостей на страницу