Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 285 664

Количество 285 664

github логотип

GHSA-xx6m-fqm7-6ghv

около 3 лет назад

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx6m-c65f-7c53

больше 2 лет назад

Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSenha, (4) termo, (5) nome, (6) cnpj, (7) ie, (8) cep, (9) logradouro, (10) numero, (11) bairro, (12) cidade, (13) uf, (14) telefone, (15) email, (16) id, (17) app_name, (18) per_page, (19) app_theme, (20) os_notification, (21) email_automatico, (22) control_estoque, (23) notifica_whats, (24) control_baixa, (25) control_editos, (26) control_edit_vendas, (27) control_datatable, (28) pix_key, (29) os_status_list, (30) control_2vias, (31) status, (32) start, (33) end in file application/controllers/Mapos.php; (34) token, (35) senha, (36) email, (37) nomeCliente, (38) documento, (39) telefone, (40) celular, (41) rua, (42) numero, (43) complemento, (44) bairro, (45) cidade, (46) estado, (47) cep, (48) idClientes, (49) descricaoProduto, (50) defeito in file application/controllers/Mine.php; (51) pesquisa, (52) stat...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx6j-wqj7-mrv3

около 3 лет назад

The HTTP client in the Build tool in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx6j-mphq-3862

около 3 лет назад

Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

EPSS: Низкий
github логотип

GHSA-xx6h-j6cp-9v8w

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of OCG objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6435.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx6h-c2fx-v78f

8 месяцев назад

Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx6g-jj35-pxjv

больше 2 лет назад

Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xx6g-8fh5-hq6c

10 месяцев назад

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-xx6c-8hhq-9qc2

около 3 лет назад

Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx69-w8cq-c673

около 2 лет назад

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx69-qcm3-mp67

больше 3 лет назад

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xx69-9jc8-q7jv

5 месяцев назад

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx68-jfcg-xmmf

больше 6 лет назад

Commons FileUpload Denial of service vulnerability

EPSS: Критический
github логотип

GHSA-xx68-3f2p-v63m

больше 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0113.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xx68-37v4-4596

8 месяцев назад

SiYuan has an arbitrary file read via /api/template/render

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx67-mj7c-3wvg

около 3 лет назад

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx67-2j3v-h76p

больше 3 лет назад

PrestaShop PHP Object Injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx66-m4r3-r5vf

около 3 лет назад

An XML External Entity (XXE) issue exists in Kaseya VSA before 9.5.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx66-m35j-5xhv

больше 3 лет назад

Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.

EPSS: Низкий
github логотип

GHSA-xx66-279r-8pgf

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change application settings or (2) conduct cross-site scripting (XSS) attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx6m-fqm7-6ghv

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xx6m-c65f-7c53

Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSenha, (4) termo, (5) nome, (6) cnpj, (7) ie, (8) cep, (9) logradouro, (10) numero, (11) bairro, (12) cidade, (13) uf, (14) telefone, (15) email, (16) id, (17) app_name, (18) per_page, (19) app_theme, (20) os_notification, (21) email_automatico, (22) control_estoque, (23) notifica_whats, (24) control_baixa, (25) control_editos, (26) control_edit_vendas, (27) control_datatable, (28) pix_key, (29) os_status_list, (30) control_2vias, (31) status, (32) start, (33) end in file application/controllers/Mapos.php; (34) token, (35) senha, (36) email, (37) nomeCliente, (38) documento, (39) telefone, (40) celular, (41) rua, (42) numero, (43) complemento, (44) bairro, (45) cidade, (46) estado, (47) cep, (48) idClientes, (49) descricaoProduto, (50) defeito in file application/controllers/Mine.php; (51) pesquisa, (52) stat...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xx6j-wqj7-mrv3

The HTTP client in the Build tool in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx6j-mphq-3862

Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

2%
Низкий
около 3 лет назад
github логотип
GHSA-xx6h-j6cp-9v8w

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of OCG objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6435.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx6h-c2fx-v78f

Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx6g-jj35-pxjv

Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx6g-8fh5-hq6c

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 2.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-xx6c-8hhq-9qc2

Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx69-w8cq-c673

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
github логотип
GHSA-xx69-qcm3-mp67

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."

38%
Средний
больше 3 лет назад
github логотип
GHSA-xx69-9jc8-q7jv

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xx68-jfcg-xmmf

Commons FileUpload Denial of service vulnerability

93%
Критический
больше 6 лет назад
github логотип
GHSA-xx68-3f2p-v63m

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0113.

CVSS3: 7.5
24%
Средний
больше 3 лет назад
github логотип
GHSA-xx68-37v4-4596

SiYuan has an arbitrary file read via /api/template/render

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx67-mj7c-3wvg

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xx67-2j3v-h76p

PrestaShop PHP Object Injection

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-xx66-m4r3-r5vf

An XML External Entity (XXE) issue exists in Kaseya VSA before 9.5.6.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx66-m35j-5xhv

Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx66-279r-8pgf

Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change application settings or (2) conduct cross-site scripting (XSS) attacks.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу