Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xmf4-vfcf-qcjg

около 2 лет назад

A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the function uploadeditor of the file /uploadeditor.html?action=uploadimage of the component Image Upload. The manipulation of the argument upfile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xmf4-pwcw-hwqf

около 1 года назад

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.4. A shortcut may be able to bypass sensitive Shortcuts app settings.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmf4-j3j7-xj7q

больше 4 лет назад

Apache Tomcat DoS Via Requests Including Null Characters

EPSS: Низкий
github логотип

GHSA-xmf4-8m9h-6vvh

больше 1 года назад

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A Shortcut may run with admin privileges without authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmf4-5rj8-j896

больше 4 лет назад

FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.

EPSS: Низкий
github логотип

GHSA-xmf3-54fg-fhvv

около 4 лет назад

Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.

EPSS: Низкий
github логотип

GHSA-xmcx-3xp5-5g3c

больше 4 лет назад

NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmcw-mv9p-7pq2

11 месяцев назад

Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmcw-9j53-54pc

около 4 лет назад

data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, allows remote attackers to modify data via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xmcv-qgcf-rfp5

около 2 месяцев назад

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmcr-x5x3-gjfx

около 4 лет назад

Microweber XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmcr-r54g-jx72

около 2 лет назад

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xmcr-q7rg-rxqc

около 4 лет назад

A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could exploit this vulnerability by sending specific API GET requests to an affected device. A successful exploit could allow the attacker to enumerate users of the CMX system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmcr-cjjw-v9f4

больше 4 лет назад

A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmcr-4fjr-782r

почти 4 года назад

An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmcq-x3wj-p8v6

16 дней назад

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. This issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmcq-hv2q-36wr

почти 4 года назад

MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmcq-9fff-fwm4

около 2 лет назад

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xmcp-gcvr-349m

больше 4 лет назад

Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.

EPSS: Низкий
github логотип

GHSA-xmcp-6wwf-qfhc

больше 4 лет назад

The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmf4-vfcf-qcjg

A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the function uploadeditor of the file /uploadeditor.html?action=uploadimage of the component Image Upload. The manipulation of the argument upfile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xmf4-pwcw-hwqf

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.4. A shortcut may be able to bypass sensitive Shortcuts app settings.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xmf4-j3j7-xj7q

Apache Tomcat DoS Via Requests Including Null Characters

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xmf4-8m9h-6vvh

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A Shortcut may run with admin privileges without authentication.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xmf4-5rj8-j896

FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xmf3-54fg-fhvv

Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmcx-3xp5-5g3c

NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.

CVSS3: 6.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-xmcw-mv9p-7pq2

Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks

CVSS3: 4.3
11 месяцев назад
github логотип
GHSA-xmcw-9j53-54pc

data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, allows remote attackers to modify data via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmcv-qgcf-rfp5

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xmcr-x5x3-gjfx

Microweber XSS Vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmcr-r54g-jx72

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xmcr-q7rg-rxqc

A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could exploit this vulnerability by sending specific API GET requests to an affected device. A successful exploit could allow the attacker to enumerate users of the CMX system.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmcr-cjjw-v9f4

A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmcr-4fjr-782r

An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xmcq-x3wj-p8v6

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. This issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.

CVSS3: 6.5
0%
Низкий
16 дней назад
github логотип
GHSA-xmcq-hv2q-36wr

MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xmcq-9fff-fwm4

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-xmcp-gcvr-349m

Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xmcp-6wwf-qfhc

The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу