Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjvf-w7h7-789h

3 месяца назад

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization.  *:Canon PIXUS iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (Japan) Canon PIXMA MG2500 Series and iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (US and Europe)

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xjvf-42q4-95c2

около 4 лет назад

TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).

EPSS: Низкий
github логотип

GHSA-xjvc-pw2r-6878

4 месяца назад

Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xjvc-8mfj-g22v

около 3 лет назад

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjvc-8hj8-5w68

около 4 лет назад

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjvc-75fh-37jq

больше 4 лет назад

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/AdminAuthorisationFrame.jsp" has reflected XSS via the ConnPoolName or GroupId parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjv9-mm4p-p398

около 4 лет назад

cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjv7-6w92-42r7

11 месяцев назад

marimo vulnerable to proxy abuse of /mpl/{port}/

EPSS: Низкий
github логотип

GHSA-xjv7-588c-8c3p

около 4 лет назад

A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjv6-qwmr-5pf6

около 1 месяца назад

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class attribute. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xjv5-hx29-64jx

больше 4 лет назад

SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.

EPSS: Низкий
github логотип

GHSA-xjv5-fr35-f76p

4 месяца назад

Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xjv4-rvr6-c234

около 4 лет назад

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8307.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjv4-m8pj-r294

больше 4 лет назад

The mintToken function of a smart contract implementation for CarToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjv4-5hjm-mw83

больше 4 лет назад

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjv3-c433-c8q8

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xjv2-8h6h-m75g

8 месяцев назад

ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjv2-3c45-5x63

12 месяцев назад

A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially result in arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xjrx-qpvm-6f2q

больше 3 лет назад

A vulnerability classified as critical was found in SourceCodester Lost and Found Information System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=items/manage_item of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228979.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xjrx-g2f3-92fc

больше 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjvf-w7h7-789h

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization.  *:Canon PIXUS iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (Japan) Canon PIXMA MG2500 Series and iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (US and Europe)

CVSS3: 5
0%
Низкий
3 месяца назад
github логотип
GHSA-xjvf-42q4-95c2

TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjvc-pw2r-6878

Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-xjvc-8mfj-g22v

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xjvc-8hj8-5w68

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xjvc-75fh-37jq

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/AdminAuthorisationFrame.jsp" has reflected XSS via the ConnPoolName or GroupId parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjv9-mm4p-p398

cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjv7-6w92-42r7

marimo vulnerable to proxy abuse of /mpl/{port}/

11 месяцев назад
github логотип
GHSA-xjv7-588c-8c3p

A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjv6-qwmr-5pf6

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class attribute. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xjv5-hx29-64jx

SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjv5-fr35-f76p

Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code

CVSS3: 4.9
1%
Низкий
4 месяца назад
github логотип
GHSA-xjv4-rvr6-c234

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8307.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjv4-m8pj-r294

The mintToken function of a smart contract implementation for CarToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjv4-5hjm-mw83

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjv3-c433-c8q8

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-xjv2-8h6h-m75g

ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xjv2-3c45-5x63

A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially result in arbitrary code execution.

1%
Низкий
12 месяцев назад
github логотип
GHSA-xjrx-qpvm-6f2q

A vulnerability classified as critical was found in SourceCodester Lost and Found Information System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=items/manage_item of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228979.

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xjrx-g2f3-92fc

Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.

CVSS3: 9.9
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу