Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjp4-3fqh-rcxj

больше 4 лет назад

The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.

EPSS: Низкий
github логотип

GHSA-xjp3-rc99-3w6g

больше 4 лет назад

Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.

EPSS: Низкий
github логотип

GHSA-xjp3-r7cm-r64g

больше 4 лет назад

Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjp3-2m5j-pg7v

больше 4 лет назад

PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

EPSS: Низкий
github логотип

GHSA-xjp2-mpr3-rh6p

больше 4 лет назад

FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file.

EPSS: Низкий
github логотип

GHSA-xjp2-j35f-7rj7

больше 4 лет назад

Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have &lt; and &gt; representations.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjp2-83cp-q7hr

больше 4 лет назад

PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.

EPSS: Низкий
github логотип

GHSA-xjmx-fv6v-2m3q

больше 3 лет назад

ChirchCRm 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjmx-cprh-646r

около 4 лет назад

MantisBT unauthorized users able to access private files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjmx-223q-52rw

10 дней назад

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation is a two-step chain: an attacker first saves a crafted guest-author token via the wpma_metabox_authors_list parameter during post creation or editing, then triggers the injection when any admin user loads the post list screen at /wp-admin/edit.php, causing the injected SQL result to be rendered in the Authors column.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjmw-vcw9-m3mx

больше 4 лет назад

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjmw-rm34-58c8

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam Rehub rehub-theme allows Stored XSS.This issue affects Rehub: from n/a through < 19.9.9.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjmw-fgrv-38gm

больше 4 лет назад

Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions prior to 2022/I.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjmv-q8w5-38gf

около 4 лет назад

Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

EPSS: Низкий
github логотип

GHSA-xjmv-cr7x-38wr

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjmv-7wr2-r7c4

больше 4 лет назад

Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjmv-3379-gmjr

около 4 лет назад

Dynamics Finance and Operations Cross-site Scripting Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjmr-q9w7-m3w7

около 4 лет назад

Azure RTOS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42302, CVE-2021-42303.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xjmr-hvq4-xrmr

11 месяцев назад

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure authentication related settings.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjmr-f49m-496p

около 4 лет назад

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0945, CVE-2019-0946.

CVSS3: 7.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjp4-3fqh-rcxj

The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp3-rc99-3w6g

Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp3-r7cm-r64g

Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp3-2m5j-pg7v

PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp2-mpr3-rh6p

FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp2-j35f-7rj7

Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have &lt; and &gt; representations.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp2-83cp-q7hr

PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmx-fv6v-2m3q

ChirchCRm 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xjmx-cprh-646r

MantisBT unauthorized users able to access private files

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjmx-223q-52rw

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation is a two-step chain: an attacker first saves a crafted guest-author token via the wpma_metabox_authors_list parameter during post creation or editing, then triggers the injection when any admin user loads the post list screen at /wp-admin/edit.php, causing the injected SQL result to be rendered in the Authors column.

CVSS3: 6.5
0%
Низкий
10 дней назад
github логотип
GHSA-xjmw-vcw9-m3mx

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmw-rm34-58c8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam Rehub rehub-theme allows Stored XSS.This issue affects Rehub: from n/a through < 19.9.9.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xjmw-fgrv-38gm

Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions prior to 2022/I.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmv-q8w5-38gf

Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjmv-cr7x-38wr

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xjmv-7wr2-r7c4

Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmv-3379-gmjr

Dynamics Finance and Operations Cross-site Scripting Vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjmr-q9w7-m3w7

Azure RTOS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42302, CVE-2021-42303.

CVSS3: 6.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjmr-hvq4-xrmr

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure authentication related settings.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-xjmr-f49m-496p

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0945, CVE-2019-0946.

CVSS3: 7.8
14%
Средний
около 4 лет назад

Уязвимостей на страницу