Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-xx6m-m9v2-vc78

около 4 лет назад

Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx6m-fqm7-6ghv

около 4 лет назад

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx6m-c65f-7c53

больше 3 лет назад

Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSenha, (4) termo, (5) nome, (6) cnpj, (7) ie, (8) cep, (9) logradouro, (10) numero, (11) bairro, (12) cidade, (13) uf, (14) telefone, (15) email, (16) id, (17) app_name, (18) per_page, (19) app_theme, (20) os_notification, (21) email_automatico, (22) control_estoque, (23) notifica_whats, (24) control_baixa, (25) control_editos, (26) control_edit_vendas, (27) control_datatable, (28) pix_key, (29) os_status_list, (30) control_2vias, (31) status, (32) start, (33) end in file application/controllers/Mapos.php; (34) token, (35) senha, (36) email, (37) nomeCliente, (38) documento, (39) telefone, (40) celular, (41) rua, (42) numero, (43) complemento, (44) bairro, (45) cidade, (46) estado, (47) cep, (48) idClientes, (49) descricaoProduto, (50) defeito in file application/controllers/Mine.php; (51) pesquisa, (52) stat...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx6j-wqj7-mrv3

около 4 лет назад

The HTTP client in the Build tool in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx6j-mphq-3862

около 4 лет назад

Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

EPSS: Низкий
github логотип

GHSA-xx6j-2vc6-x568

4 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows PHP Local File Inclusion.This issue affects Amfissa: from n/a through <= 1.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xx6h-j6cp-9v8w

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of OCG objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6435.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx6h-c2fx-v78f

больше 1 года назад

Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx6g-jj35-pxjv

больше 3 лет назад

Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xx6g-8fh5-hq6c

почти 2 года назад

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-xx6g-43w2-9g6g

5 месяцев назад

OliveTin's email argument makes compliance harder, enables log injection

EPSS: Низкий
github логотип

GHSA-xx6c-8hhq-9qc2

около 4 лет назад

Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx69-w8cq-c673

почти 3 года назад

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx69-qcm3-mp67

больше 4 лет назад

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xx69-9jc8-q7jv

больше 1 года назад

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx68-jfcg-xmmf

больше 7 лет назад

Commons FileUpload Denial of service vulnerability

EPSS: Высокий
github логотип

GHSA-xx68-gfhf-pwvh

5 месяцев назад

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xx68-3f2p-v63m

около 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0113.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xx68-37v4-4596

больше 1 года назад

SiYuan has an arbitrary file read via /api/template/render

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx67-mj7c-3wvg

около 4 лет назад

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx6m-m9v2-vc78

Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx6m-fqm7-6ghv

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx6m-c65f-7c53

Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSenha, (4) termo, (5) nome, (6) cnpj, (7) ie, (8) cep, (9) logradouro, (10) numero, (11) bairro, (12) cidade, (13) uf, (14) telefone, (15) email, (16) id, (17) app_name, (18) per_page, (19) app_theme, (20) os_notification, (21) email_automatico, (22) control_estoque, (23) notifica_whats, (24) control_baixa, (25) control_editos, (26) control_edit_vendas, (27) control_datatable, (28) pix_key, (29) os_status_list, (30) control_2vias, (31) status, (32) start, (33) end in file application/controllers/Mapos.php; (34) token, (35) senha, (36) email, (37) nomeCliente, (38) documento, (39) telefone, (40) celular, (41) rua, (42) numero, (43) complemento, (44) bairro, (45) cidade, (46) estado, (47) cep, (48) idClientes, (49) descricaoProduto, (50) defeito in file application/controllers/Mine.php; (51) pesquisa, (52) stat...

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx6j-wqj7-mrv3

The HTTP client in the Build tool in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xx6j-mphq-3862

Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xx6j-2vc6-x568

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows PHP Local File Inclusion.This issue affects Amfissa: from n/a through <= 1.1.

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xx6h-j6cp-9v8w

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of OCG objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6435.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xx6h-c2fx-v78f

Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-xx6g-jj35-pxjv

Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx6g-8fh5-hq6c

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 2.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-xx6g-43w2-9g6g

OliveTin's email argument makes compliance harder, enables log injection

5 месяцев назад
github логотип
GHSA-xx6c-8hhq-9qc2

Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx69-w8cq-c673

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xx69-qcm3-mp67

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."

46%
Средний
больше 4 лет назад
github логотип
GHSA-xx69-9jc8-q7jv

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx68-jfcg-xmmf

Commons FileUpload Denial of service vulnerability

83%
Высокий
больше 7 лет назад
github логотип
GHSA-xx68-gfhf-pwvh

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

CVSS3: 8
1%
Низкий
5 месяцев назад
github логотип
GHSA-xx68-3f2p-v63m

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0113.

CVSS3: 7.5
17%
Средний
около 4 лет назад
github логотип
GHSA-xx68-37v4-4596

SiYuan has an arbitrary file read via /api/template/render

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xx67-mj7c-3wvg

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured file policy for HTTP packets and deliver a malicious payload.

CVSS3: 7.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу