Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhch-j6v3-w4f3

5 месяцев назад

An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhch-7j88-pg68

больше 2 лет назад

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhch-6vq5-g6rw

2 месяца назад

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhcg-p7cj-pf6v

больше 4 лет назад

The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.

EPSS: Низкий
github логотип

GHSA-xhcg-fx4c-m8q6

больше 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhcg-2f6v-67xr

больше 4 лет назад

Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xhcf-wm8x-cp97

больше 4 лет назад

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhcf-h698-rm2h

около 3 лет назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhcf-gx4j-5q75

больше 4 лет назад

On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xhc9-5794-7px7

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection.This issue affects B2B Login Panel: before 15.01.2025.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhc9-2rpq-wh58

4 месяца назад

Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xhc8-4cg9-pfch

около 2 лет назад

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhc7-qp6w-xmwm

около 4 лет назад

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-xhc7-32vm-6c85

больше 3 лет назад

Information disclosure in modem due to improper check of IP type while processing DNS server query

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhc6-mmf6-vvgh

11 месяцев назад

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This manipulation of the argument nm_tipo/descricao causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xhc5-mpp2-4rmp

больше 4 лет назад

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

EPSS: Низкий
github логотип

GHSA-xhc5-97cf-65v8

больше 4 лет назад

Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xhc5-7m84-pqq9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4055.

EPSS: Низкий
github логотип

GHSA-xhc4-5vj2-qmpr

больше 4 лет назад

BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhc3-w35m-fp4q

около 1 месяца назад

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhch-j6v3-w4f3

An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xhch-7j88-pg68

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xhch-6vq5-g6rw

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xhcg-p7cj-pf6v

The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xhcg-fx4c-m8q6

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xhcg-2f6v-67xr

Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation

CVSS3: 8.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhcf-wm8x-cp97

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhcf-h698-rm2h

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhcf-gx4j-5q75

On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xhc9-5794-7px7

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection.This issue affects B2B Login Panel: before 15.01.2025.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhc9-2rpq-wh58

Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xhc8-4cg9-pfch

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xhc7-qp6w-xmwm

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

CVSS3: 6.1
14%
Средний
около 4 лет назад
github логотип
GHSA-xhc7-32vm-6c85

Information disclosure in modem due to improper check of IP type while processing DNS server query

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xhc6-mmf6-vvgh

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This manipulation of the argument nm_tipo/descricao causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 3.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xhc5-mpp2-4rmp

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhc5-97cf-65v8

Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xhc5-7m84-pqq9

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4055.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhc4-5vj2-qmpr

BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhc3-w35m-fp4q

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу