Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh64-7799-q5r8

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Microcart 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or (2) query string to _admin/index.php or (3) first_name, (4) last_name, (5) cc, (6) exp, (7) cvv, (8) address1, (9) address2, (10) city, (11) state, (12) zip, (13) phone, or (14) email parameter to checkout.php, which is not properly handled in an error message.

EPSS: Низкий
github логотип

GHSA-xh64-3cxr-cqq7

больше 4 лет назад

SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

EPSS: Низкий
github логотип

GHSA-xh64-2p6v-xmjr

больше 4 лет назад

InfoSphere Guardium aix_ktap module: DoS

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh63-pmfx-3pr8

около 4 лет назад

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xh63-f847-m5r7

больше 3 лет назад

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh63-cv27-942f

4 месяца назад

Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser.

EPSS: Низкий
github логотип

GHSA-xh62-mxvq-v84j

около 4 лет назад

The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This version of QCMAP is used in many kinds of networking devices, primarily mobile hotspots and LTE routers.

EPSS: Низкий
github логотип

GHSA-xh62-2frp-2wpv

больше 1 года назад

The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xh5x-q49r-r9w4

около 4 лет назад

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh5x-j8jf-pcpx

больше 4 лет назад

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-xh5x-gc2m-92g9

больше 3 лет назад

Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh5x-756j-vhq8

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xh5w-g8gq-r3v9

9 месяцев назад

Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xh5w-7cjj-c462

около 4 лет назад

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xh5v-qfjh-27v2

около 3 лет назад

A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/ticket/create of the component Support Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. VDB-235150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xh5r-qv8m-7hqj

больше 4 лет назад

The mintToken function of a smart contract implementation for Good Time Coin (GTY), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh5r-95xw-9rq3

8 месяцев назад

In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh5q-pch5-g3xq

больше 1 года назад

A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh5p-rm5r-7f82

больше 1 года назад

A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to cause unexpected system termination.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh5m-rf6f-g69m

больше 4 лет назад

Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh64-7799-q5r8

Multiple cross-site scripting (XSS) vulnerabilities in Microcart 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or (2) query string to _admin/index.php or (3) first_name, (4) last_name, (5) cc, (6) exp, (7) cvv, (8) address1, (9) address2, (10) city, (11) state, (12) zip, (13) phone, or (14) email parameter to checkout.php, which is not properly handled in an error message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh64-3cxr-cqq7

SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh64-2p6v-xmjr

InfoSphere Guardium aix_ktap module: DoS

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh63-pmfx-3pr8

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

CVSS3: 7.6
2%
Низкий
около 4 лет назад
github логотип
GHSA-xh63-f847-m5r7

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xh63-cv27-942f

Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser.

0%
Низкий
4 месяца назад
github логотип
GHSA-xh62-mxvq-v84j

The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This version of QCMAP is used in many kinds of networking devices, primarily mobile hotspots and LTE routers.

10%
Низкий
около 4 лет назад
github логотип
GHSA-xh62-2frp-2wpv

The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh5x-q49r-r9w4

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVSS3: 7.5
5%
Низкий
около 4 лет назад
github логотип
GHSA-xh5x-j8jf-pcpx

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat

9%
Низкий
больше 4 лет назад
github логотип
GHSA-xh5x-gc2m-92g9

Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xh5x-756j-vhq8

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xh5w-g8gq-r3v9

Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices

CVSS3: 8.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-xh5w-7cjj-c462

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause arbitrary code execution.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xh5v-qfjh-27v2

A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/ticket/create of the component Support Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. VDB-235150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xh5r-qv8m-7hqj

The mintToken function of a smart contract implementation for Good Time Coin (GTY), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh5r-95xw-9rq3

In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xh5q-pch5-g3xq

A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVSS3: 7.5
9%
Низкий
больше 1 года назад
github логотип
GHSA-xh5p-rm5r-7f82

A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to cause unexpected system termination.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh5m-rf6f-g69m

Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу