Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xgh5-w62m-8mpr

5 месяцев назад

CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xgh5-gwq5-rpx8

больше 3 лет назад

Arbitrary javascript injection in Apache Jena

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xgh5-f3fw-4wgg

около 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xgh5-7gp7-7mg3

около 1 года назад

Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of the HTTP Content-Length header. The issue results from the lack of proper validation of user-supplied data, which can result in memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26300.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgh4-wmvj-9mvr

около 1 года назад

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgh4-3f7c-mx5r

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrary web script or HTML via Javascript events in the username parameter, a different vulnerability than CVE-2005-4876.

EPSS: Низкий
github логотип

GHSA-xgh3-px9j-7w6v

больше 4 лет назад

Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of JavaScript events and appropriate manipulation."

EPSS: Низкий
github логотип

GHSA-xgh3-j7cj-8mp6

больше 3 лет назад

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. This issue affects the function save_brand of the file /classes/Master.php?f=save_brand. The manipulation of the argument name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225533 was assigned to this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xgh3-993q-r2x8

около 1 года назад

A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xgh3-3p7j-83p8

больше 4 лет назад

Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgh2-wjm9-43xj

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xggx-wg32-cjw8

больше 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise HRMS eProfile Manager component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.8 SP1, 8.9 Bundle 19, and 9.0 Bundle 9 allows remote authenticated users to affect confidentiality via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xggx-rf7g-q3f6

больше 4 лет назад

** DISPUTED ** Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vulnerability. The vendor plans to fix it at a future time.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xggx-fx6w-v7ch

около 7 лет назад

Improper Neutralization of Wildcards or Matching Symbols

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xggx-cjmv-qpq3

около 4 лет назад

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker could exploit this vulnerability by convincing a targeted user who is currently authenticated to Cisco Webex Software to follow a link designed to pass malicious input to the Cisco Webex Software application authorization interface. A successful exploit could allow the attacker to cause Cisco Webex Software to authorize an application on the user's behalf without the express consent of the user, possibly allowing external applications to read data from that user's profile.

EPSS: Низкий
github логотип

GHSA-xggx-9p6w-334x

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xggx-88w4-2942

около 2 лет назад

File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xggx-47c9-6v7m

больше 3 лет назад

A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown part of the file wan.asp of the component Web Management Interface. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220017 was assigned to this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xggw-g9pm-9qhh

5 месяцев назад

AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xggr-8f99-gpgj

3 месяца назад

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory traversal sequences in the GET action parameter to load files via CSRF, bypassing authentication on vulnerable AJAX actions.

CVSS3: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgh5-w62m-8mpr

CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS

CVSS3: 9.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-xgh5-gwq5-rpx8

Arbitrary javascript injection in Apache Jena

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xgh5-f3fw-4wgg

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xgh5-7gp7-7mg3

Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of the HTTP Content-Length header. The issue results from the lack of proper validation of user-supplied data, which can result in memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26300.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xgh4-wmvj-9mvr

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xgh4-3f7c-mx5r

Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrary web script or HTML via Javascript events in the username parameter, a different vulnerability than CVE-2005-4876.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgh3-px9j-7w6v

Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filenames via vectors involving "detection of JavaScript events and appropriate manipulation."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgh3-j7cj-8mp6

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. This issue affects the function save_brand of the file /classes/Master.php?f=save_brand. The manipulation of the argument name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225533 was assigned to this vulnerability.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xgh3-993q-r2x8

A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."

CVSS3: 2.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xgh3-3p7j-83p8

Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgh2-wjm9-43xj

Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xggx-wg32-cjw8

Unspecified vulnerability in the PeopleSoft Enterprise HRMS eProfile Manager component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.8 SP1, 8.9 Bundle 19, and 9.0 Bundle 9 allows remote authenticated users to affect confidentiality via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xggx-rf7g-q3f6

** DISPUTED ** Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vulnerability. The vendor plans to fix it at a future time.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xggx-fx6w-v7ch

Improper Neutralization of Wildcards or Matching Symbols

CVSS3: 5.3
1%
Низкий
около 7 лет назад
github логотип
GHSA-xggx-cjmv-qpq3

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker could exploit this vulnerability by convincing a targeted user who is currently authenticated to Cisco Webex Software to follow a link designed to pass malicious input to the Cisco Webex Software application authorization interface. A successful exploit could allow the attacker to cause Cisco Webex Software to authorize an application on the user's behalf without the express consent of the user, possibly allowing external applications to read data from that user's profile.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xggx-9p6w-334x

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-xggx-88w4-2942

File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xggx-47c9-6v7m

A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. This affects an unknown part of the file wan.asp of the component Web Management Interface. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220017 was assigned to this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xggw-g9pm-9qhh

AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin

CVSS3: 8.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-xggr-8f99-gpgj

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory traversal sequences in the GET action parameter to load files via CSRF, bypassing authentication on vulnerable AJAX actions.

CVSS3: 4
1%
Низкий
3 месяца назад

Уязвимостей на страницу