Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 343 364

Количество 343 364

github логотип

GHSA-xwxx-whw4-f73w

6 месяцев назад

Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.9.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwxx-v4g2-q5p4

больше 1 года назад

The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xwxx-8397-833r

около 4 лет назад

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xwxw-pwqh-w83w

7 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwxw-ph5c-h3rg

около 4 лет назад

Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Management.

EPSS: Низкий
github логотип

GHSA-xwxw-c548-rmpj

3 месяца назад

A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwxw-9gfj-g2c9

больше 1 года назад

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xwxv-x6g8-hh45

почти 3 года назад

An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xwxr-6p65-6chj

около 4 лет назад

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A malicious HTML document may be able to render iframes with sensitive user information.

EPSS: Низкий
github логотип

GHSA-xwxp-rxpg-mg4w

около 4 лет назад

SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

EPSS: Низкий
github логотип

GHSA-xwxp-fcpw-w82j

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc() The call to lpfc_sli4_resume_rpi() in lpfc_rcv_padisc() may return an unsuccessful status. In such cases, the elsiocb is not issued, the completion is not called, and thus the elsiocb resource is leaked. Check return value after calling lpfc_sli4_resume_rpi() and conditionally release the elsiocb resource.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwxp-5m2x-m8vj

больше 4 лет назад

The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.

EPSS: Низкий
github логотип

GHSA-xwxp-2934-fp75

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

EPSS: Средний
github логотип

GHSA-xwxm-hg2j-hpjq

почти 4 года назад

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xwxm-298x-phpj

9 месяцев назад

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwxj-5cm4-pc27

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Filtr8 Easy Magazine allows DOM-Based XSS. This issue affects Easy Magazine: from n/a through 2.1.13.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwxh-r5pc-7pp9

около 4 лет назад

Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska video (aka MKV) file.

EPSS: Низкий
github логотип

GHSA-xwxh-84mx-hgrr

около 1 месяца назад

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xwxg-r73m-j39w

около 4 лет назад

The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwxf-pqj7-vq4g

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwxx-whw4-f73w

Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.9.6.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xwxx-v4g2-q5p4

The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwxx-8397-833r

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xwxw-pwqh-w83w

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xwxw-ph5c-h3rg

Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Management.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xwxw-c548-rmpj

A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xwxw-9gfj-g2c9

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwxv-x6g8-hh45

An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMs

CVSS3: 8.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xwxr-6p65-6chj

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A malicious HTML document may be able to render iframes with sensitive user information.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xwxp-rxpg-mg4w

SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xwxp-fcpw-w82j

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc() The call to lpfc_sli4_resume_rpi() in lpfc_rcv_padisc() may return an unsuccessful status. In such cases, the elsiocb is not issued, the completion is not called, and thus the elsiocb resource is leaked. Check return value after calling lpfc_sli4_resume_rpi() and conditionally release the elsiocb resource.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwxp-5m2x-m8vj

The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xwxp-2934-fp75

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

12%
Средний
больше 4 лет назад
github логотип
GHSA-xwxm-hg2j-hpjq

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

CVSS3: 7.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwxm-298x-phpj

The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s grammar allows a 'PROCEDURE ANALYSE' clause immediately after a LIMIT clause. Unauthenticated attackers controlling 'row_count' can append a stored‐procedure call, enabling error‐based or time‐based blind SQL injection that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xwxj-5cm4-pc27

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Filtr8 Easy Magazine allows DOM-Based XSS. This issue affects Easy Magazine: from n/a through 2.1.13.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwxh-r5pc-7pp9

Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska video (aka MKV) file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xwxh-84mx-hgrr

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

CVSS3: 8.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xwxg-r73m-j39w

The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xwxf-pqj7-vq4g

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 1 года назад

Уязвимостей на страницу