Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg9p-p463-3qjp

около 1 года назад

Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xg9p-hhc9-47q5

больше 4 лет назад

The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_mgmt_addr_tlv_print().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg9p-gw4f-gxg2

больше 4 лет назад

These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xg9p-54cj-5498

больше 4 лет назад

Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg9m-9pg9-92j4

около 4 лет назад

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg9j-97mr-8v79

больше 4 лет назад

Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and unspecified other components. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xg9h-qhxw-v8vr

около 12 часов назад

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg9f-qgvm-j933

9 месяцев назад

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xg9f-gj9x-f37p

больше 4 лет назад

On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. As a result, system memory usage increases over time, which may eventually cause a decrease in performance or a system reboot due to memory exhaustion.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg9f-g7g7-2323

больше 3 лет назад

High resource usage when parsing multipart form data with many fields

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg9f-423r-vcp9

4 месяца назад

The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain MainWP Child Reports activity log entries (including action summaries, user information, IP addresses, and contextual data) via the WordPress Heartbeat API by sending a crafted heartbeat request with the 'wp-mainwp-stream-heartbeat' data key.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xg9c-9wrp-86xv

больше 4 лет назад

Unspecified vulnerability in the SIP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.17), 8.1 before 8.1(2.45), and 8.2 before 8.2(2.13) allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCtd32106.

EPSS: Низкий
github логотип

GHSA-xg99-mpwj-gf2c

больше 4 лет назад

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-xg99-57hh-rfjv

больше 4 лет назад

A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated table variable EFI_BOOT_SERVICES. This can be used by an attacker to overwrite address location of any of the functions (FreePool,LocateHandleBuffer,HandleProtocol) to the address location of arbitrary code controlled by the attacker. On system call to SWSMI handler, the arbitrary code can be triggered to execute.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xg98-5m8g-vc99

больше 4 лет назад

KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg97-vmg6-hhf5

около 4 лет назад

SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg97-v2xv-3fx7

около 3 лет назад

Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xg96-6p7g-7wcf

больше 4 лет назад

Vulnerability in the Oracle Endeca Information Discovery Integrator component of Oracle Fusion Middleware (subcomponent: Integrator ETL). Supported versions that are affected are 3.1.0 and 3.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Endeca Information Discovery Integrator. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Endeca Information Discovery Integrator accessible data as well as unauthorized read access to a subset of Oracle Endeca Information Discovery Integrator accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg95-3326-8h9q

больше 4 лет назад

The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-xg94-r739-55h8

больше 4 лет назад

PmWiki before 2.2.21 has XSS.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg9p-p463-3qjp

Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access

CVSS3: 7.2
1%
Низкий
около 1 года назад
github логотип
GHSA-xg9p-hhc9-47q5

The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_mgmt_addr_tlv_print().

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9p-gw4f-gxg2

These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.

CVSS3: 4.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9p-54cj-5498

Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9m-9pg9-92j4

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xg9j-97mr-8v79

Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and unspecified other components. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9h-qhxw-v8vr

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 7.5
около 12 часов назад
github логотип
GHSA-xg9f-qgvm-j933

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

CVSS3: 5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xg9f-gj9x-f37p

On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. As a result, system memory usage increases over time, which may eventually cause a decrease in performance or a system reboot due to memory exhaustion.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9f-g7g7-2323

High resource usage when parsing multipart form data with many fields

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xg9f-423r-vcp9

The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain MainWP Child Reports activity log entries (including action summaries, user information, IP addresses, and contextual data) via the WordPress Heartbeat API by sending a crafted heartbeat request with the 'wp-mainwp-stream-heartbeat' data key.

CVSS3: 5.3
1%
Низкий
4 месяца назад
github логотип
GHSA-xg9c-9wrp-86xv

Unspecified vulnerability in the SIP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.17), 8.1 before 8.1(2.45), and 8.2 before 8.2(2.13) allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCtd32106.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg99-mpwj-gf2c

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

CVSS3: 8.8
74%
Высокий
больше 4 лет назад
github логотип
GHSA-xg99-57hh-rfjv

A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated table variable EFI_BOOT_SERVICES. This can be used by an attacker to overwrite address location of any of the functions (FreePool,LocateHandleBuffer,HandleProtocol) to the address location of arbitrary code controlled by the attacker. On system call to SWSMI handler, the arbitrary code can be triggered to execute.

CVSS3: 8.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg98-5m8g-vc99

KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg97-vmg6-hhf5

SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

CVSS3: 8.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-xg97-v2xv-3fx7

Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File

CVSS3: 7.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xg96-6p7g-7wcf

Vulnerability in the Oracle Endeca Information Discovery Integrator component of Oracle Fusion Middleware (subcomponent: Integrator ETL). Supported versions that are affected are 3.1.0 and 3.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Endeca Information Discovery Integrator. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Endeca Information Discovery Integrator accessible data as well as unauthorized read access to a subset of Oracle Endeca Information Discovery Integrator accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg95-3326-8h9q

The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."

17%
Средний
больше 4 лет назад
github логотип
GHSA-xg94-r739-55h8

PmWiki before 2.2.21 has XSS.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу