Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-xfxf-qw26-hr33

больше 5 лет назад

Arbitrary command execution in roar-pidusage

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xfxf-hvqm-h74g

28 дней назад

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xfxc-c47w-9432

около 4 лет назад

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xfxc-48qf-j4g6

больше 2 лет назад

Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xfx9-x566-2hwr

7 месяцев назад

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

CVSS3: 8.4
EPSS: Средний
github логотип

GHSA-xfx9-q5gv-952r

больше 1 года назад

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xfx9-7343-fmvv

больше 3 лет назад

Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xfx9-5x3p-32f4

11 месяцев назад

A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xfx8-39w8-9g2h

около 1 месяца назад

The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned. The nonce required to authenticate the cancellation request is printed on the Appointments admin page, which is itself gated only by the edit_posts capability that Authors possess, making the nonce readily accessible to low-privileged users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xfx8-2v9j-75g4

больше 3 лет назад

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xfx6-r52c-8v32

около 2 лет назад

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xfx6-p444-pvw8

больше 4 лет назад

Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

EPSS: Низкий
github логотип

GHSA-xfx6-fh5x-72pf

около 4 лет назад

Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xfx5-j9h7-r9mh

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xfx5-f3j8-fmxq

больше 4 лет назад

Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.

EPSS: Низкий
github логотип

GHSA-xfx5-6q2x-cp8j

больше 4 лет назад

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xfx4-m9c7-7v6v

больше 4 лет назад

Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xfx4-jrpq-pvcp

около 2 месяцев назад

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xfx4-9q4j-5v3q

почти 2 года назад

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xfx3-cr74-x3cv

около 2 лет назад

Exposure of secrets through system log in Jenkins Structs Plugin

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xfxf-qw26-hr33

Arbitrary command execution in roar-pidusage

CVSS3: 5.6
1%
Низкий
больше 5 лет назад
github логотип
GHSA-xfxf-hvqm-h74g

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

CVSS3: 4.9
0%
Низкий
28 дней назад
github логотип
GHSA-xfxc-c47w-9432

An improper access control flaw in GitLab CE/EE since version 13.9 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xfxc-48qf-j4g6

Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xfx9-x566-2hwr

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

CVSS3: 8.4
26%
Средний
7 месяцев назад
github логотип
GHSA-xfx9-q5gv-952r

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xfx9-7343-fmvv

Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xfx9-5x3p-32f4

A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-xfx8-39w8-9g2h

The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned. The nonce required to authenticate the cancellation request is printed on the Appointments admin page, which is itself gated only by the edit_posts capability that Authors possess, making the nonce readily accessible to low-privileged users.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xfx8-2v9j-75g4

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xfx6-r52c-8v32

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xfx6-p444-pvw8

Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xfx6-fh5x-72pf

Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xfx5-j9h7-r9mh

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xfx5-f3j8-fmxq

Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xfx5-6q2x-cp8j

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xfx4-m9c7-7v6v

Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xfx4-jrpq-pvcp

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xfx4-9q4j-5v3q

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-xfx3-cr74-x3cv

Exposure of secrets through system log in Jenkins Structs Plugin

CVSS3: 3.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу