Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-xwcp-g9fq-2mmp

около 2 лет назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives specific valid TCP traffic, the pfe crashes and restarts leading to a momentary but complete service outage. This issue affects Junos OS: 21.2 releases from 21.2R3-S5 before 21.2R3-S6. This issue does not affect earlier or later releases.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwcp-9cqm-x4j8

3 месяца назад

Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Contracts accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwcp-6g2q-65gm

около 1 года назад

An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwcm-x564-9rvc

около 3 лет назад

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This OS command injection is triggered through a TCP packet.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwcm-wrx2-hfrr

больше 3 лет назад

A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xwcm-q6m6-465v

почти 4 года назад

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwcm-f545-r47q

около 4 лет назад

When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will cause a division by 0 exception.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwcj-w2w2-2g7c

около 1 года назад

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xwcj-m6m8-mr3g

около 2 лет назад

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xwcj-hwhf-h378

5 месяцев назад

OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs

EPSS: Низкий
github логотип

GHSA-xwcj-h7v7-f6r9

около 4 лет назад

An information disclosure vulnerability exists when "Kernel Remote Procedure Call Provider" driver improperly initializes objects in memory, aka "MSRPC Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwcj-grfm-xm6q

больше 1 года назад

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwcj-5r58-c5mv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

EPSS: Низкий
github логотип

GHSA-xwch-xg3p-x5q5

около 4 лет назад

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

EPSS: Низкий
github логотип

GHSA-xwch-qpr5-vp62

больше 4 лет назад

ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.

EPSS: Низкий
github логотип

GHSA-xwch-gx2x-qj27

около 4 лет назад

Remote Desktop Client Remote Code Execution Vulnerability.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xwch-5xjc-3j47

больше 3 лет назад

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwcg-xmmg-hh8r

около 2 лет назад

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xwcg-44xm-88h2

около 4 лет назад

The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xwcg-2ff3-38xv

12 месяцев назад

Rejected reason: Not used

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwcp-g9fq-2mmp

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives specific valid TCP traffic, the pfe crashes and restarts leading to a momentary but complete service outage. This issue affects Junos OS: 21.2 releases from 21.2R3-S5 before 21.2R3-S6. This issue does not affect earlier or later releases.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwcp-9cqm-x4j8

Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Contracts accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xwcp-6g2q-65gm

An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xwcm-x564-9rvc

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This OS command injection is triggered through a TCP packet.

CVSS3: 8.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-xwcm-wrx2-hfrr

A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwcm-q6m6-465v

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xwcm-f545-r47q

When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will cause a division by 0 exception.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xwcj-w2w2-2g7c

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.

CVSS3: 9.8
17%
Средний
около 1 года назад
github логотип
GHSA-xwcj-m6m8-mr3g

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwcj-hwhf-h378

OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs

5 месяцев назад
github логотип
GHSA-xwcj-h7v7-f6r9

An information disclosure vulnerability exists when "Kernel Remote Procedure Call Provider" driver improperly initializes objects in memory, aka "MSRPC Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xwcj-grfm-xm6q

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwcj-5r58-c5mv

Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xwch-xg3p-x5q5

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xwch-qpr5-vp62

ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwch-gx2x-qj27

Remote Desktop Client Remote Code Execution Vulnerability.

CVSS3: 8.8
38%
Средний
около 4 лет назад
github логотип
GHSA-xwch-5xjc-3j47

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwcg-xmmg-hh8r

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

CVSS3: 4.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwcg-44xm-88h2

The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.

CVSS3: 4.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-xwcg-2ff3-38xv

Rejected reason: Not used

12 месяцев назад

Уязвимостей на страницу