Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-xw9h-mxp6-gf7c

почти 2 года назад

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xw9h-8vfr-ppf5

около 4 лет назад

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw9g-79q2-3vjw

около 4 лет назад

Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw9f-xv55-jhcr

больше 4 лет назад

Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

EPSS: Низкий
github логотип

GHSA-xw9f-vg47-m9mf

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on devlink_alloc() failure devlink_alloc() may return NULL on allocation failure, but prestera_devlink_alloc() unconditionally calls devlink_priv() on the returned pointer. This leads to a NULL pointer dereference if devlink allocation fails. Add a check for a NULL devlink pointer and return NULL early to avoid the crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw9f-r7rv-2cfw

около 4 лет назад

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.

EPSS: Низкий
github логотип

GHSA-xw9f-jjf6-qcrc

около 4 лет назад

Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.

EPSS: Низкий
github логотип

GHSA-xw9f-hwxg-fq6r

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw9f-44rx-4f36

6 месяцев назад

The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.5.2. This is due to missing capability checks on the `image_replacement_from_url` function that is hooked to the `eri_from_url` AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to replace arbitrary image attachments on the site with images from external URLs, potentially enabling site defacement, phishing attacks, or content manipulation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw9c-r5pv-7f67

больше 4 лет назад

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

EPSS: Средний
github логотип

GHSA-xw9c-qm7m-c9wc

около 4 лет назад

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

EPSS: Низкий
github логотип

GHSA-xw9c-j6h9-9vjc

больше 4 лет назад

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

EPSS: Низкий
github логотип

GHSA-xw9c-79j7-p3p6

около 4 лет назад

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw9c-4vrc-64gr

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xw99-vmpf-qpg4

около 4 лет назад

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.

EPSS: Средний
github логотип

GHSA-xw99-jr69-5j43

около 4 лет назад

Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xw99-fqpg-v257

около 2 лет назад

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw98-vm6c-57r4

больше 4 лет назад

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

EPSS: Низкий
github логотип

GHSA-xw98-6cfw-p3wh

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.

EPSS: Низкий
github логотип

GHSA-xw98-5q62-jx94

5 месяцев назад

Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw9h-mxp6-gf7c

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xw9h-8vfr-ppf5

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw9g-79q2-3vjw

Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw9f-xv55-jhcr

Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xw9f-vg47-m9mf

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on devlink_alloc() failure devlink_alloc() may return NULL on allocation failure, but prestera_devlink_alloc() unconditionally calls devlink_priv() on the returned pointer. This leads to a NULL pointer dereference if devlink allocation fails. Add a check for a NULL devlink pointer and return NULL early to avoid the crash.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xw9f-r7rv-2cfw

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xw9f-jjf6-qcrc

Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xw9f-hwxg-fq6r

Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xw9f-44rx-4f36

The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.5.2. This is due to missing capability checks on the `image_replacement_from_url` function that is hooked to the `eri_from_url` AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to replace arbitrary image attachments on the site with images from external URLs, potentially enabling site defacement, phishing attacks, or content manipulation.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xw9c-r5pv-7f67

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

54%
Средний
больше 4 лет назад
github логотип
GHSA-xw9c-qm7m-c9wc

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xw9c-j6h9-9vjc

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xw9c-79j7-p3p6

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw9c-4vrc-64gr

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-xw99-vmpf-qpg4

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.

10%
Средний
около 4 лет назад
github логотип
GHSA-xw99-jr69-5j43

Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xw99-fqpg-v257

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xw98-vm6c-57r4

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw98-6cfw-p3wh

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xw98-5q62-jx94

Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)

CVSS3: 7.5
1%
Низкий
5 месяцев назад

Уязвимостей на страницу