Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 844

Количество 290 844

github логотип

GHSA-xvrf-q22w-5f48

больше 3 лет назад

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvrf-gvhf-wxf6

больше 3 лет назад

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

EPSS: Низкий
github логотип

GHSA-xvrf-3569-2x76

больше 1 года назад

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvrc-cwrh-jw5g

8 дней назад

Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection. This issue affects Noisa: from n/a through 2.6.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvrc-2wvh-49vc

почти 2 года назад

Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-xvr9-jr9p-grf3

больше 3 лет назад

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

EPSS: Низкий
github логотип

GHSA-xvr9-h38m-rc5q

больше 3 лет назад

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

EPSS: Низкий
github логотип

GHSA-xvr9-7fjx-5335

больше 3 лет назад

Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xvr9-244h-6gg8

9 месяцев назад

Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvr8-rhg7-pv7w

больше 3 лет назад

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvr7-xmmp-p9vr

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvr7-p2c6-j83w

15 дней назад

swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability

EPSS: Низкий
github логотип

GHSA-xvr7-j937-8w46

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

EPSS: Низкий
github логотип

GHSA-xvr7-55fh-xx8f

больше 3 лет назад

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

EPSS: Низкий
github логотип

GHSA-xvr6-m6gq-m42f

больше 3 лет назад

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvr5-pqwf-8crh

больше 3 лет назад

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvr5-gpgm-56cv

больше 3 лет назад

Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-xvr4-pc95-4727

больше 3 лет назад

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvr4-69m8-v6mv

больше 3 лет назад

Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvr2-gxcm-5972

больше 3 лет назад

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvrf-q22w-5f48

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvrf-gvhf-wxf6

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvrf-3569-2x76

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvrc-cwrh-jw5g

Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection. This issue affects Noisa: from n/a through 2.6.0.

CVSS3: 8.8
0%
Низкий
8 дней назад
github логотип
GHSA-xvrc-2wvh-49vc

Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.

CVSS3: 4.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvr9-jr9p-grf3

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr9-h38m-rc5q

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr9-7fjx-5335

Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr9-244h-6gg8

Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xvr8-rhg7-pv7w

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr7-xmmp-p9vr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xvr7-p2c6-j83w

swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability

15 дней назад
github логотип
GHSA-xvr7-j937-8w46

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr7-55fh-xx8f

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr6-m6gq-m42f

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr5-pqwf-8crh

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr5-gpgm-56cv

Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

26%
Средний
больше 3 лет назад
github логотип
GHSA-xvr4-pc95-4727

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr4-69m8-v6mv

Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr2-gxcm-5972

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу