Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-xw6m-3m5q-mxpm

10 месяцев назад

Liferay Portal's Membership page is vulnerable to XSS through “name“ text field

EPSS: Низкий
github логотип

GHSA-xw6j-vwv7-j25v

около 4 лет назад

Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages.

EPSS: Низкий
github логотип

GHSA-xw6j-mq6v-pmv6

около 3 лет назад

Jenkins SAML Single Sign On(SSO) Plugin Cross-Site Request Forgery vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xw6g-jjvf-wwf9

около 4 лет назад

Invalid file request can crash server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw6g-7x68-mrj2

почти 2 года назад

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xw6c-ffpm-fgcm

5 месяцев назад

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw69-vqf5-9v95

около 4 лет назад

laravel-bjyblog 6.1.1 has XSS via a crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw67-vhv2-m2p4

около 4 лет назад

CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

EPSS: Низкий
github логотип

GHSA-xw67-hqxc-2h5x

около 4 лет назад

Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xw67-cg5f-4m2r

3 месяца назад

AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw66-fwrq-35x6

больше 2 лет назад

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw66-7hgg-w34f

больше 4 лет назад

Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.

EPSS: Низкий
github логотип

GHSA-xw65-r59v-qpqc

около 4 лет назад

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw65-jr46-vvcm

около 4 лет назад

The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xw65-g8p2-hc6q

около 4 лет назад

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

EPSS: Низкий
github логотип

GHSA-xw65-8v8j-f5mq

около 2 лет назад

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing or incorrect nonce validation on the duplicateForm() function. This makes it possible for unauthenticated attackers to duplicate forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw65-87w9-v79c

около 4 лет назад

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw64-mvx9-6946

10 месяцев назад

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xw63-wh8f-q2fm

10 месяцев назад

A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xw63-m43m-c93h

около 4 лет назад

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw6m-3m5q-mxpm

Liferay Portal's Membership page is vulnerable to XSS through “name“ text field

0%
Низкий
10 месяцев назад
github логотип
GHSA-xw6j-vwv7-j25v

Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xw6j-mq6v-pmv6

Jenkins SAML Single Sign On(SSO) Plugin Cross-Site Request Forgery vulnerability

CVSS3: 7.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-xw6g-jjvf-wwf9

Invalid file request can crash server

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw6g-7x68-mrj2

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xw6c-ffpm-fgcm

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xw69-vqf5-9v95

laravel-bjyblog 6.1.1 has XSS via a crafted URL.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw67-vhv2-m2p4

CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xw67-hqxc-2h5x

Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw67-cg5f-4m2r

AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xw66-fwrq-35x6

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw66-7hgg-w34f

Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw65-r59v-qpqc

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xw65-jr46-vvcm

The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xw65-g8p2-hc6q

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xw65-8v8j-f5mq

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing or incorrect nonce validation on the duplicateForm() function. This makes it possible for unauthenticated attackers to duplicate forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xw65-87w9-v79c

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xw64-mvx9-6946

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-xw63-wh8f-q2fm

A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xw63-m43m-c93h

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

CVSS3: 9.8
10%
Низкий
около 4 лет назад

Уязвимостей на страницу