Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 291 062

Количество 291 062

github логотип

GHSA-xvq8-f2vm-qf3p

28 дней назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xvq8-82jr-qr82

больше 3 лет назад

The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvq8-2qwv-cr72

больше 3 лет назад

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

EPSS: Низкий
github логотип

GHSA-xvq7-6cjq-gwh7

больше 3 лет назад

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

EPSS: Низкий
github логотип

GHSA-xvq6-mh4q-2wm8

больше 3 лет назад

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

EPSS: Низкий
github логотип

GHSA-xvq6-h898-wcj8

почти 2 года назад

Mattermost denial of service vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvq5-pp86-qj79

больше 3 лет назад

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xvq3-j3j3-hfjp

больше 3 лет назад

SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Низкий
github логотип

GHSA-xvpx-6hh8-7h72

больше 3 лет назад

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.

EPSS: Средний
github логотип

GHSA-xvpw-j9f9-fw7v

больше 3 лет назад

Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.

EPSS: Низкий
github логотип

GHSA-xvpr-22g7-3fc2

больше 3 лет назад

The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.

EPSS: Низкий
github логотип

GHSA-xvpq-v2cq-9v92

больше 3 лет назад

Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.

EPSS: Низкий
github логотип

GHSA-xvpp-m96v-c2pr

больше 3 лет назад

D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.

EPSS: Средний
github логотип

GHSA-xvpp-hhff-gp7v

больше 2 лет назад

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xvpp-959v-c63p

больше 3 лет назад

Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

EPSS: Низкий
github логотип

GHSA-xvpp-5hc3-fp4m

около 2 лет назад

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvpm-v9x9-vg99

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

EPSS: Низкий
github логотип

GHSA-xvpm-8w5j-p5mw

больше 3 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvpj-rpwv-6v3h

6 месяцев назад

Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xvph-4wvx-cp6q

больше 3 лет назад

Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvq8-f2vm-qf3p

Rejected reason: Not used

28 дней назад
github логотип
GHSA-xvq8-82jr-qr82

The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvq8-2qwv-cr72

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-xvq7-6cjq-gwh7

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvq6-mh4q-2wm8

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvq6-h898-wcj8

Mattermost denial of service vulnerability

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvq5-pp86-qj79

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvq3-j3j3-hfjp

SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpx-6hh8-7h72

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.

31%
Средний
больше 3 лет назад
github логотип
GHSA-xvpw-j9f9-fw7v

Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpr-22g7-3fc2

The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpq-v2cq-9v92

Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpp-m96v-c2pr

D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.

21%
Средний
больше 3 лет назад
github логотип
GHSA-xvpp-hhff-gp7v

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvpp-959v-c63p

Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpp-5hc3-fp4m

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvpm-v9x9-vg99

Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpm-8w5j-p5mw

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xvpj-rpwv-6v3h

Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1.

CVSS3: 7.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvph-4wvx-cp6q

Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2

CVSS3: 5.3
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу