Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-xxq8-5mc3-63xg

около 3 лет назад

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxq8-555q-w627

почти 4 года назад

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxq7-hjr2-f27f

больше 3 лет назад

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-xj37-9fx7

больше 3 лет назад

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-c27j-953j

около 2 лет назад

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxq4-jv5p-cfwc

больше 3 лет назад

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xxq4-9c68-6533

больше 1 года назад

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxq4-3742-3h28

почти 4 года назад

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxq3-gj76-wh9v

почти 4 года назад

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-xxq3-764r-q6rm

больше 3 лет назад

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

EPSS: Низкий
github логотип

GHSA-xxq2-fm9w-xjv8

28 дней назад

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xxq2-74hw-vg6m

больше 2 лет назад

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxq2-62cv-vmcw

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxpx-w698-q23j

больше 3 лет назад

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxpx-f58m-683f

10 месяцев назад

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxpv-mm3c-74x5

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.

EPSS: Низкий
github логотип

GHSA-xxpv-gwrv-58xv

почти 3 года назад

Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxpv-3q6j-c873

почти 2 года назад

The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xxpr-8m4r-4fgq

больше 3 лет назад

Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-xxpq-jv5h-r9hg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxq8-5mc3-63xg

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxq8-555q-w627

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxq7-hjr2-f27f

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq5-xj37-9fx7

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq5-c27j-953j

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xxq4-jv5p-cfwc

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq4-9c68-6533

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxq4-3742-3h28

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxq3-gj76-wh9v

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xxq3-764r-q6rm

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq2-fm9w-xjv8

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVSS3: 4.9
0%
Низкий
28 дней назад
github логотип
GHSA-xxq2-74hw-vg6m

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxq2-62cv-vmcw

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxpx-w698-q23j

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxpx-f58m-683f

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxpv-mm3c-74x5

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxpv-gwrv-58xv

Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxpv-3q6j-c873

The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
3%
Низкий
почти 2 года назад
github логотип
GHSA-xxpr-8m4r-4fgq

Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265.

CVSS3: 7.8
29%
Средний
больше 3 лет назад
github логотип
GHSA-xxpq-jv5h-r9hg

Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу