Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-xxqr-hj46-74ww

около 4 лет назад

SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

EPSS: Низкий
github логотип

GHSA-xxqr-h45r-xgm7

больше 4 лет назад

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

EPSS: Средний
github логотип

GHSA-xxqq-qccx-3r89

около 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxqq-pg5g-cgqm

8 месяцев назад

Rejected reason: Voluntarily withdrawn

EPSS: Низкий
github логотип

GHSA-xxqq-477x-j22x

больше 1 года назад

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested expressions.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xxqp-r9x6-3h94

около 4 лет назад

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxqp-4rfr-9px7

около 1 года назад

A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument how leads to improper validation of array index.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xxqm-xpq7-prvx

около 4 лет назад

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0778, and CVE-2018-0781.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-xxqm-cf86-wmxp

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.

EPSS: Низкий
github логотип

GHSA-xxqj-x2pv-x5jj

около 2 лет назад

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxqj-m8p7-rjq7

около 4 лет назад

The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxqj-98q4-mp83

около 4 лет назад

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxqh-r526-fmp5

около 4 лет назад

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xxqh-mfjm-7mv9

3 месяца назад

Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xxqh-84mj-whcj

около 4 лет назад

The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

EPSS: Средний
github логотип

GHSA-xxqh-6qhx-prvr

около 4 лет назад

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document.

EPSS: Низкий
github логотип

GHSA-xxqh-2vwh-rx4f

около 4 лет назад

In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.

EPSS: Низкий
github логотип

GHSA-xxqg-cq6p-jpqq

около 4 лет назад

Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into AES to encrypt a username and base64 encode it to a client-side cookie for persistent session authentication. By knowing the key and algorithm, an attacker can select any username, encrypt it, base64 encode it, and save it in their browser with the correct JICSLoginCookie cookie format to impersonate any real user in the JICS database without the need for authenticating (or verifying with MFA if implemented).

EPSS: Низкий
github логотип

GHSA-xxqg-9cxv-cq9v

14 дней назад

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xxqg-57h9-26v8

больше 1 года назад

A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxqr-hj46-74ww

SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxqr-h45r-xgm7

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

53%
Средний
больше 4 лет назад
github логотип
GHSA-xxqq-qccx-3r89

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xxqq-pg5g-cgqm

Rejected reason: Voluntarily withdrawn

8 месяцев назад
github логотип
GHSA-xxqq-477x-j22x

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested expressions.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxqp-r9x6-3h94

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxqp-4rfr-9px7

A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument how leads to improper validation of array index.

CVSS3: 8
1%
Низкий
около 1 года назад
github логотип
GHSA-xxqm-xpq7-prvx

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0778, and CVE-2018-0781.

CVSS3: 7.5
78%
Высокий
около 4 лет назад
github логотип
GHSA-xxqm-cf86-wmxp

Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xxqj-x2pv-x5jj

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xxqj-m8p7-rjq7

The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xxqj-98q4-mp83

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xxqh-r526-fmp5

The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

CVSS3: 6.5
13%
Средний
около 4 лет назад
github логотип
GHSA-xxqh-mfjm-7mv9

Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

CVSS3: 5.8
1%
Низкий
3 месяца назад
github логотип
GHSA-xxqh-84mj-whcj

The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.

50%
Средний
около 4 лет назад
github логотип
GHSA-xxqh-6qhx-prvr

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xxqh-2vwh-rx4f

In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxqg-cq6p-jpqq

Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into AES to encrypt a username and base64 encode it to a client-side cookie for persistent session authentication. By knowing the key and algorithm, an attacker can select any username, encrypt it, base64 encode it, and save it in their browser with the correct JICSLoginCookie cookie format to impersonate any real user in the JICS database without the need for authenticating (or verifying with MFA if implemented).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxqg-9cxv-cq9v

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

CVSS3: 9.9
0%
Низкий
14 дней назад
github логотип
GHSA-xxqg-57h9-26v8

A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу