Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-43m8-wxpm-8hm7

почти 2 года назад

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-43m8-rg5f-9pr8

больше 3 лет назад

Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43m8-5qf6-mvf6

почти 4 года назад

Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.

EPSS: Низкий
github логотип

GHSA-43m7-cr4f-cpcc

около 4 лет назад

Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Snapshot Integration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS SA Integration Pack. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS SA Integration Pack accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-43m6-wvc8-2m7j

больше 3 лет назад

Mattermost Server's Session ID and Session Token are potentially compromised

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43m6-mm77-vrc8

больше 3 лет назад

Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-43m5-x878-2c62

больше 3 лет назад

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

EPSS: Низкий
github логотип

GHSA-43m5-c88r-cjvv

больше 5 лет назад

XSS due to lack of CSRF validation for replying/publishing

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43m3-7v7r-4vh7

около 4 лет назад

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

EPSS: Низкий
github логотип

GHSA-43m3-5mhm-q5fc

больше 3 лет назад

This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory.

EPSS: Низкий
github логотип

GHSA-43m3-2gf4-gx9r

больше 3 лет назад

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43m2-c25v-9rrv

4 месяца назад

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actions on the site like creating new posts and injecting XSS payloads.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43m2-5vcp-3fpm

6 месяцев назад

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-43jx-m6w2-jq4p

10 месяцев назад

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-43jv-rf9m-vfp4

почти 3 года назад

Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43jv-mfhv-x3hx

около 3 лет назад

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43jr-gj2x-p9c9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

EPSS: Низкий
github логотип

GHSA-43jr-65gg-fq95

больше 3 лет назад

Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific embedded resource file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43jq-vh77-69vm

больше 3 лет назад

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-43jp-qxr7-8hf7

больше 3 лет назад

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43m8-wxpm-8hm7

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

CVSS3: 5.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-43m8-rg5f-9pr8

Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43m8-5qf6-mvf6

Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.

0%
Низкий
почти 4 года назад
github логотип
GHSA-43m7-cr4f-cpcc

Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Snapshot Integration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS SA Integration Pack. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS SA Integration Pack accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

2%
Низкий
около 4 лет назад
github логотип
GHSA-43m6-wvc8-2m7j

Mattermost Server's Session ID and Session Token are potentially compromised

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43m6-mm77-vrc8

Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43m5-x878-2c62

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43m5-c88r-cjvv

XSS due to lack of CSRF validation for replying/publishing

CVSS3: 6.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-43m3-7v7r-4vh7

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

0%
Низкий
около 4 лет назад
github логотип
GHSA-43m3-5mhm-q5fc

This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-43m3-2gf4-gx9r

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43m2-c25v-9rrv

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key and subsequently use that to perform actions on the site like creating new posts and injecting XSS payloads.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-43m2-5vcp-3fpm

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-43jx-m6w2-jq4p

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

CVSS3: 6.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-43jv-rf9m-vfp4

Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-43jv-mfhv-x3hx

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.

CVSS3: 9.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-43jr-gj2x-p9c9

Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43jr-65gg-fq95

Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific embedded resource file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43jq-vh77-69vm

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43jp-qxr7-8hf7

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу