Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 231

Количество 306 231

github логотип

GHSA-3h6m-3jhx-cfg9

больше 3 лет назад

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions.

EPSS: Низкий
github логотип

GHSA-3h6h-wq56-3w89

около 3 лет назад

The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h6h-v2q2-7mx9

больше 3 лет назад

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h6h-8756-mj4f

больше 3 лет назад

A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h6g-vwfm-p62q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

EPSS: Низкий
github логотип

GHSA-3h6g-r953-7g4p

больше 3 лет назад

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3h6f-g5f3-gc4w

больше 2 лет назад

Access Control Bypass in Spring Security

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-3h6c-fr7r-7jmg

почти 2 года назад

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3h6c-c475-jm7v

больше 1 года назад

Arbitrary Code Execution in Gitea

CVSS3: 7.2
EPSS: Критический
github логотип

GHSA-3h6c-6qpq-hv5j

около 1 года назад

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3h69-hjjf-qcc3

около 2 лет назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <= 0.2.3 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h69-fjjv-586m

больше 3 лет назад

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3h69-8qf2-5hg7

5 месяцев назад

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php files can be uploaded and included.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h69-7jmr-q5h4

больше 3 лет назад

AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

EPSS: Низкий
github логотип

GHSA-3h69-4frw-g2jm

больше 3 лет назад

Magento 2 Community Unrestricted File Upload

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h68-wvv6-8r5h

около 4 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h67-wjhc-r8m7

больше 3 лет назад

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h67-j53j-m22p

5 месяцев назад

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3h67-9pvc-gvv9

больше 3 лет назад

updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.

EPSS: Низкий
github логотип

GHSA-3h67-687r-7fpc

4 месяца назад

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h6m-3jhx-cfg9

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h6h-wq56-3w89

The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3h6h-v2q2-7mx9

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h6h-8756-mj4f

A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h6g-vwfm-p62q

Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h6g-r953-7g4p

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h6f-g5f3-gc4w

Access Control Bypass in Spring Security

CVSS3: 9.1
48%
Средний
больше 2 лет назад
github логотип
GHSA-3h6c-fr7r-7jmg

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

CVSS3: 9.8
14%
Средний
почти 2 года назад
github логотип
GHSA-3h6c-c475-jm7v

Arbitrary Code Execution in Gitea

CVSS3: 7.2
93%
Критический
больше 1 года назад
github логотип
GHSA-3h6c-6qpq-hv5j

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3h69-hjjf-qcc3

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <= 0.2.3 versions.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h69-fjjv-586m

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVSS3: 9.8
91%
Критический
больше 3 лет назад
github логотип
GHSA-3h69-8qf2-5hg7

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php files can be uploaded and included.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3h69-7jmr-q5h4

AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h69-4frw-g2jm

Magento 2 Community Unrestricted File Upload

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h68-wvv6-8r5h

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h67-wjhc-r8m7

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3h67-j53j-m22p

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-3h67-9pvc-gvv9

updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h67-687r-7fpc

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

38%
Средний
4 месяца назад

Уязвимостей на страницу