Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-427c-cc94-833h

больше 1 года назад

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4279-qvh5-v435

больше 3 лет назад

Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4278-w8xg-58qx

больше 1 года назад

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4278-658q-vpxq

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4278-2v5v-65r4

больше 4 лет назад

Heap buffer overflow in `RaggedBinCount`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-4277-m35q-7c9w

около 1 года назад

Salt preflight script could be attacker controlled

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4277-8779-3fvr

около 3 лет назад

Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4276-cm8c-788h

6 месяцев назад

Mattermost Fails to Properly Validate Team Role Modification

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-4276-4w95-82xg

больше 3 лет назад

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-4275-m544-m6p7

около 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4274-hq9q-h55c

больше 2 лет назад

SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4274-f6v9-qg7w

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4273-vg8f-3qj2

больше 3 лет назад

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4273-ccpv-pfm8

больше 1 года назад

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it may be dropped, or may result in a Wrong Destination response). An attack would take days to complete.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4272-8494-h23x

почти 2 года назад

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-426w-g76x-326w

больше 3 лет назад

Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426w-795m-hg3h

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Show Stats allows Cross Site Request Forgery. This issue affects WP Show Stats: from n/a through 1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-426v-3j6g-3rj5

больше 3 лет назад

The Pegasus Airlines (aka com.wPegasusAirlines) application 0.84.13503.96707 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-426r-76c6-x67x

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-426q-975p-w5cr

больше 3 лет назад

phpMyAdmin Denial of service (DOS) attack with dbase extension

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-427c-cc94-833h

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4279-qvh5-v435

Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4278-w8xg-58qx

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4278-658q-vpxq

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4278-2v5v-65r4

Heap buffer overflow in `RaggedBinCount`

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4277-m35q-7c9w

Salt preflight script could be attacker controlled

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-4277-8779-3fvr

Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

CVSS3: 6.5
4%
Низкий
около 3 лет назад
github логотип
GHSA-4276-cm8c-788h

Mattermost Fails to Properly Validate Team Role Modification

CVSS3: 3.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-4276-4w95-82xg

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4275-m544-m6p7

** UNSUPPORTED WHEN ASSIGNED ** A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-4274-hq9q-h55c

SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4274-f6v9-qg7w

Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4273-vg8f-3qj2

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4273-ccpv-pfm8

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it may be dropped, or may result in a Wrong Destination response). An attack would take days to complete.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4272-8494-h23x

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-426w-g76x-326w

Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-426w-795m-hg3h

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Show Stats allows Cross Site Request Forgery. This issue affects WP Show Stats: from n/a through 1.5.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-426v-3j6g-3rj5

The Pegasus Airlines (aka com.wPegasusAirlines) application 0.84.13503.96707 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-426r-76c6-x67x

Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-426q-975p-w5cr

phpMyAdmin Denial of service (DOS) attack with dbase extension

CVSS3: 5.9
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу