Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 282 713

Количество 282 713

github логотип

GHSA-222x-p874-5j5q

около 3 лет назад

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-222x-4qhm-7h5f

больше 2 лет назад

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable. The setsockopt TCP_ULP operation does not require any privilege. We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-222w-39qf-5f2w

около 3 лет назад

The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-222v-cx2c-q2f5

5 месяцев назад

phpMyAdmin XSS when checking tables

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-222r-jmhg-vqvf

около 1 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-222r-h4fw-7xv3

около 3 лет назад

Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Asset Liability Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Asset Liability Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-222r-5h2g-hwf2

около 3 лет назад

SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-222r-4v3h-874c

около 3 лет назад

Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.

EPSS: Низкий
github логотип

GHSA-222q-2853-6fvc

около 3 лет назад

DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.

EPSS: Низкий
github логотип

GHSA-222p-ppph-c5v8

около 3 лет назад

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.

EPSS: Низкий
github логотип

GHSA-222p-485j-75xg

около 3 лет назад

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-222m-wr93-px9g

около 3 лет назад

A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-222m-mgc9-9mqv

около 3 лет назад

Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.

EPSS: Средний
github логотип

GHSA-222j-rx46-g89g

4 месяца назад

Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-222h-mmp9-4hcv

около 3 лет назад

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

EPSS: Низкий
github логотип

GHSA-222h-9c7q-5wm5

около 3 лет назад

The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-222g-mvfx-v2wm

около 3 лет назад

Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.

EPSS: Низкий
github логотип

GHSA-222f-7x5j-3g7p

около 3 лет назад

IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-222c-qv22-f3wj

около 3 лет назад

The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers to cause a denial of service (prevention of on-demand scanning) via "specific events" that prevent the user from having read access to unspecified resources.

EPSS: Низкий
github логотип

GHSA-2229-567x-2rpg

почти 3 года назад

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-222x-p874-5j5q

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-222x-4qhm-7h5f

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable. The setsockopt TCP_ULP operation does not require any privilege. We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-222w-39qf-5f2w

The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

CVSS3: 7.5
6%
Низкий
около 3 лет назад
github логотип
GHSA-222v-cx2c-q2f5

phpMyAdmin XSS when checking tables

CVSS3: 6.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-222r-jmhg-vqvf

Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-222r-h4fw-7xv3

Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Asset Liability Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Asset Liability Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-222r-5h2g-hwf2

SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-222r-4v3h-874c

Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.

3%
Низкий
около 3 лет назад
github логотип
GHSA-222q-2853-6fvc

DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.

1%
Низкий
около 3 лет назад
github логотип
GHSA-222p-ppph-c5v8

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.

0%
Низкий
около 3 лет назад
github логотип
GHSA-222p-485j-75xg

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-222m-wr93-px9g

A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-222m-mgc9-9mqv

Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.

17%
Средний
около 3 лет назад
github логотип
GHSA-222j-rx46-g89g

Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-222h-mmp9-4hcv

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

1%
Низкий
около 3 лет назад
github логотип
GHSA-222h-9c7q-5wm5

The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.

1%
Низкий
около 3 лет назад
github логотип
GHSA-222g-mvfx-v2wm

Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.

1%
Низкий
около 3 лет назад
github логотип
GHSA-222f-7x5j-3g7p

IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-222c-qv22-f3wj

The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers to cause a denial of service (prevention of on-demand scanning) via "specific events" that prevent the user from having read access to unspecified resources.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2229-567x-2rpg

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978.

CVSS3: 7.2
0%
Низкий
почти 3 года назад

Уязвимостей на страницу