Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 437

Количество 290 437

github логотип

GHSA-2fch-hv74-fgw9

больше 2 лет назад

Cross site scripting (XSS) in wwbn/avideo

EPSS: Низкий
github логотип

GHSA-2fch-4j3w-44mf

больше 3 лет назад

cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).

EPSS: Низкий
github логотип

GHSA-2fcg-hwv9-g767

почти 2 года назад

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fcg-5wrc-pm23

больше 3 лет назад

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2fcg-48pf-99vm

больше 3 лет назад

Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.

EPSS: Низкий
github логотип

GHSA-2fcc-jc2g-q7h3

7 месяцев назад

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fcc-j9wr-vcj4

27 дней назад

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fc9-xpp8-2g9h

больше 1 года назад

`@backstage/backend-common` vulnerable to path traversal through symlinks

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2fc8-wj99-h595

больше 3 лет назад

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

EPSS: Низкий
github логотип

GHSA-2fc8-f6cq-59vj

больше 3 лет назад

Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fc8-2w75-6pjh

больше 3 лет назад

Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

EPSS: Низкий
github логотип

GHSA-2fc7-57pg-9g23

больше 1 года назад

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2fc6-qgjv-7hw5

11 дней назад

Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Neon Channel Product Customizer Free: from n/a through 2.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fc6-fh8m-r4wf

больше 3 лет назад

OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fc6-73c9-q328

больше 3 лет назад

IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fc6-6f56-6w7m

4 месяца назад

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_cart of the file /oews/classes/Master.php?f=delete_cart. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fc6-449p-gv59

больше 3 лет назад

Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

EPSS: Низкий
github логотип

GHSA-2fc5-xwgx-gmqm

больше 2 лет назад

PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fc5-f5mf-j7xp

больше 3 лет назад

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetservicecfg function.

EPSS: Низкий
github логотип

GHSA-2fc5-5jjf-fmx7

больше 3 лет назад

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fch-hv74-fgw9

Cross site scripting (XSS) in wwbn/avideo

больше 2 лет назад
github логотип
GHSA-2fch-4j3w-44mf

cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fcg-hwv9-g767

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fcg-5wrc-pm23

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fcg-48pf-99vm

Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fcc-jc2g-q7h3

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.&nbsp; This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.

CVSS3: 7.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-2fcc-j9wr-vcj4

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
27 дней назад
github логотип
GHSA-2fc9-xpp8-2g9h

`@backstage/backend-common` vulnerable to path traversal through symlinks

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fc8-wj99-h595

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc8-f6cq-59vj

Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc8-2w75-6pjh

Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc7-57pg-9g23

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.

CVSS3: 5.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fc6-qgjv-7hw5

Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Neon Channel Product Customizer Free: from n/a through 2.0.

CVSS3: 7.5
0%
Низкий
11 дней назад
github логотип
GHSA-2fc6-fh8m-r4wf

OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc6-73c9-q328

IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc6-6f56-6w7m

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_cart of the file /oews/classes/Master.php?f=delete_cart. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2fc6-449p-gv59

Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc5-xwgx-gmqm

PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fc5-f5mf-j7xp

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetservicecfg function.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fc5-5jjf-fmx7

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу