Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wwc-jjmg-r6gq

около 2 лет назад

Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3wwc-8979-r93x

больше 3 лет назад

CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

EPSS: Низкий
github логотип

GHSA-3ww9-jwr8-mpg3

больше 3 лет назад

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3ww8-8v8c-wrr2

больше 3 лет назад

In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3ww8-82c8-5vpr

больше 3 лет назад

Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification.

EPSS: Низкий
github логотип

GHSA-3ww7-w2h2-5c4x

больше 3 лет назад

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ww7-qxrg-gc3h

больше 3 лет назад

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.

EPSS: Низкий
github логотип

GHSA-3ww7-mwq4-x3gc

11 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3ww7-mpcv-cwwh

больше 3 лет назад

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3ww7-h83j-f3rc

больше 1 года назад

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3ww5-qm6q-xhcg

11 месяцев назад

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3ww4-hpff-r8mv

почти 4 года назад

Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

EPSS: Низкий
github логотип

GHSA-3ww4-gg4f-jr7f

около 2 лет назад

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ww4-cp53-6g2x

больше 4 лет назад

Cross Site Request Forgery in kindeditor

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ww4-5h8f-6c2q

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.

EPSS: Низкий
github логотип

GHSA-3ww3-8fh8-5jcc

почти 4 года назад

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-3ww3-6whr-vv99

больше 3 лет назад

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3wvx-jrh2-66c7

больше 1 года назад

Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation.   This issue affects Application Lifecycle Management (ALM),Quality Center: 15.00, 15.01, 15.01 P1, 15.01 P2, 15.01 P3, 15.01 P4, 15.01 P5, 15.51, 15.51 P1, 15.51 P2, 15.51 P3, 16.00, 16.01 P1.

EPSS: Низкий
github логотип

GHSA-3wvx-cc6q-7chr

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).

EPSS: Низкий
github логотип

GHSA-3wvw-x258-gj48

около 1 года назад

home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wwc-jjmg-r6gq

Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.

CVSS3: 4.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wwc-8979-r93x

CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww9-jwr8-mpg3

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww8-8v8c-wrr2

In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww8-82c8-5vpr

Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww7-w2h2-5c4x

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww7-qxrg-gc3h

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww7-mwq4-x3gc

Rejected reason: Not used

11 месяцев назад
github логотип
GHSA-3ww7-mpcv-cwwh

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww7-h83j-f3rc

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS3: 5.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3ww5-qm6q-xhcg

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3ww4-hpff-r8mv

Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3ww4-gg4f-jr7f

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3ww4-cp53-6g2x

Cross Site Request Forgery in kindeditor

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3ww4-5h8f-6c2q

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ww3-8fh8-5jcc

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).

CVSS3: 2.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-3ww3-6whr-vv99

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

CVSS3: 9.8
23%
Средний
больше 3 лет назад
github логотип
GHSA-3wvx-jrh2-66c7

Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation.   This issue affects Application Lifecycle Management (ALM),Quality Center: 15.00, 15.01, 15.01 P1, 15.01 P2, 15.01 P3, 15.01 P4, 15.01 P5, 15.51, 15.51 P1, 15.51 P2, 15.51 P3, 16.00, 16.01 P1.

0%
Низкий
больше 1 года назад
github логотип
GHSA-3wvx-cc6q-7chr

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wvw-x258-gj48

home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user.

CVSS3: 7.2
0%
Низкий
около 1 года назад

Уязвимостей на страницу