Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wmm-v973-qmxx

больше 3 лет назад

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wmm-94p8-9h9p

почти 4 года назад

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.

EPSS: Низкий
github логотип

GHSA-3wmj-p44f-xcmr

почти 4 года назад

Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.

EPSS: Низкий
github логотип

GHSA-3wmj-6h74-prmg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.

EPSS: Низкий
github логотип

GHSA-3wmh-mfm8-2v8w

больше 3 лет назад

Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-3wmh-2q6f-xj5c

больше 3 лет назад

A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the component Network Config. The manipulation leads to privilege escalation. The attack may be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wmg-58pp-mmfc

больше 3 лет назад

ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5937, and CVE-2015-5939.

EPSS: Низкий
github логотип

GHSA-3wmg-53g4-p9v4

больше 3 лет назад

The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wmg-2qxc-2xqw

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Peter CyClop WordPress Video allows Stored XSS.This issue affects WordPress Video: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wmg-28v9-8hf6

около 3 лет назад

Subrion CMS is vulnerable to Cross-Site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wmf-q566-h69q

больше 3 лет назад

On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3wmf-hh5m-35jh

почти 4 года назад

UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of "dbase".

EPSS: Низкий
github логотип

GHSA-3wmf-6xrp-7qch

почти 2 года назад

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3wmf-459p-g5g2

почти 2 года назад

Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21676.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wmc-pwpw-7fh8

почти 4 года назад

Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.

EPSS: Низкий
github логотип

GHSA-3wmc-pp6x-rp8g

больше 3 лет назад

A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wmc-fg6p-fq4v

больше 3 лет назад

The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3wm9-x999-hch2

почти 4 года назад

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

EPSS: Низкий
github логотип

GHSA-3wm8-xffc-5pg9

больше 3 лет назад

in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large number of MCPD context messages destined to secondary blades consuming memory leading to MCPD failure. This issue affects only VIPRION hosts with two or more blades installed. Single-blade VIPRION hosts are not affected.

EPSS: Низкий
github логотип

GHSA-3wm8-ph73-r7q9

около 2 месяцев назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wmm-v973-qmxx

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmm-94p8-9h9p

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3wmj-p44f-xcmr

Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3wmj-6h74-prmg

Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3wmh-mfm8-2v8w

Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosure via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmh-2q6f-xj5c

A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the component Network Config. The manipulation leads to privilege escalation. The attack may be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmg-58pp-mmfc

ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5937, and CVE-2015-5939.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmg-53g4-p9v4

The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmg-2qxc-2xqw

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Peter CyClop WordPress Video allows Stored XSS.This issue affects WordPress Video: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wmg-28v9-8hf6

Subrion CMS is vulnerable to Cross-Site Scripting (XSS)

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3wmf-q566-h69q

On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmf-hh5m-35jh

UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of "dbase".

1%
Низкий
почти 4 года назад
github логотип
GHSA-3wmf-6xrp-7qch

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

CVSS3: 6.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wmf-459p-g5g2

Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21676.

CVSS3: 7.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-3wmc-pwpw-7fh8

Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3wmc-pp6x-rp8g

A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmc-fg6p-fq4v

The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.

CVSS3: 7.3
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wm9-x999-hch2

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3wm8-xffc-5pg9

in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large number of MCPD context messages destined to secondary blades consuming memory leading to MCPD failure. This issue affects only VIPRION hosts with two or more blades installed. Single-blade VIPRION hosts are not affected.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wm8-ph73-r7q9

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу