Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vcr-vjpj-p33c

почти 4 года назад

join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.

EPSS: Низкий
github логотип

GHSA-3vcr-m67m-mr3p

почти 4 года назад

Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.

EPSS: Низкий
github логотип

GHSA-3vcr-579j-4x48

больше 2 лет назад

Stored XSS vulnerability in Jenkins TAP Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vcq-64gh-84x2

почти 4 года назад

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

EPSS: Низкий
github логотип

GHSA-3vcp-r62v-xpvg

5 месяцев назад

Apache DolphinScheduler vulnerable to Alert Script Attack

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vcm-c42p-3hhf

5 месяцев назад

Mattermost Missing Authorization vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vcm-c256-hxfx

больше 3 лет назад

Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file.

EPSS: Низкий
github логотип

GHSA-3vcm-3w42-g672

почти 4 года назад

Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3vcj-x75g-g7r9

почти 3 года назад

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: ALPS07628612.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3vcj-crmp-9f49

почти 4 года назад

Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.

EPSS: Низкий
github логотип

GHSA-3vcj-cj9g-vfr3

5 месяцев назад

This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.

EPSS: Низкий
github логотип

GHSA-3vcj-6338-x74x

почти 4 года назад

BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.

EPSS: Низкий
github логотип

GHSA-3vch-5776-vg3j

больше 3 лет назад

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vcg-jhjm-5ffm

11 месяцев назад

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vcg-j39x-cwfm

9 месяцев назад

Vyper's `slice()` may elide side-effects when output length is 0

EPSS: Низкий
github логотип

GHSA-3vcg-8p79-jpcv

почти 5 лет назад

SVGlib Vulnerable to XXE Attacks

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vcc-wpcm-9vgm

10 месяцев назад

Unauthenticated attackers can rename "rooms" of arbitrary users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3vcc-qrc9-5rvw

больше 3 лет назад

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

EPSS: Высокий
github логотип

GHSA-3vcc-pp2v-7ffr

почти 4 года назад

A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vcc-ghcj-6f52

13 дней назад

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vcr-vjpj-p33c

join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3vcr-m67m-mr3p

Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3vcr-579j-4x48

Stored XSS vulnerability in Jenkins TAP Plugin

CVSS3: 5.4
6%
Низкий
больше 2 лет назад
github логотип
GHSA-3vcq-64gh-84x2

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3vcp-r62v-xpvg

Apache DolphinScheduler vulnerable to Alert Script Attack

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3vcm-c42p-3hhf

Mattermost Missing Authorization vulnerability

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3vcm-c256-hxfx

Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcm-3w42-g672

Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vcj-x75g-g7r9

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: ALPS07628612.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3vcj-crmp-9f49

Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3vcj-cj9g-vfr3

This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.

0%
Низкий
5 месяцев назад
github логотип
GHSA-3vcj-6338-x74x

BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3vch-5776-vg3j

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcg-jhjm-5ffm

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

CVSS3: 7.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-3vcg-j39x-cwfm

Vyper's `slice()` may elide side-effects when output length is 0

0%
Низкий
9 месяцев назад
github логотип
GHSA-3vcg-8p79-jpcv

SVGlib Vulnerable to XXE Attacks

CVSS3: 9.8
0%
Низкий
почти 5 лет назад
github логотип
GHSA-3vcc-wpcm-9vgm

Unauthenticated attackers can rename "rooms" of arbitrary users.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3vcc-qrc9-5rvw

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

73%
Высокий
больше 3 лет назад
github логотип
GHSA-3vcc-pp2v-7ffr

A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3vcc-ghcj-6f52

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.

0%
Низкий
13 дней назад

Уязвимостей на страницу