Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3v2h-3966-qxpq

почти 4 года назад

Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.

EPSS: Низкий
github логотип

GHSA-3v2g-q648-8v38

больше 3 лет назад

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.

EPSS: Низкий
github логотип

GHSA-3v2g-m6qm-pvj3

около 4 лет назад

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v28-9jjp-4g5w

больше 3 лет назад

Plone Privilege Escalation Vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3v27-h7pg-jm95

почти 4 года назад

Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this issue was later reported for 2.5.1.1.

EPSS: Низкий
github логотип

GHSA-3v25-grm8-qvf9

больше 3 лет назад

SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3v25-95xx-r27w

почти 4 года назад

Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).

EPSS: Низкий
github логотип

GHSA-3v24-r367-63mh

почти 4 года назад

Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.

EPSS: Высокий
github логотип

GHSA-3v24-cp75-hv5g

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authentication of administrators for requests that add accounts via a new-client action.

EPSS: Низкий
github логотип

GHSA-3v23-qhr8-m9w2

больше 3 лет назад

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.

EPSS: Низкий
github логотип

GHSA-3rxx-hfrv-77fv

почти 2 года назад

A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function DeleteImage of the file /apps/system/router/upload.go. The manipulation of the argument fileName with the input ../../../../../../../../../tmp/1.txt leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257062 is the identifier assigned to this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rxx-8f33-7p6p

почти 2 года назад

Concrete CMS Cross Site Request Forgery (CSRF) vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rxw-g5h2-cm9q

почти 4 года назад

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request with a long Accept-Language header.

EPSS: Средний
github логотип

GHSA-3rxw-3rwx-9c67

больше 1 года назад

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rxw-2675-c3j9

больше 1 года назад

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rxq-7p39-5hg9

больше 3 лет назад

IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3rxp-78v9-g8cc

больше 3 лет назад

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response via an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rxp-2593-q684

больше 3 лет назад

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.

EPSS: Низкий
github логотип

GHSA-3rxm-qjgx-2m73

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rxj-99fp-83j6

больше 3 лет назад

Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v2h-3966-qxpq

Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3v2g-q648-8v38

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3v2g-m6qm-pvj3

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3v28-9jjp-4g5w

Plone Privilege Escalation Vulnerability

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3v27-h7pg-jm95

Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this issue was later reported for 2.5.1.1.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3v25-grm8-qvf9

SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v25-95xx-r27w

Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).

0%
Низкий
почти 4 года назад
github логотип
GHSA-3v24-r367-63mh

Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.

74%
Высокий
почти 4 года назад
github логотип
GHSA-3v24-cp75-hv5g

Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authentication of administrators for requests that add accounts via a new-client action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v23-qhr8-m9w2

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rxx-hfrv-77fv

A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function DeleteImage of the file /apps/system/router/upload.go. The manipulation of the argument fileName with the input ../../../../../../../../../tmp/1.txt leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257062 is the identifier assigned to this vulnerability.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3rxx-8f33-7p6p

Concrete CMS Cross Site Request Forgery (CSRF) vulnerability

CVSS3: 4.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3rxw-g5h2-cm9q

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request with a long Accept-Language header.

27%
Средний
почти 4 года назад
github логотип
GHSA-3rxw-3rwx-9c67

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rxw-2675-c3j9

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rxq-7p39-5hg9

IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rxp-78v9-g8cc

Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response via an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rxp-2593-q684

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rxm-qjgx-2m73

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3rxj-99fp-83j6

Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу