Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3p8m-j85q-pgmj

5 месяцев назад

Netty's decoders vulnerable to DoS via zip bomb style attack

EPSS: Низкий
github логотип

GHSA-3p8m-82f9-hcgw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3p8j-x56c-55cf

больше 3 лет назад

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality based on Trillium, a different vulnerability than CVE-2015-0443, CVE-2015-0444, CVE-2015-0445, CVE-2015-0446, CVE-2015-2634, CVE-2015-2635, CVE-2015-4758, and CVE-2015-4759.

EPSS: Низкий
github логотип

GHSA-3p8j-jfr3-2cfp

больше 3 лет назад

SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.

EPSS: Низкий
github логотип

GHSA-3p8j-6252-2pmw

больше 3 лет назад

The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCP SYN packets, as demonstrated by hping, a related issue to CVE-1999-0116.

EPSS: Средний
github логотип

GHSA-3p8j-52c6-rwvv

больше 3 лет назад

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Высокий
github логотип

GHSA-3p8h-m2x9-m6x7

больше 3 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

EPSS: Низкий
github логотип

GHSA-3p8g-7v7v-3gxg

почти 2 года назад

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_hb' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3p8g-7gxj-j8h5

почти 4 года назад

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.

EPSS: Средний
github логотип

GHSA-3p8g-6946-c7f2

больше 3 лет назад

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."

EPSS: Низкий
github логотип

GHSA-3p8f-j2vw-7hw9

около 7 лет назад

mssql-node is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p8c-x7m5-892x

почти 4 года назад

Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.

EPSS: Низкий
github логотип

GHSA-3p89-wgrc-2wm7

почти 4 года назад

PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3p89-8hm7-44h4

почти 2 года назад

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p89-46h6-fhm6

почти 4 года назад

SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3p88-x42x-8hrq

около 2 лет назад

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p87-w3c5-27gf

больше 3 лет назад

phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save

EPSS: Низкий
github логотип

GHSA-3p87-gqw8-4pf2

больше 3 лет назад

Showdoc CSRF Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p87-8mrf-82ww

3 месяца назад

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3p86-xgrq-m6p6

почти 4 года назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p8m-j85q-pgmj

Netty's decoders vulnerable to DoS via zip bomb style attack

0%
Низкий
5 месяцев назад
github логотип
GHSA-3p8m-82f9-hcgw

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8j-x56c-55cf

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality based on Trillium, a different vulnerability than CVE-2015-0443, CVE-2015-0444, CVE-2015-0445, CVE-2015-0446, CVE-2015-2634, CVE-2015-2635, CVE-2015-4758, and CVE-2015-4759.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8j-jfr3-2cfp

SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8j-6252-2pmw

The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCP SYN packets, as demonstrated by hping, a related issue to CVE-1999-0116.

29%
Средний
больше 3 лет назад
github логотип
GHSA-3p8j-52c6-rwvv

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

73%
Высокий
больше 3 лет назад
github логотип
GHSA-3p8h-m2x9-m6x7

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8g-7v7v-3gxg

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_hb' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3p8g-7gxj-j8h5

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.

11%
Средний
почти 4 года назад
github логотип
GHSA-3p8g-6946-c7f2

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8f-j2vw-7hw9

mssql-node is malware

CVSS3: 7.5
0%
Низкий
около 7 лет назад
github логотип
GHSA-3p8c-x7m5-892x

Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3p89-wgrc-2wm7

PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: some of these details are obtained from third party information.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3p89-8hm7-44h4

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3p89-46h6-fhm6

SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3p88-x42x-8hrq

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3p87-w3c5-27gf

phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p87-gqw8-4pf2

Showdoc CSRF Vulnerability

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p87-8mrf-82ww

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3p86-xgrq-m6p6

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

26%
Средний
почти 4 года назад

Уязвимостей на страницу