Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3q3v-9mp5-cqff

около 2 лет назад

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-3q3v-4552-vg2p

больше 3 лет назад

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q3r-r4q5-9j62

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, when running on Internet Explorer, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

EPSS: Низкий
github логотип

GHSA-3q3r-9fqq-hxcm

около 2 лет назад

Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3q3r-47jp-8cqm

больше 2 лет назад

The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3q3q-qxg4-v82q

больше 3 лет назад

Improper input validation in the Intel(R) Ethernet Controllers X722 and 800 series Linux RMDA driver before version 1.3.19 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-3q3p-p5f8-mq9j

больше 3 лет назад

Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3q3p-p4rx-fcjw

больше 3 лет назад

The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (remote-administration outage) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3q3p-mxc5-jrmq

почти 2 года назад

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. 

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3q3p-mhr4-4m53

больше 2 лет назад

Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q3p-5x2r-j3hq

8 месяцев назад

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q3m-hfjx-w733

больше 1 года назад

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3q3m-ghwm-59r3

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows Stored XSS.This issue affects Master Slider: from n/a through 3.9.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q3m-3ccv-7882

почти 4 года назад

PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.

EPSS: Низкий
github логотип

GHSA-3q3j-5m7x-chq6

больше 2 лет назад

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3q3h-cf5f-xf24

почти 4 года назад

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: Средний
github логотип

GHSA-3q3h-5pcw-f3fh

почти 4 года назад

Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3q3g-7rqj-c25p

больше 3 лет назад

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the api.php page. A successful exploit could allow an attacker to execute arbitrary scripts.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3q3f-m2cj-5323

больше 3 лет назад

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.

EPSS: Низкий
github логотип

GHSA-3q3f-6h94-9gg7

почти 3 года назад

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q3v-9mp5-cqff

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.

CVSS3: 7.2
79%
Высокий
около 2 лет назад
github логотип
GHSA-3q3v-4552-vg2p

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3r-r4q5-9j62

Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, when running on Internet Explorer, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3r-9fqq-hxcm

Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3q3r-47jp-8cqm

The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q3q-qxg4-v82q

Improper input validation in the Intel(R) Ethernet Controllers X722 and 800 series Linux RMDA driver before version 1.3.19 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3p-p5f8-mq9j

Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3p-p4rx-fcjw

The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (remote-administration outage) via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3p-mxc5-jrmq

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. 

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3q3p-mhr4-4m53

Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3q3p-5x2r-j3hq

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3q3m-hfjx-w733

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q3m-ghwm-59r3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows Stored XSS.This issue affects Master Slider: from n/a through 3.9.8.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3q3m-3ccv-7882

PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3q3j-5m7x-chq6

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q3h-cf5f-xf24

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

13%
Средний
почти 4 года назад
github логотип
GHSA-3q3h-5pcw-f3fh

Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3q3g-7rqj-c25p

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the api.php page. A successful exploit could allow an attacker to execute arbitrary scripts.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3f-m2cj-5323

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q3f-6h94-9gg7

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу