Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3pc3-3mfc-x5vj

больше 3 лет назад

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.

EPSS: Низкий
github логотип

GHSA-3pc2-fm7p-q2vg

больше 5 лет назад

Cross-site Scripting in October

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3pc2-c878-63rj

больше 2 лет назад

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3p9x-xxx6-2w4p

около 3 лет назад

Broken Access Control in 3rd party TYPO3 extension "femanager"

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3p9x-xxjc-hw5p

больше 3 лет назад

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

EPSS: Низкий
github логотип

GHSA-3p9x-fj5f-w25c

больше 3 лет назад

A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3p9x-34w6-f58v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p9w-wq67-w93f

больше 3 лет назад

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

EPSS: Низкий
github логотип

GHSA-3p9w-w3x4-vc62

больше 3 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p9w-w3g3-89rg

больше 3 лет назад

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

EPSS: Низкий
github логотип

GHSA-3p9w-pv5h-crrp

около 4 лет назад

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p9w-cf27-62fv

больше 2 лет назад

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p9w-7x8w-2m9v

почти 4 года назад

PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

EPSS: Средний
github логотип

GHSA-3p9v-xp6w-wcmc

больше 3 лет назад

QuickAppsCMS Cross-Site Request Forgery (CSRF)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p9v-8h44-8rrr

около 3 лет назад

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3p9v-2c3q-cf4v

около 1 года назад

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3p9r-x2jj-qm7x

больше 3 лет назад

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9r-g8j3-8wq4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

EPSS: Низкий
github логотип

GHSA-3p9r-c4wp-v55p

больше 3 лет назад

** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. NOTE: the vendor does not recognize this issue and will not patch it.

EPSS: Низкий
github логотип

GHSA-3p9r-c4f8-vv7m

больше 1 года назад

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pc3-3mfc-x5vj

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pc2-fm7p-q2vg

Cross-site Scripting in October

CVSS3: 3.7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-3pc2-c878-63rj

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

CVSS3: 7.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p9x-xxx6-2w4p

Broken Access Control in 3rd party TYPO3 extension "femanager"

CVSS3: 8.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p9x-xxjc-hw5p

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9x-fj5f-w25c

A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9x-34w6-f58v

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9w-wq67-w93f

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9w-w3x4-vc62

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9w-w3g3-89rg

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9w-pv5h-crrp

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-3p9w-cf27-62fv

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-3p9w-7x8w-2m9v

PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

17%
Средний
почти 4 года назад
github логотип
GHSA-3p9v-xp6w-wcmc

QuickAppsCMS Cross-Site Request Forgery (CSRF)

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9v-8h44-8rrr

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3p9v-2c3q-cf4v

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVSS3: 9.8
11%
Средний
около 1 года назад
github логотип
GHSA-3p9r-x2jj-qm7x

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9r-g8j3-8wq4

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9r-c4wp-v55p

** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. NOTE: the vendor does not recognize this issue and will not patch it.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9r-c4f8-vv7m

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу