Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3p87-w3c5-27gf

больше 3 лет назад

phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save

EPSS: Низкий
github логотип

GHSA-3p87-gqw8-4pf2

больше 3 лет назад

Showdoc CSRF Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p87-8mrf-82ww

3 месяца назад

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3p86-xgrq-m6p6

почти 4 года назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
github логотип

GHSA-3p86-mc6x-347c

около 1 года назад

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p86-9fpc-5qvc

больше 3 лет назад

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

EPSS: Низкий
github логотип

GHSA-3p86-9955-h393

больше 2 лет назад

Arbitrary File Overwrite in Eclipse JGit

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p85-p4qg-hcrp

около 4 лет назад

pimcore is vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p85-44fv-28jc

больше 2 лет назад

Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p82-g7cx-7qrf

9 месяцев назад

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3p82-57h4-gc59

больше 3 лет назад

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p7x-pg2q-x6w8

больше 3 лет назад

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3p7x-m58j-fm72

больше 3 лет назад

Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).

EPSS: Низкий
github логотип

GHSA-3p7x-94q9-jq9x

3 дня назад

pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p7w-fr8h-8fxc

больше 3 лет назад

The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions.

EPSS: Низкий
github логотип

GHSA-3p7v-r2rf-xx9x

больше 2 лет назад

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3p7v-c8pg-528c

почти 4 года назад

Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.

EPSS: Низкий
github логотип

GHSA-3p7v-5rxq-8fw3

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through 1.14.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3p7v-42w7-qvff

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.

EPSS: Низкий
github логотип

GHSA-3p7r-h3vx-2qj9

10 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows SQL Injection. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p87-w3c5-27gf

phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p87-gqw8-4pf2

Showdoc CSRF Vulnerability

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p87-8mrf-82ww

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3p86-xgrq-m6p6

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

26%
Средний
почти 4 года назад
github логотип
GHSA-3p86-mc6x-347c

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3p86-9fpc-5qvc

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3p86-9955-h393

Arbitrary File Overwrite in Eclipse JGit

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p85-p4qg-hcrp

pimcore is vulnerable to Cross-site Scripting

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-3p85-44fv-28jc

Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p82-g7cx-7qrf

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3p82-57h4-gc59

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3p7x-pg2q-x6w8

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

CVSS3: 9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p7x-m58j-fm72

Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p7x-94q9-jq9x

pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

CVSS3: 7.4
0%
Низкий
3 дня назад
github логотип
GHSA-3p7w-fr8h-8fxc

The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p7v-r2rf-xx9x

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p7v-c8pg-528c

Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3p7v-5rxq-8fw3

Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through 1.14.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3p7v-42w7-qvff

Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3p7r-h3vx-2qj9

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows SQL Injection. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3.

CVSS3: 9.3
0%
Низкий
10 месяцев назад

Уязвимостей на страницу