Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3hv7-66gj-8929

около 2 лет назад

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hv5-9cgc-v44r

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

EPSS: Средний
github логотип

GHSA-3hv5-2p2f-9642

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.

EPSS: Низкий
github логотип

GHSA-3hv4-r3g6-p2wr

больше 1 года назад

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hv4-r2fm-h27f

почти 2 года назад

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3hv4-8798-cj3h

почти 4 года назад

Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDPS HTTP module, via crafted URLs that are "misinterpreted."

EPSS: Низкий
github логотип

GHSA-3hv3-qm2r-7xr8

5 месяцев назад

A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3hv3-pvmg-qv35

больше 3 лет назад

The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hv3-jqjm-jhqf

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.

EPSS: Низкий
github логотип

GHSA-3hrx-rh52-3vwx

больше 3 лет назад

CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.

EPSS: Низкий
github логотип

GHSA-3hrw-8w6h-x9jc

больше 3 лет назад

An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3hrw-324r-f9xj

больше 3 лет назад

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

EPSS: Низкий
github логотип

GHSA-3hrv-ghrw-48w6

больше 1 года назад

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hrv-5j8v-742x

почти 4 года назад

SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

EPSS: Низкий
github логотип

GHSA-3hrr-xwvg-hxvr

почти 2 года назад

Duplicate Advisory: Keycloak DoS via account lockout

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3hrq-4v7v-gjm4

почти 4 года назад

SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

EPSS: Низкий
github логотип

GHSA-3hrp-jhgv-872c

почти 4 года назад

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hrp-jghr-jv6p

больше 3 лет назад

jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hrp-72rj-vmgh

больше 3 лет назад

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow in DBMS_AW.EXECUTE, which allows code execution via a long Current Directory Alias (CDA) command.

EPSS: Низкий
github логотип

GHSA-3hrm-jr5c-jm96

больше 3 лет назад

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hv7-66gj-8929

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3hv5-9cgc-v44r

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

10%
Средний
больше 3 лет назад
github логотип
GHSA-3hv5-2p2f-9642

Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hv4-r3g6-p2wr

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-3hv4-r2fm-h27f

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hv4-8798-cj3h

Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDPS HTTP module, via crafted URLs that are "misinterpreted."

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hv3-qm2r-7xr8

A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3hv3-pvmg-qv35

The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hv3-jqjm-jhqf

A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hrx-rh52-3vwx

CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hrw-8w6h-x9jc

An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

CVSS3: 4.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hrw-324r-f9xj

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hrv-ghrw-48w6

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hrv-5j8v-742x

SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hrr-xwvg-hxvr

Duplicate Advisory: Keycloak DoS via account lockout

CVSS3: 3.7
почти 2 года назад
github логотип
GHSA-3hrq-4v7v-gjm4

SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hrp-jhgv-872c

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

CVSS3: 8.8
9%
Низкий
почти 4 года назад
github логотип
GHSA-3hrp-jghr-jv6p

jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hrp-72rj-vmgh

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow in DBMS_AW.EXECUTE, which allows code execution via a long Current Directory Alias (CDA) command.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3hrm-jr5c-jm96

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу