Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mjq-8c52-rc5f

больше 1 года назад

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3mjp-p938-4329

больше 3 лет назад

Apache Tomcat vulnerable to SecurityManager bypass

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mjp-86xg-ff9v

больше 3 лет назад

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjj-mr4f-qxmx

больше 3 лет назад

Mercurial mishandles integer addition and subtraction

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mjj-j5cv-mf5p

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.

EPSS: Низкий
github логотип

GHSA-3mjj-cjvr-532f

почти 4 года назад

Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

EPSS: Низкий
github логотип

GHSA-3mjh-87v6-2677

почти 4 года назад

Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3mjh-34gx-h2r7

больше 3 лет назад

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

EPSS: Низкий
github логотип

GHSA-3mjg-gvfx-f783

почти 4 года назад

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

EPSS: Низкий
github логотип

GHSA-3mjg-59rv-9hm8

больше 2 лет назад

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjg-24q2-wgh5

2 месяца назад

In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mjf-7c4r-qw77

больше 2 лет назад

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mjc-mr9p-3j4r

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3mjc-cvm2-cpqw

больше 3 лет назад

Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.

EPSS: Низкий
github логотип

GHSA-3mjc-9976-q699

почти 4 года назад

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

EPSS: Низкий
github логотип

GHSA-3mjc-8px4-f596

почти 4 года назад

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

EPSS: Низкий
github логотип

GHSA-3mjc-3jvj-6m9f

почти 2 года назад

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3mj9-vrrp-55v4

около 2 месяцев назад

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mj9-r4cx-8mx5

почти 4 года назад

Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mj9-p2pr-gqr4

больше 3 лет назад

A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mjq-8c52-rc5f

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mjp-p938-4329

Apache Tomcat vulnerable to SecurityManager bypass

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjp-86xg-ff9v

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjj-mr4f-qxmx

Mercurial mishandles integer addition and subtraction

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjj-j5cv-mf5p

Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjj-cjvr-532f

Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mjh-87v6-2677

Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mjh-34gx-h2r7

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjg-gvfx-f783

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3mjg-59rv-9hm8

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mjg-24q2-wgh5

In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3mjf-7c4r-qw77

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mjc-mr9p-3j4r

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-3mjc-cvm2-cpqw

Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjc-9976-q699

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mjc-8px4-f596

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3mjc-3jvj-6m9f

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mj9-vrrp-55v4

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3mj9-r4cx-8mx5

Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3mj9-p2pr-gqr4

A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу