Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jj8-4wp7-f858

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3jj6-g8g9-j5w2

больше 2 лет назад

Due to improper input validation, a remote attacker could execute arbitrary commands on the target system.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3jj5-cjmr-chw6

больше 3 лет назад

Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jj3-875w-p3wj

больше 3 лет назад

Sipwise C5 NGCP CSC through CE_m39.3.1 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3jj3-7hg7-2w24

больше 3 лет назад

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3jj3-575f-c7gh

почти 4 года назад

IMail POP3 daemon uses weak encryption, which allows local users to read files.

EPSS: Низкий
github логотип

GHSA-3jhw-x2w4-9xvv

больше 3 лет назад

Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-3jhw-vwp2-45mp

больше 3 лет назад

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jhw-mxw2-vh5x

больше 3 лет назад

NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward password-cracking exercise.

EPSS: Низкий
github логотип

GHSA-3jhw-mc8h-c9h7

около 3 лет назад

Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can be used by attackers to gain server privileges

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3jhr-f4w6-98q4

больше 3 лет назад

There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.

EPSS: Низкий
github логотип

GHSA-3jhq-878q-9676

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager allows PHP Local File Inclusion. This issue affects WP Event Manager: from n/a through 3.1.49.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3jhq-49ph-54f5

около 4 лет назад

In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752

EPSS: Низкий
github логотип

GHSA-3jhp-7x6r-7792

больше 3 лет назад

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

EPSS: Средний
github логотип

GHSA-3jhm-f5jx-jwjj

больше 3 лет назад

A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server credentials. An attacker could exploit this vulnerability by intercepting the legitimate traffic that is generated by an affected system. An exploit could allow the attacker to obtain the TURN server credentials, which the attacker could use to place audio/video calls and forward packets through the configured TURN server. The attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.

EPSS: Низкий
github логотип

GHSA-3jhm-87m6-x959

больше 3 лет назад

Path traversal mitigation bypass in OctoRPKI

EPSS: Низкий
github логотип

GHSA-3jhj-3m5p-2g94

4 месяца назад

Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.This issue affects Captcha.eu: from n/a through <= 1.0.61.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3jhj-2cfq-97q3

больше 3 лет назад

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3jhh-jx96-63p5

больше 2 лет назад

UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3jhh-8pq8-rfch

больше 3 лет назад

The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jj8-4wp7-f858

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 4.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3jj6-g8g9-j5w2

Due to improper input validation, a remote attacker could execute arbitrary commands on the target system.

CVSS3: 9.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jj5-cjmr-chw6

Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jj3-875w-p3wj

Sipwise C5 NGCP CSC through CE_m39.3.1 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jj3-7hg7-2w24

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT allow any security-sensitive operation to be run unless the bootloader is unlocked.

CVSS3: 6.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jj3-575f-c7gh

IMail POP3 daemon uses weak encryption, which allows local users to read files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jhw-x2w4-9xvv

Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.3
30%
Средний
больше 3 лет назад
github логотип
GHSA-3jhw-vwp2-45mp

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhw-mxw2-vh5x

NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward password-cracking exercise.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhw-mc8h-c9h7

Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can be used by attackers to gain server privileges

CVSS3: 7.2
2%
Низкий
около 3 лет назад
github логотип
GHSA-3jhr-f4w6-98q4

There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhq-878q-9676

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager allows PHP Local File Inclusion. This issue affects WP Event Manager: from n/a through 3.1.49.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-3jhq-49ph-54f5

In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752

0%
Низкий
около 4 лет назад
github логотип
GHSA-3jhp-7x6r-7792

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

54%
Средний
больше 3 лет назад
github логотип
GHSA-3jhm-f5jx-jwjj

A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server credentials. An attacker could exploit this vulnerability by intercepting the legitimate traffic that is generated by an affected system. An exploit could allow the attacker to obtain the TURN server credentials, which the attacker could use to place audio/video calls and forward packets through the configured TURN server. The attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhm-87m6-x959

Path traversal mitigation bypass in OctoRPKI

больше 3 лет назад
github логотип
GHSA-3jhj-3m5p-2g94

Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.This issue affects Captcha.eu: from n/a through <= 1.0.61.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3jhj-2cfq-97q3

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhh-jx96-63p5

UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.

CVSS3: 6.5
48%
Средний
больше 2 лет назад
github логотип
GHSA-3jhh-8pq8-rfch

The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу