Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3jf7-8x4g-597x

почти 3 года назад

Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3jf5-fxfr-q6hw

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Panel ParcelPanel allows Reflected XSS.This issue affects ParcelPanel: from n/a through 4.3.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jf4-pmg8-mhm6

больше 3 лет назад

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jf4-h2h6-qc4x

почти 4 года назад

Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3jf4-7gx3-875f

больше 3 лет назад

SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jf4-5q72-7r87

больше 3 лет назад

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-3jf4-475v-2r4g

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3jf3-xmwv-mv5p

больше 3 лет назад

An issue was discovered in Openfind Mail2000 v6 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jf3-rqfc-mfmr

больше 3 лет назад

Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.

EPSS: Низкий
github логотип

GHSA-3jf3-8c3v-79gx

почти 2 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-33891. Reason: This candidate is a reservation duplicate of CVE-2024-33891. Notes: All CVE users should reference CVE-2024-33891 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

EPSS: Низкий
github логотип

GHSA-3jf2-c8c6-ph58

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.

EPSS: Низкий
github логотип

GHSA-3jf2-2rp2-p843

почти 4 года назад

IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.

EPSS: Низкий
github логотип

GHSA-3jcx-v57w-c6rq

около 4 лет назад

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jcw-ph85-3mv4

больше 3 лет назад

OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

EPSS: Низкий
github логотип

GHSA-3jcv-phqx-p74w

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale allows Reflected XSS. This issue affects WOO Codice Fiscale: from n/a through 1.6.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jcv-mqf8-ww8q

почти 4 года назад

The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

EPSS: Низкий
github логотип

GHSA-3jcv-5f9p-2f2p

почти 2 года назад

Cross-site Scripting in electron-pdf

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jcr-m733-wp5w

около 1 года назад

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jcq-cwr7-6332

больше 3 лет назад

jplayer Cross Site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-3jcq-7m4x-57r2

почти 4 года назад

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jf7-8x4g-597x

Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability

CVSS3: 5.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-3jf5-fxfr-q6hw

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Panel ParcelPanel allows Reflected XSS.This issue affects ParcelPanel: from n/a through 4.3.2.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3jf4-pmg8-mhm6

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.

CVSS3: 7.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf4-h2h6-qc4x

Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3jf4-7gx3-875f

SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf4-5q72-7r87

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf4-475v-2r4g

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-3jf3-xmwv-mv5p

An issue was discovered in Openfind Mail2000 v6 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf3-rqfc-mfmr

Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf3-8c3v-79gx

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-33891. Reason: This candidate is a reservation duplicate of CVE-2024-33891. Notes: All CVE users should reference CVE-2024-33891 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

почти 2 года назад
github логотип
GHSA-3jf2-c8c6-ph58

Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf2-2rp2-p843

IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jcx-v57w-c6rq

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3jcw-ph85-3mv4

OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcv-phqx-p74w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale allows Reflected XSS. This issue affects WOO Codice Fiscale: from n/a through 1.6.3.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3jcv-mqf8-ww8q

The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3jcv-5f9p-2f2p

Cross-site Scripting in electron-pdf

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3jcr-m733-wp5w

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3jcq-cwr7-6332

jplayer Cross Site Scripting vulnerability

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcq-7m4x-57r2

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу