Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3j6w-w5q2-q9cm

почти 4 года назад

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-3j6w-p6vm-g8hg

около 1 месяца назад

A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were exploited, an attacker‘s capabilities would only be limited by role based access controls (RBAC).

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3j6w-7mhc-r5hr

больше 3 лет назад

A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.

EPSS: Низкий
github логотип

GHSA-3j6r-rxq5-32pr

почти 4 года назад

Heap-based buffer overflow in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure.

EPSS: Средний
github логотип

GHSA-3j6r-49cw-7x36

больше 3 лет назад

Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ARF file, aka Bug IDs CSCue74118, CSCub28371, CSCud23401, and CSCud31109.

EPSS: Низкий
github логотип

GHSA-3j6m-wc56-qvw2

больше 3 лет назад

Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCA6574AU, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j6m-rjrw-hpjc

больше 3 лет назад

MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j6m-r2w5-2j6r

почти 2 года назад

The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to mark orders as paid.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3j6m-m5v5-9785

больше 3 лет назад

OpenCart Cross-Site Request Forgery (CSRF)

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3j6m-cq99-v646

больше 1 года назад

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3j6m-cf6c-7f3h

больше 2 лет назад

Insecure permissions in the ps_customer table of Prestashop scquickaccounting before v3.7.3 allows attackers to access sensitive information stored in the component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3j6h-ffr2-hw5m

больше 3 лет назад

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3j6h-5v68-hvqg

6 месяцев назад

Liferay Portal CAPTCHA Bypass for Gogo Shell

EPSS: Низкий
github логотип

GHSA-3j6g-xwcr-2hcw

около 1 года назад

Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j6g-hxx5-3q26

больше 4 лет назад

Observable Discrepancy in Apache Kafka

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3j6f-gvgr-r53v

почти 3 года назад

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j6f-38xg-724m

8 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Path Traversal. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j6c-pw4r-rhxw

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements allows DOM-Based XSS.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.11.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3j6c-cpfp-ff5p

больше 3 лет назад

Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit these vulnerabilities by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should be activated for the ENIP packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j69-7qgr-69pj

11 месяцев назад

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-services.php. The manipulation of the argument sertitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j6w-w5q2-q9cm

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3j6w-p6vm-g8hg

A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were exploited, an attacker‘s capabilities would only be limited by role based access controls (RBAC).

CVSS3: 8.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3j6w-7mhc-r5hr

A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6r-rxq5-32pr

Heap-based buffer overflow in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure.

13%
Средний
почти 4 года назад
github логотип
GHSA-3j6r-49cw-7x36

Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ARF file, aka Bug IDs CSCue74118, CSCub28371, CSCud23401, and CSCud31109.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6m-wc56-qvw2

Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCA6574AU, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6m-rjrw-hpjc

MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6m-r2w5-2j6r

The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to mark orders as paid.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3j6m-m5v5-9785

OpenCart Cross-Site Request Forgery (CSRF)

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6m-cq99-v646

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3j6m-cf6c-7f3h

Insecure permissions in the ps_customer table of Prestashop scquickaccounting before v3.7.3 allows attackers to access sensitive information stored in the component.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3j6h-ffr2-hw5m

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j6h-5v68-hvqg

Liferay Portal CAPTCHA Bypass for Gogo Shell

0%
Низкий
6 месяцев назад
github логотип
GHSA-3j6g-xwcr-2hcw

Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3j6g-hxx5-3q26

Observable Discrepancy in Apache Kafka

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3j6f-gvgr-r53v

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3j6f-38xg-724m

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Path Traversal. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3j6c-pw4r-rhxw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements allows DOM-Based XSS.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.11.0.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3j6c-cpfp-ff5p

Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit these vulnerabilities by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should be activated for the ENIP packet.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j69-7qgr-69pj

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-services.php. The manipulation of the argument sertitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу