Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3gxg-hfhr-6g9x

почти 3 года назад

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3gxf-q95p-q9cg

почти 4 года назад

Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows remote attackers to cause a denial of service by sending crafted packets to dynamic UDP ports, related to a "processing error."

EPSS: Низкий
github логотип

GHSA-3gxf-gcm8-jmp8

около 4 лет назад

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).

EPSS: Средний
github логотип

GHSA-3gxf-9r58-2ghg

почти 3 года назад

`openssl` `X509NameBuilder::build` returned object is not thread safe

EPSS: Низкий
github логотип

GHSA-3gxc-gprv-rpqq

больше 3 лет назад

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3gxc-fc6m-v573

почти 4 года назад

robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 3500.

EPSS: Высокий
github логотип

GHSA-3gx9-chfw-vff5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update.

EPSS: Низкий
github логотип

GHSA-3gx9-8889-ccm7

9 месяцев назад

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3gx9-7v2h-vcxw

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3gx9-37ww-9qw6

почти 4 года назад

Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured

CVSS3: 10
EPSS: Критический
github логотип

GHSA-3gx8-jjh4-8pvh

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.

EPSS: Низкий
github логотип

GHSA-3gx7-xhv7-5mx3

больше 6 лет назад

Arbitrary Code Execution in eslint-utils

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gx7-r2xg-967q

больше 3 лет назад

SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3gx7-hcg4-pm64

8 месяцев назад

A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/users.php. The manipulation of the argument delete leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3gx6-pfq2-pf53

почти 2 года назад

The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-3gx6-h57h-rm27

больше 3 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-3gx6-9g98-g4w5

больше 3 лет назад

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

EPSS: Низкий
github логотип

GHSA-3gx5-q8r9-268f

почти 4 года назад

Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.

EPSS: Низкий
github логотип

GHSA-3gx4-9wgv-v9c6

больше 3 лет назад

Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz_op.cgi.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gx4-563f-8wxf

больше 3 лет назад

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gxg-hfhr-6g9x

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3gxf-q95p-q9cg

Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows remote attackers to cause a denial of service by sending crafted packets to dynamic UDP ports, related to a "processing error."

3%
Низкий
почти 4 года назад
github логотип
GHSA-3gxf-gcm8-jmp8

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).

11%
Средний
около 4 лет назад
github логотип
GHSA-3gxf-9r58-2ghg

`openssl` `X509NameBuilder::build` returned object is not thread safe

почти 3 года назад
github логотип
GHSA-3gxc-gprv-rpqq

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gxc-fc6m-v573

robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 3500.

85%
Высокий
почти 4 года назад
github логотип
GHSA-3gx9-chfw-vff5

Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gx9-8889-ccm7

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.

CVSS3: 7.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-3gx9-7v2h-vcxw

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gx9-37ww-9qw6

Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured

CVSS3: 10
94%
Критический
почти 4 года назад
github логотип
GHSA-3gx8-jjh4-8pvh

Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3gx7-xhv7-5mx3

Arbitrary Code Execution in eslint-utils

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
github логотип
GHSA-3gx7-r2xg-967q

SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gx7-hcg4-pm64

A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/users.php. The manipulation of the argument delete leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3gx6-pfq2-pf53

The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVSS3: 8.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3gx6-h57h-rm27

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
94%
Критический
больше 3 лет назад
github логотип
GHSA-3gx6-9g98-g4w5

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gx5-q8r9-268f

Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3gx4-9wgv-v9c6

Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz_op.cgi.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gx4-563f-8wxf

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу