Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3fc3-xgjx-f77w

больше 3 лет назад

SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3fc2-v7qw-hp8q

больше 3 лет назад

A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

EPSS: Низкий
github логотип

GHSA-3fc2-jqm9-wxw3

почти 4 года назад

Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3fc2-hr6q-94x9

больше 3 лет назад

cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Reset Poisoning, specifically a reset URL pointing at an attacker controlled server can be created by using a host header attack.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fc2-9v98-58qv

больше 3 лет назад

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.

EPSS: Низкий
github логотип

GHSA-3f9w-j677-96fc

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization allows Reflected XSS. This issue affects Quick Localization: from n/a through 0.1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3f9w-fv2p-w675

больше 3 лет назад

The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f9w-9gh8-8jm4

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages the mishandling of strict mode functions.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3f9w-974v-5vhv

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Simple Travel Map allows Stored XSS.This issue affects Simple Travel Map: from n/a through 0.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3f9w-7983-qcmq

около 2 лет назад

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3f9w-43j6-x43v

больше 3 лет назад

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.

EPSS: Средний
github логотип

GHSA-3f9v-x6pf-3296

почти 4 года назад

The tr_rx function in ibmtr.c for Linux kernel 2.6.19 assigns the wrong flag to the ip_summed field, which allows remote attackers to cause a denial of service (memory corruption) via crafted packets that cause the kernel to interpret another field as an offset.

EPSS: Низкий
github логотип

GHSA-3f9v-jhc5-p8jp

12 месяцев назад

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3f9r-qr29-wv82

около 3 лет назад

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f9q-r2pw-87vm

больше 2 лет назад

libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f9q-pqwh-9q72

почти 4 года назад

Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

EPSS: Низкий
github логотип

GHSA-3f9q-jjqq-4g32

больше 3 лет назад

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not validated.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f9p-mvpq-ggr6

больше 3 лет назад

The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT from CVE-2014-3951 per ADT2 due to different vulnerability types.

EPSS: Низкий
github логотип

GHSA-3f9p-f8r2-mqhp

больше 1 года назад

: Authentication Bypass Using an Alternate Path or Channel vulnerability in sooskriszta, webforza BuddyPress Better Registration allows : Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a through 1.6.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f9p-7mj8-2f34

больше 3 лет назад

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fc3-xgjx-f77w

SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fc2-v7qw-hp8q

A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fc2-jqm9-wxw3

Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3fc2-hr6q-94x9

cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Reset Poisoning, specifically a reset URL pointing at an attacker controlled server can be created by using a host header attack.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fc2-9v98-58qv

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f9w-j677-96fc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization allows Reflected XSS. This issue affects Quick Localization: from n/a through 0.1.0.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3f9w-fv2p-w675

The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f9w-9gh8-8jm4

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code via a crafted web site that leverages the mishandling of strict mode functions.

CVSS3: 8.8
25%
Средний
больше 3 лет назад
github логотип
GHSA-3f9w-974v-5vhv

Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Simple Travel Map allows Stored XSS.This issue affects Simple Travel Map: from n/a through 0.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3f9w-7983-qcmq

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
2%
Низкий
около 2 лет назад
github логотип
GHSA-3f9w-43j6-x43v

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.

19%
Средний
больше 3 лет назад
github логотип
GHSA-3f9v-x6pf-3296

The tr_rx function in ibmtr.c for Linux kernel 2.6.19 assigns the wrong flag to the ip_summed field, which allows remote attackers to cause a denial of service (memory corruption) via crafted packets that cause the kernel to interpret another field as an offset.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3f9v-jhc5-p8jp

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
1%
Низкий
12 месяцев назад
github логотип
GHSA-3f9r-qr29-wv82

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3f9q-r2pw-87vm

libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3f9q-pqwh-9q72

Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3f9q-jjqq-4g32

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not validated.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f9p-mvpq-ggr6

The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT from CVE-2014-3951 per ADT2 due to different vulnerability types.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f9p-f8r2-mqhp

: Authentication Bypass Using an Alternate Path or Channel vulnerability in sooskriszta, webforza BuddyPress Better Registration allows : Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a through 1.6.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f9p-7mj8-2f34

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу