Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3c9m-23pf-qj34

больше 3 лет назад

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138441.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3c9j-r976-x5vf

больше 2 лет назад

In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c9j-8326-hh7c

6 месяцев назад

A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3c9j-4f4v-vmxx

больше 3 лет назад

The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.

EPSS: Низкий
github логотип

GHSA-3c9h-j75v-3mr5

больше 3 лет назад

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This vulnerability affects Firefox < 84.

EPSS: Низкий
github логотип

GHSA-3c9g-4q34-jp78

почти 4 года назад

Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c9f-c64m-h4wc

7 месяцев назад

Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3c9c-mvvg-2vw7

больше 3 лет назад

Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security). The supported version that is affected is 12.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle AutoVue accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3c9c-9w7c-4f9j

8 месяцев назад

Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3c9c-2p65-qvwv

больше 4 лет назад

Prototype pollution in aurelia-path

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3c99-j6qp-35xx

12 месяцев назад

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c99-g4qv-p9wq

почти 2 года назад

Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3c98-cg94-53j7

почти 4 года назад

Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).

EPSS: Низкий
github логотип

GHSA-3c96-xf6p-r5wm

11 месяцев назад

The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This vulnerability is potentially a duplicate of CVE-2025-22320.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c96-x4xm-9p54

больше 3 лет назад

The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element.

EPSS: Низкий
github логотип

GHSA-3c96-w4r4-hg26

больше 1 года назад

A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3c96-jfc7-h3r6

больше 2 лет назад

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3c96-cx8m-c77h

больше 3 лет назад

In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3c96-8q7p-6jr2

больше 3 лет назад

IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

EPSS: Низкий
github логотип

GHSA-3c94-ghvc-4j26

около 1 года назад

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c9m-23pf-qj34

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138441.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9j-r976-x5vf

In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c9j-8326-hh7c

A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3c9j-4f4v-vmxx

The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9h-j75v-3mr5

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This vulnerability affects Firefox < 84.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9g-4q34-jp78

Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3c9f-c64m-h4wc

Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3c9c-mvvg-2vw7

Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security). The supported version that is affected is 12.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle AutoVue accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9c-9w7c-4f9j

Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-3c9c-2p65-qvwv

Prototype pollution in aurelia-path

CVSS3: 9.1
9%
Низкий
больше 4 лет назад
github логотип
GHSA-3c99-j6qp-35xx

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.

CVSS3: 8.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-3c99-g4qv-p9wq

Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3c98-cg94-53j7

Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c96-xf6p-r5wm

The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all versions up to, and including, 1.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This vulnerability is potentially a duplicate of CVE-2025-22320.

CVSS3: 6.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-3c96-x4xm-9p54

The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3c96-w4r4-hg26

A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
3%
Низкий
больше 1 года назад
github логотип
GHSA-3c96-jfc7-h3r6

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c96-cx8m-c77h

In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c96-8q7p-6jr2

IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c94-ghvc-4j26

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу