Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-35q6-5v8g-78c6

около 2 лет назад

Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35q5-r29v-56m2

больше 3 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-35q3-4p7p-rfwc

почти 4 года назад

Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.

EPSS: Низкий
github логотип

GHSA-35q3-3jc2-w9w3

почти 3 года назад

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35q2-47q7-3pc3

почти 5 лет назад

Node-Redis potential exponential regex in monitor mode

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35px-6m82-p8rw

больше 3 лет назад

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35pw-jwxr-q4v2

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35pv-r327-8m4j

больше 1 года назад

Missing Authorization vulnerability in Tobias Conrad Get Better Reviews for WooCommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through 4.0.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35pv-8c58-rxqx

больше 3 лет назад

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-35pr-gqm6-r366

больше 3 лет назад

Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information

EPSS: Низкий
github логотип

GHSA-35pq-x9mv-j9hq

2 месяца назад

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-35pq-fvh7-h49r

больше 3 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

EPSS: Низкий
github логотип

GHSA-35pq-7pv2-2rfw

около 1 года назад

ps_contactinfo has a potential XSS due to usage of the nofilter tag in template

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-35pp-4j8v-5825

больше 3 лет назад

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-35pm-xrv5-x4qv

больше 3 лет назад

IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35pm-rxh5-93qj

почти 4 года назад

Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.

EPSS: Низкий
github логотип

GHSA-35pm-7mgg-xfm6

больше 3 лет назад

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

EPSS: Низкий
github логотип

GHSA-35pj-p27v-5rpc

2 месяца назад

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35pj-cxpm-pvh5

больше 3 лет назад

Prototype pollution vulnerability in 'cache-base' versions 0.7.0 through 4.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

EPSS: Низкий
github логотип

GHSA-35pg-ggpq-j763

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Submitted By module 6.x before 6.x-1.3 for Drupal allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via an input string for "submitted by" text.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35q6-5v8g-78c6

Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-35q5-r29v-56m2

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-35q3-4p7p-rfwc

Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.

10%
Низкий
почти 4 года назад
github логотип
GHSA-35q3-3jc2-w9w3

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-35q2-47q7-3pc3

Node-Redis potential exponential regex in monitor mode

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-35px-6m82-p8rw

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35pw-jwxr-q4v2

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-35pv-r327-8m4j

Missing Authorization vulnerability in Tobias Conrad Get Better Reviews for WooCommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through 4.0.6.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-35pv-8c58-rxqx

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-35pr-gqm6-r366

Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35pq-x9mv-j9hq

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
2 месяца назад
github логотип
GHSA-35pq-fvh7-h49r

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35pq-7pv2-2rfw

ps_contactinfo has a potential XSS due to usage of the nofilter tag in template

CVSS3: 6.2
0%
Низкий
около 1 года назад
github логотип
GHSA-35pp-4j8v-5825

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35pm-xrv5-x4qv

IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35pm-rxh5-93qj

Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.

5%
Низкий
почти 4 года назад
github логотип
GHSA-35pm-7mgg-xfm6

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-35pj-p27v-5rpc

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

CVSS3: 7.1
0%
Низкий
2 месяца назад
github логотип
GHSA-35pj-cxpm-pvh5

Prototype pollution vulnerability in 'cache-base' versions 0.7.0 through 4.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

больше 3 лет назад
github логотип
GHSA-35pg-ggpq-j763

Cross-site scripting (XSS) vulnerability in the Submitted By module 6.x before 6.x-1.3 for Drupal allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via an input string for "submitted by" text.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу