Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-3754-x86m-fj9m

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

EPSS: Низкий
github логотип

GHSA-3754-wv73-4cjw

больше 1 года назад

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3754-735c-c4rm

больше 3 лет назад

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3754-5x4h-p35m

почти 4 года назад

Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.

EPSS: Низкий
github логотип

GHSA-3753-r5q9-x6fx

больше 1 года назад

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS) condition. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.   This vulnerability is due to improper validation of user input that is in incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3753-7733-qrv7

4 месяца назад

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3753-237w-wx4r

почти 4 года назад

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

EPSS: Низкий
github логотип

GHSA-3752-8v88-868j

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.

EPSS: Низкий
github логотип

GHSA-374x-f6v3-7m9h

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-374x-c55q-x732

больше 3 лет назад

The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.

EPSS: Низкий
github логотип

GHSA-374w-gwqr-fmxg

больше 3 лет назад

brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-374v-mj9j-3hr8

9 месяцев назад

Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-374v-hgw3-c32p

больше 3 лет назад

Microsoft PowerPoint Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-374r-77x4-6c6p

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-374q-r433-22pc

больше 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 617, SD 650/52, SD 808, SD 810, and SDX20, in a QTEE syscall handler, an untrusted pointer dereference can occur.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-374q-g769-jjp8

больше 3 лет назад

A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device. The vulnerability exists because the software incorrectly forwards IPv6 packets that have an IPv6 node-local multicast group address destination and are received on the management interfaces. An attacker could exploit this vulnerability by connecting to the same network as the management interfaces and injecting IPv6 packets that have an IPv6 node-local multicast group address destination. A successful exploit could allow the attacker to cause an IPv6 flood on the corresponding network. Depending on the number of Cisco IOS XR Software nodes on that network segment, exploitation could cause excessive network traffic, resulting in network degradation or a denial of service (DoS) condition.

EPSS: Низкий
github логотип

GHSA-374p-c2qx-7686

4 месяца назад

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-374m-mqq5-65qf

больше 3 лет назад

Remote Desktop Protocol Server Information Disclosure Vulnerability

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-374m-jm66-3vj8

больше 4 лет назад

Heap OOB in `SparseBinCount`

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-374j-r27m-f9mv

больше 2 лет назад

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to bypass certain Privacy preferences

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3754-x86m-fj9m

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3754-wv73-4cjw

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-3754-735c-c4rm

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3754-5x4h-p35m

Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3753-r5q9-x6fx

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS) condition. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.   This vulnerability is due to improper validation of user input that is in incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3753-7733-qrv7

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

CVSS3: 7.2
0%
Низкий
4 месяца назад
github логотип
GHSA-3753-237w-wx4r

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3752-8v88-868j

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-374x-f6v3-7m9h

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-374x-c55q-x732

The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-374w-gwqr-fmxg

brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-374v-mj9j-3hr8

Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.

CVSS3: 3.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-374v-hgw3-c32p

Microsoft PowerPoint Remote Code Execution Vulnerability.

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-374r-77x4-6c6p

Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-374q-r433-22pc

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 617, SD 650/52, SD 808, SD 810, and SDX20, in a QTEE syscall handler, an untrusted pointer dereference can occur.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-374q-g769-jjp8

A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device. The vulnerability exists because the software incorrectly forwards IPv6 packets that have an IPv6 node-local multicast group address destination and are received on the management interfaces. An attacker could exploit this vulnerability by connecting to the same network as the management interfaces and injecting IPv6 packets that have an IPv6 node-local multicast group address destination. A successful exploit could allow the attacker to cause an IPv6 flood on the corresponding network. Depending on the number of Cisco IOS XR Software nodes on that network segment, exploitation could cause excessive network traffic, resulting in network degradation or a denial of service (DoS) condition.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-374p-c2qx-7686

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-374m-mqq5-65qf

Remote Desktop Protocol Server Information Disclosure Vulnerability

CVSS3: 7.7
2%
Низкий
больше 3 лет назад
github логотип
GHSA-374m-jm66-3vj8

Heap OOB in `SparseBinCount`

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-374j-r27m-f9mv

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to bypass certain Privacy preferences

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу