Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-367q-qqwh-pw9w

больше 3 лет назад

The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-367q-prcf-2r3g

больше 3 лет назад

In Bftpd before 4.7, there is a memory leak in the file rename function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-367q-j23v-q67j

почти 4 года назад

Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.

EPSS: Низкий
github логотип

GHSA-367q-hhvx-9x63

3 месяца назад

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-367q-63cf-925j

почти 3 года назад

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-367p-mrph-mgh2

больше 2 лет назад

Information disclosure in Automotive multimedia due to buffer over-read.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-367p-3wqr-p598

больше 3 лет назад

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-367m-r4wp-v752

больше 2 лет назад

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-367j-phrj-8hv2

больше 3 лет назад

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

EPSS: Низкий
github логотип

GHSA-367h-9ph3-3jv2

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-367h-866v-prvm

больше 3 лет назад

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

EPSS: Низкий
github логотип

GHSA-367f-x5pr-rh7f

больше 3 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-367f-4w4m-gh7p

почти 4 года назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.

EPSS: Средний
github логотип

GHSA-367f-3f3f-6cpx

больше 3 лет назад

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

EPSS: Низкий
github логотип

GHSA-367c-j2f5-vj73

больше 3 лет назад

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

EPSS: Низкий
github логотип

GHSA-367c-cgj5-h4gx

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3679-w9pg-j7j7

больше 3 лет назад

An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3679-rrg7-2vqr

почти 4 года назад

Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.

EPSS: Низкий
github логотип

GHSA-3679-r3pr-hwr2

больше 3 лет назад

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6329 and CVE-2014-6376.

EPSS: Средний
github логотип

GHSA-3679-h6wq-5h4c

больше 3 лет назад

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-367q-qqwh-pw9w

The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-367q-prcf-2r3g

In Bftpd before 4.7, there is a memory leak in the file rename function.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-367q-j23v-q67j

Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-367q-hhvx-9x63

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-367q-63cf-925j

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
github логотип
GHSA-367p-mrph-mgh2

Information disclosure in Automotive multimedia due to buffer over-read.

CVSS3: 5.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-367p-3wqr-p598

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-367m-r4wp-v752

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

CVSS3: 5.4
4%
Низкий
больше 2 лет назад
github логотип
GHSA-367j-phrj-8hv2

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-367h-9ph3-3jv2

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-367h-866v-prvm

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-367f-x5pr-rh7f

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-367f-4w4m-gh7p

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.

15%
Средний
почти 4 года назад
github логотип
GHSA-367f-3f3f-6cpx

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-367c-j2f5-vj73

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-367c-cgj5-h4gx

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3679-w9pg-j7j7

An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3679-rrg7-2vqr

Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3679-r3pr-hwr2

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6329 and CVE-2014-6376.

30%
Средний
больше 3 лет назад
github логотип
GHSA-3679-h6wq-5h4c

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу