Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-34w6-68wc-gx7h

больше 3 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34w6-4rx6-2cg7

больше 3 лет назад

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195035.

EPSS: Низкий
github логотип

GHSA-34w5-cvqh-fxgw

около 1 года назад

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-34w5-49cc-qp8r

почти 3 года назад

The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-34w4-wrqp-j47g

больше 2 лет назад

Sensitive cookie in HTTPS session without 'Secure' attribute in thorsten/phpmyfaq

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34w4-v7w4-hxvc

больше 3 лет назад

SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34w4-3qr3-m637

10 месяцев назад

Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34w3-rhpm-qv77

больше 1 года назад

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-34w3-ccxr-5822

почти 4 года назад

Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.

EPSS: Низкий
github логотип

GHSA-34w3-c4pr-6xhv

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 Update 2011-D allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll Core.

EPSS: Низкий
github логотип

GHSA-34w2-vr99-v872

2 месяца назад

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Failed value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of existing markup and inject arbitrary script. A remote attacker can supply a crafted payload that closes an existing HTML list element, inserts attacker-controlled JavaScript, and comments out remaining code, leading to script execution in a victim’s browser when the victim visits a malicious link. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34w2-qwhq-wprv

больше 2 лет назад

Request to LDAP is sent before user permissions are checked.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-34w2-p277-pp7p

больше 3 лет назад

An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. This issue does not affect Prisma Access.

EPSS: Низкий
github логотип

GHSA-34vx-pc43-g6xj

больше 3 лет назад

The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34vx-jr58-q9x4

больше 3 лет назад

A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-34vx-3926-gfg8

около 4 лет назад

IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34vw-wmm7-63j4

больше 3 лет назад

A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server on the device. The web server is running with root privileges and the injected code will also run with root privileges.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-34vw-vvrj-pr33

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34vw-rxxh-698f

около 2 лет назад

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34vw-m4rh-r36p

больше 3 лет назад

Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34w6-68wc-gx7h

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34w6-4rx6-2cg7

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195035.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34w5-cvqh-fxgw

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-34w5-49cc-qp8r

The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode.

CVSS3: 8.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-34w4-wrqp-j47g

Sensitive cookie in HTTPS session without 'Secure' attribute in thorsten/phpmyfaq

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34w4-v7w4-hxvc

SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-34w4-3qr3-m637

Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-34w3-rhpm-qv77

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-34w3-ccxr-5822

Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.

0%
Низкий
почти 4 года назад
github логотип
GHSA-34w3-c4pr-6xhv

Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 Update 2011-D allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll Core.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-34w2-vr99-v872

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Failed value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of existing markup and inject arbitrary script. A remote attacker can supply a crafted payload that closes an existing HTML list element, inserts attacker-controlled JavaScript, and comments out remaining code, leading to script execution in a victim’s browser when the victim visits a malicious link. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-34w2-qwhq-wprv

Request to LDAP is sent before user permissions are checked.

CVSS3: 8.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34w2-p277-pp7p

An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. This issue does not affect Prisma Access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34vx-pc43-g6xj

The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34vx-jr58-q9x4

A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found.

CVSS3: 9.8
39%
Средний
больше 3 лет назад
github логотип
GHSA-34vx-3926-gfg8

IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-34vw-wmm7-63j4

A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server on the device. The web server is running with root privileges and the injected code will also run with root privileges.

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34vw-vvrj-pr33

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-34vw-rxxh-698f

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

CVSS3: 9.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-34vw-m4rh-r36p

Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM

CVSS3: 7
больше 3 лет назад

Уязвимостей на страницу