Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 801

Количество 301 801

github логотип

GHSA-2928-r2w9-gm4x

25 дней назад

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2928-6w5x-9xm3

больше 3 лет назад

i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2927-hv3p-f3vp

больше 3 лет назад

Open redirect in caddy

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2924-xwpv-8gcj

больше 3 лет назад

IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2924-mp4r-x286

больше 3 лет назад

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2924-9cv7-3gpq

больше 3 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.

EPSS: Низкий
github логотип

GHSA-2924-22w3-7pm7

больше 3 лет назад

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.

EPSS: Низкий
github логотип

GHSA-2923-cx8w-xvxh

больше 3 лет назад

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

EPSS: Низкий
github логотип

GHSA-28xx-8j99-m32j

около 5 лет назад

Malicious Package in nginxbeautifier

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28xx-6gh9-8gp4

больше 3 лет назад

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Средний
github логотип

GHSA-28xx-46x6-h92x

почти 2 года назад

A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-28xw-m7jp-89ch

больше 3 лет назад

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28xv-h724-wvrh

10 месяцев назад

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28xv-77rw-c8pr

больше 3 лет назад

NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.

EPSS: Низкий
github логотип

GHSA-28xr-x3rf-rhgr

больше 3 лет назад

A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

EPSS: Низкий
github логотип

GHSA-28xr-rgjv-2mgp

почти 3 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Средний
github логотип

GHSA-28xr-mwxg-3qc8

больше 3 лет назад

Command injection in simple-git

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28xq-f23c-p68m

6 месяцев назад

Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28xq-93rr-jp78

больше 3 лет назад

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28xp-g7f6-7mhf

больше 3 лет назад

Syncthing vulnerable to symlink traversal and arbitrary file overwrite

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2928-r2w9-gm4x

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

CVSS3: 5
0%
Низкий
25 дней назад
github логотип
GHSA-2928-6w5x-9xm3

i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2927-hv3p-f3vp

Open redirect in caddy

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2924-xwpv-8gcj

IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2924-mp4r-x286

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2924-9cv7-3gpq

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2924-22w3-7pm7

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2923-cx8w-xvxh

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-28xx-8j99-m32j

Malicious Package in nginxbeautifier

CVSS3: 9.8
около 5 лет назад
github логотип
GHSA-28xx-6gh9-8gp4

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

21%
Средний
больше 3 лет назад
github логотип
GHSA-28xx-46x6-h92x

A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-28xw-m7jp-89ch

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

CVSS3: 8.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-28xv-h724-wvrh

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-28xv-77rw-c8pr

NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28xr-x3rf-rhgr

A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28xr-rgjv-2mgp

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
49%
Средний
почти 3 года назад
github логотип
GHSA-28xr-mwxg-3qc8

Command injection in simple-git

CVSS3: 8.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-28xq-f23c-p68m

Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-28xq-93rr-jp78

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-28xp-g7f6-7mhf

Syncthing vulnerable to symlink traversal and arbitrary file overwrite

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу