Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 694

Количество 301 694

github логотип

GHSA-286p-v4j3-jjrh

больше 3 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.

EPSS: Низкий
github логотип

GHSA-286p-qr36-86ph

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E2Pdf.Com allows Stored XSS.This issue affects e2pdf: from n/a through 1.25.05.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-286p-j2mm-3mx9

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins All Embed – Elementor Addons allows Stored XSS. This issue affects All Embed – Elementor Addons: from n/a through 1.1.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-286p-cf2h-fc7g

больше 3 лет назад

One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

EPSS: Средний
github логотип

GHSA-286m-rx96-29m7

больше 3 лет назад

The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-286m-6pg9-v42v

4 месяца назад

Duplicate Advisory: Multiple issues involving quote API in shlex

CVSS3: 3.2
EPSS: Низкий
github логотип

GHSA-286j-65v5-3w84

больше 3 лет назад

STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-286j-5pg5-82c5

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker needs valid administrator credentials.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-286j-4758-jr9w

больше 3 лет назад

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

EPSS: Низкий
github логотип

GHSA-286h-7xfj-fm4g

2 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-286h-2f8v-j572

больше 3 лет назад

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security). Supported versions that are affected are 11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. Note: Contact Support for fixes. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-286g-52x6-9289

больше 3 лет назад

Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-286g-3jpc-9mqf

больше 3 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially occur.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-286f-m35x-h7r5

7 месяцев назад

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-286f-h89f-6gf2

почти 2 года назад

A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-286c-pf2q-9ghm

около 3 лет назад

A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could exploit this vulnerability by rebooting the switch into ROMMON and entering specific commands through the console. A successful exploit could allow the attacker to read any file or reset the enable password.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2869-r8x6-9882

больше 3 лет назад

Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.

EPSS: Низкий
github логотип

GHSA-2868-jvjx-qxr9

больше 3 лет назад

Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2868-gw76-97vq

около 2 лет назад

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2868-ff44-43qv

больше 2 лет назад

Liferay portal unauthorized access to objects via OAuth 2 scope

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-286p-v4j3-jjrh

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-286p-qr36-86ph

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E2Pdf.Com allows Stored XSS.This issue affects e2pdf: from n/a through 1.25.05.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-286p-j2mm-3mx9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins All Embed – Elementor Addons allows Stored XSS. This issue affects All Embed – Elementor Addons: from n/a through 1.1.3.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-286p-cf2h-fc7g

One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

16%
Средний
больше 3 лет назад
github логотип
GHSA-286m-rx96-29m7

The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-286m-6pg9-v42v

Duplicate Advisory: Multiple issues involving quote API in shlex

CVSS3: 3.2
4 месяца назад
github логотип
GHSA-286j-65v5-3w84

STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-286j-5pg5-82c5

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker needs valid administrator credentials.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-286j-4758-jr9w

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-286h-7xfj-fm4g

Rejected reason: Not used

2 месяца назад
github логотип
GHSA-286h-2f8v-j572

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security). Supported versions that are affected are 11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. Note: Contact Support for fixes. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

CVSS3: 7.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-286g-52x6-9289

Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-286g-3jpc-9mqf

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially occur.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-286f-m35x-h7r5

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-286f-h89f-6gf2

A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data.

CVSS3: 9.8
4%
Низкий
почти 2 года назад
github логотип
GHSA-286c-pf2q-9ghm

A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could exploit this vulnerability by rebooting the switch into ROMMON and entering specific commands through the console. A successful exploit could allow the attacker to read any file or reset the enable password.

CVSS3: 4.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-2869-r8x6-9882

Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2868-jvjx-qxr9

Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2868-gw76-97vq

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2868-ff44-43qv

Liferay portal unauthorized access to objects via OAuth 2 scope

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу