Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2w82-jh8v-fhg4

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Liquido allows Stored XSS.This issue affects Liquido: from n/a through 1.0.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w82-h9hh-7q9j

больше 3 лет назад

Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.

EPSS: Низкий
github логотип

GHSA-2w82-25p5-4h8g

больше 3 лет назад

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2w7x-w5p4-w2mw

почти 4 года назад

The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.

EPSS: Низкий
github логотип

GHSA-2w7x-cxph-48x2

больше 3 лет назад

The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.

EPSS: Низкий
github логотип

GHSA-2w7w-x22q-pmfp

больше 3 лет назад

An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

EPSS: Низкий
github логотип

GHSA-2w7w-qghr-j69p

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."

EPSS: Низкий
github логотип

GHSA-2w7w-5xvh-2987

больше 3 лет назад

Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

EPSS: Низкий
github логотип

GHSA-2w7w-2j92-44hx

больше 4 лет назад

HTTP Request Smuggling in akka-http-core

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w7r-ggfp-x894

4 месяца назад

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w7r-9m4h-c58p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

EPSS: Низкий
github логотип

GHSA-2w7q-mj4w-9cm2

около 2 лет назад

An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2w7p-wvwf-625f

почти 4 года назад

Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.

EPSS: Низкий
github логотип

GHSA-2w7m-jf2p-xvr5

больше 3 лет назад

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.

EPSS: Высокий
github логотип

GHSA-2w7j-pwrp-qpxj

8 месяцев назад

WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of cryptographic keys used in vendor-specific encrypted communications. The issue results from the lack of proper initialization of a variable prior to accessing it. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26295.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2w7j-hchq-jpj6

больше 3 лет назад

GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name.

EPSS: Низкий
github логотип

GHSA-2w7h-qcrg-cr5p

почти 4 года назад

Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2w7h-pgq5-9g2m

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option.

EPSS: Низкий
github логотип

GHSA-2w7h-g4qr-jpgp

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mobile allows Reflected XSS. This issue affects Mobile: from n/a through 1.3.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2w7h-66vj-246p

больше 3 лет назад

OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2w82-jh8v-fhg4

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Liquido allows Stored XSS.This issue affects Liquido: from n/a through 1.0.1.2.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2w82-h9hh-7q9j

Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w82-25p5-4h8g

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7x-w5p4-w2mw

The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2w7x-cxph-48x2

The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7w-x22q-pmfp

An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7w-qghr-j69p

Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2w7w-5xvh-2987

Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7w-2j92-44hx

HTTP Request Smuggling in akka-http-core

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2w7r-ggfp-x894

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2w7r-9m4h-c58p

Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7q-mj4w-9cm2

An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS3: 6.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-2w7p-wvwf-625f

Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2w7m-jf2p-xvr5

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.

79%
Высокий
больше 3 лет назад
github логотип
GHSA-2w7j-pwrp-qpxj

WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of cryptographic keys used in vendor-specific encrypted communications. The issue results from the lack of proper initialization of a variable prior to accessing it. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26295.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2w7j-hchq-jpj6

GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7h-qcrg-cr5p

Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2w7h-pgq5-9g2m

Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w7h-g4qr-jpgp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mobile allows Reflected XSS. This issue affects Mobile: from n/a through 1.3.3.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2w7h-66vj-246p

OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу