Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32fx-c759-m7hg

больше 3 лет назад

Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.

EPSS: Низкий
github логотип

GHSA-32fw-h9ch-p4w3

больше 3 лет назад

Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operations). Supported versions that are affected are 7.0 and 7.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Office. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Xstore Office accessible data as well as unauthorized read access to a subset of Oracle Retail Xstore Office accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Office. CVSS 3.0 Base Score 5.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L).

EPSS: Низкий
github логотип

GHSA-32fw-gq77-f2f2

2 месяца назад

Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes

EPSS: Низкий
github логотип

GHSA-32fw-9wq8-9x9c

больше 3 лет назад

node-latex-pdf is susceptible to command injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-32fw-87x8-mg62

почти 4 года назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0492.

EPSS: Низкий
github логотип

GHSA-32fr-wvmv-2x73

29 дней назад

The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdevart_countdown' shortcode in all versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-32fr-j8gw-q3x6

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to wp-admin/options-general.php.

EPSS: Низкий
github логотип

GHSA-32fr-c24m-729q

почти 4 года назад

Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.

EPSS: Низкий
github логотип

GHSA-32fr-79cm-96p3

больше 3 лет назад

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-32fr-75xx-54f3

3 месяца назад

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-32fr-55pf-phw8

больше 3 лет назад

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-32fq-m2q5-h83g

почти 3 года назад

XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data

CVSS3: 8.9
EPSS: Низкий
github логотип

GHSA-32fq-74q4-425r

около 3 лет назад

Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32fq-43mr-f4fp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.

EPSS: Низкий
github логотип

GHSA-32fp-mqg5-24wv

почти 4 года назад

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

EPSS: Низкий
github логотип

GHSA-32fp-f974-p3vf

9 месяцев назад

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32fp-8jww-ww7j

почти 3 года назад

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This attack can be mitigated using IOMMU protection for the ACPI runtime memory used for the command buffer. This attack can be mitigated by copying the firmware block services data to SMRAM before checking it.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-32fm-pgxp-v67w

7 месяцев назад

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-32fm-h45j-grpv

около 2 месяцев назад

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32fm-h2hh-vxjg

около 3 лет назад

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthorized users may view or execute programs illegally.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32fx-c759-m7hg

Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32fw-h9ch-p4w3

Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operations). Supported versions that are affected are 7.0 and 7.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Office. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Xstore Office accessible data as well as unauthorized read access to a subset of Oracle Retail Xstore Office accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Office. CVSS 3.0 Base Score 5.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32fw-gq77-f2f2

Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes

0%
Низкий
2 месяца назад
github логотип
GHSA-32fw-9wq8-9x9c

node-latex-pdf is susceptible to command injection

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32fw-87x8-mg62

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0492.

1%
Низкий
почти 4 года назад
github логотип
GHSA-32fr-wvmv-2x73

The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdevart_countdown' shortcode in all versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
29 дней назад
github логотип
GHSA-32fr-j8gw-q3x6

Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to wp-admin/options-general.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32fr-c24m-729q

Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32fr-79cm-96p3

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32fr-75xx-54f3

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

CVSS3: 5.7
0%
Низкий
3 месяца назад
github логотип
GHSA-32fr-55pf-phw8

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32fq-m2q5-h83g

XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data

CVSS3: 8.9
1%
Низкий
почти 3 года назад
github логотип
GHSA-32fq-74q4-425r

Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-32fq-43mr-f4fp

Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32fp-mqg5-24wv

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

1%
Низкий
почти 4 года назад
github логотип
GHSA-32fp-f974-p3vf

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-32fp-8jww-ww7j

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This attack can be mitigated using IOMMU protection for the ACPI runtime memory used for the command buffer. This attack can be mitigated by copying the firmware block services data to SMRAM before checking it.

CVSS3: 7
0%
Низкий
почти 3 года назад
github логотип
GHSA-32fm-pgxp-v67w

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue.

CVSS3: 6.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-32fm-h45j-grpv

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-32fm-h2hh-vxjg

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthorized users may view or execute programs illegally.

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу