Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 405

Количество 300 405

github логотип

GHSA-23p9-r47f-2m64

больше 3 лет назад

SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.

EPSS: Низкий
github логотип

GHSA-23p9-75pp-2wv4

12 месяцев назад

A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit this vulnerability by sending malicious requests to an API endpoint. An exploit could allow the attacker to download files from or modify limited configuration options on the affected system.There are no workarounds that address this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23p9-49c6-fm5w

больше 3 лет назад

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

EPSS: Низкий
github логотип

GHSA-23p7-2cxv-3gpw

7 месяцев назад

A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23p6-m374-wpr8

больше 3 лет назад

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23p6-gh9w-qhrf

больше 3 лет назад

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

EPSS: Низкий
github логотип

GHSA-23p5-23pm-xvp3

около 1 года назад

The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-23p4-xxgc-xqvf

почти 2 года назад

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-23p4-qm9x-842q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23p4-5ppc-536p

больше 3 лет назад

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

EPSS: Низкий
github логотип

GHSA-23p3-vg9x-qw6p

больше 3 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

EPSS: Низкий
github логотип

GHSA-23p3-vcf6-94xq

около 2 лет назад

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23p3-rx33-wm34

больше 3 лет назад

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

EPSS: Низкий
github логотип

GHSA-23p3-9m3p-qpwp

5 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23p2-2jrp-5wcp

около 1 года назад

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23mx-m43g-r4fh

5 месяцев назад

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-23mw-hwq9-w4q8

около 2 лет назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mr-m7vf-wgmp

больше 3 лет назад

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-23mr-c4wx-m5rr

больше 3 лет назад

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23mm-fp65-w636

больше 2 лет назад

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23p9-r47f-2m64

SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23p9-75pp-2wv4

A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit this vulnerability by sending malicious requests to an API endpoint. An exploit could allow the attacker to download files from or modify limited configuration options on the affected system.There are no workarounds that address this vulnerability.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-23p9-49c6-fm5w

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23p7-2cxv-3gpw

A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-23p6-m374-wpr8

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23p6-gh9w-qhrf

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p5-23pm-xvp3

The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-23p4-xxgc-xqvf

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-23p4-qm9x-842q

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p4-5ppc-536p

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-23p3-vg9x-qw6p

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p3-vcf6-94xq

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-23p3-rx33-wm34

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p3-9m3p-qpwp

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-23p2-2jrp-5wcp

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-23mx-m43g-r4fh

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-23mw-hwq9-w4q8

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-23mr-m7vf-wgmp

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-23mr-c4wx-m5rr

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23mm-fp65-w636

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу