Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 405

Количество 300 405

github логотип

GHSA-23g3-82cg-4v75

больше 3 лет назад

Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: CMRO). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-23g2-f757-4428

12 дней назад

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. This issue affects Fireware OS: from 12.0 before 12.11.2.

EPSS: Низкий
github логотип

GHSA-23g2-95w8-rx32

больше 3 лет назад

An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allows a remote attacker to take full control of the device with a high-privileged account. By sending a crafted message, an attacker is able to remotely deliver a telnet session. Any attacker that has the ability to control DNS can exploit this vulnerability to remotely login to the device and gain access to the camera system.

EPSS: Низкий
github логотип

GHSA-23g2-8rfg-4ppg

больше 3 лет назад

Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

EPSS: Низкий
github логотип

GHSA-23g2-8hr8-76p4

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: Input: uinput - reject requests with unreasonable number of slots When exercising uinput interface syzkaller may try setting up device with a really large number of slots, which causes memory allocation failure in input_mt_init_slots(). While this allocation failure is handled properly and request is rejected, it results in syzkaller reports. Additionally, such request may put undue burden on the system which will try to free a lot of memory for a bogus request. Fix it by limiting allowed number of slots to 100. This can easily be extended if we see devices that can track more than 100 contacts.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23fx-r767-q5g7

10 месяцев назад

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23fx-92m6-4f2g

больше 2 лет назад

pretalx allows path traversal in HTML export

CVSS3: 4.3
EPSS: Высокий
github логотип

GHSA-23fw-5352-7h9v

около 1 года назад

Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23fv-pj9m-qvh4

почти 3 года назад

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23fv-m8pv-77j9

больше 3 лет назад

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23fr-29gc-hh5j

больше 3 лет назад

McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

EPSS: Низкий
github логотип

GHSA-23fq-q7hc-993r

около 4 лет назад

HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23fq-fj6g-jf68

больше 3 лет назад

IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

EPSS: Средний
github логотип

GHSA-23fq-26rx-3gc4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.

EPSS: Низкий
github логотип

GHSA-23fp-xqj8-q68w

больше 3 лет назад

SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

EPSS: Низкий
github логотип

GHSA-23fp-wmqj-rfh4

около 1 месяца назад

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_LT.ASP'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23fp-mrfv-cwv4

5 месяцев назад

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern.

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-23fp-mccx-jgj3

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23fp-fmrv-f5px

почти 4 года назад

Uncontrolled Resource Consumption in strapi

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-23fm-wgmf-mc43

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23g3-82cg-4v75

Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: CMRO). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 8.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-23g2-f757-4428

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. This issue affects Fireware OS: from 12.0 before 12.11.2.

0%
Низкий
12 дней назад
github логотип
GHSA-23g2-95w8-rx32

An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allows a remote attacker to take full control of the device with a high-privileged account. By sending a crafted message, an attacker is able to remotely deliver a telnet session. Any attacker that has the ability to control DNS can exploit this vulnerability to remotely login to the device and gain access to the camera system.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-23g2-8rfg-4ppg

Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23g2-8hr8-76p4

In the Linux kernel, the following vulnerability has been resolved: Input: uinput - reject requests with unreasonable number of slots When exercising uinput interface syzkaller may try setting up device with a really large number of slots, which causes memory allocation failure in input_mt_init_slots(). While this allocation failure is handled properly and request is rejected, it results in syzkaller reports. Additionally, such request may put undue burden on the system which will try to free a lot of memory for a bogus request. Fix it by limiting allowed number of slots to 100. This can easily be extended if we see devices that can track more than 100 contacts.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-23fx-r767-q5g7

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-23fx-92m6-4f2g

pretalx allows path traversal in HTML export

CVSS3: 4.3
74%
Высокий
больше 2 лет назад
github логотип
GHSA-23fw-5352-7h9v

Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant.

CVSS3: 7.5
8%
Низкий
около 1 года назад
github логотип
GHSA-23fv-pj9m-qvh4

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-23fv-m8pv-77j9

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23fr-29gc-hh5j

McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fq-q7hc-993r

HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0

CVSS3: 9.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-23fq-fj6g-jf68

IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

12%
Средний
больше 3 лет назад
github логотип
GHSA-23fq-26rx-3gc4

Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fp-xqj8-q68w

SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fp-wmqj-rfh4

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_LT.ASP'.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-23fp-mrfv-cwv4

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern.

CVSS3: 10
81%
Высокий
5 месяцев назад
github логотип
GHSA-23fp-mccx-jgj3

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fp-fmrv-f5px

Uncontrolled Resource Consumption in strapi

CVSS3: 4.9
1%
Низкий
почти 4 года назад
github логотип
GHSA-23fm-wgmf-mc43

Rejected reason: Not used

8 месяцев назад

Уязвимостей на страницу