Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 694

Количество 306 694

github логотип

GHSA-24r9-p447-gxg2

больше 3 лет назад

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

EPSS: Низкий
github логотип

GHSA-24r9-8wx9-6g9f

больше 1 года назад

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r8-jmfh-r268

почти 3 года назад

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24r8-fm9r-cpj2

около 6 лет назад

Low severity vulnerability that affects com.linecorp.armeria:armeria

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-24r7-x8mx-hc2h

почти 4 года назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r7-c5r6-xxmj

больше 3 лет назад

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Средний
github логотип

GHSA-24r6-29j2-hrjv

больше 3 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

EPSS: Низкий
github логотип

GHSA-24r5-xw2j-9h9x

около 2 лет назад

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24r3-rx3r-wgvw

больше 1 года назад

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24r3-qrv6-6jx6

больше 3 лет назад

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-24r2-2rf2-whfq

8 месяцев назад

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24qx-986r-jvf4

больше 3 лет назад

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qw-g5w5-55fm

больше 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-24qw-797r-8hmj

больше 3 лет назад

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24qv-pghr-gg8x

больше 3 лет назад

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

EPSS: Низкий
github логотип

GHSA-24qv-j57w-wmcf

5 месяцев назад

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-24qv-68gq-r7hr

больше 3 лет назад

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

EPSS: Низкий
github логотип

GHSA-24qv-6795-29jh

больше 3 лет назад

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24qq-8vc9-wp3m

больше 1 года назад

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-24qp-pvw9-442x

больше 3 лет назад

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24r9-p447-gxg2

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24r9-8wx9-6g9f

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVSS3: 9.8
66%
Средний
больше 1 года назад
github логотип
GHSA-24r8-jmfh-r268

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-24r8-fm9r-cpj2

Low severity vulnerability that affects com.linecorp.armeria:armeria

CVSS3: 4.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-24r7-x8mx-hc2h

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
22%
Средний
почти 4 года назад
github логотип
GHSA-24r7-c5r6-xxmj

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

13%
Средний
больше 3 лет назад
github логотип
GHSA-24r6-29j2-hrjv

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

4%
Низкий
больше 3 лет назад
github логотип
GHSA-24r5-xw2j-9h9x

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-24r3-rx3r-wgvw

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-24r3-qrv6-6jx6

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

23%
Средний
больше 3 лет назад
github логотип
GHSA-24r2-2rf2-whfq

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-24qx-986r-jvf4

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24qw-g5w5-55fm

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
21%
Средний
больше 3 лет назад
github логотип
GHSA-24qw-797r-8hmj

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24qv-pghr-gg8x

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-24qv-j57w-wmcf

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-24qv-68gq-r7hr

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24qv-6795-29jh

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24qq-8vc9-wp3m

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-24qp-pvw9-442x

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

10%
Средний
больше 3 лет назад

Уязвимостей на страницу