Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2j3g-p2x2-c94q

больше 2 лет назад

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2j3g-mmqf-22pf

больше 3 лет назад

vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.

EPSS: Низкий
github логотип

GHSA-2j3g-cq99-w5x4

почти 4 года назад

** DISPUTED ** PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected.

EPSS: Низкий
github логотип

GHSA-2j3g-9pf6-phh4

больше 2 лет назад

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j3f-mgwg-2gjh

больше 3 лет назад

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.

EPSS: Низкий
github логотип

GHSA-2j3f-gh3p-94vc

почти 4 года назад

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

EPSS: Высокий
github логотип

GHSA-2j3f-972q-6fv5

больше 3 лет назад

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j3f-2fhx-9r3x

почти 4 года назад

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

EPSS: Низкий
github логотип

GHSA-2j3c-m8j3-c8j2

больше 3 лет назад

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

EPSS: Низкий
github логотип

GHSA-2j3c-jv49-w6c7

больше 3 лет назад

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j39-qcjm-428w

около 2 лет назад

Apache Struts vulnerable to path traversal

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2j39-6c38-r3mx

больше 3 лет назад

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-2j39-64q5-rjfv

почти 4 года назад

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j38-xhmg-c3g9

больше 3 лет назад

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

EPSS: Средний
github логотип

GHSA-2j38-pmwm-2h3f

больше 3 лет назад

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

EPSS: Низкий
github логотип

GHSA-2j38-64p3-w8wc

5 месяцев назад

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2j38-53q9-crr9

больше 3 лет назад

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j37-h336-4w29

больше 3 лет назад

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

EPSS: Низкий
github логотип

GHSA-2j35-5wj8-vcv8

больше 3 лет назад

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j33-qvm8-55q5

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress allows Stored XSS. This issue affects VoucherPress: from n/a through 1.5.7.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j3g-p2x2-c94q

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

CVSS3: 9.8
92%
Критический
больше 2 лет назад
github логотип
GHSA-2j3g-mmqf-22pf

vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3g-cq99-w5x4

** DISPUTED ** PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2j3g-9pf6-phh4

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j3f-mgwg-2gjh

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3f-gh3p-94vc

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

71%
Высокий
почти 4 года назад
github логотип
GHSA-2j3f-972q-6fv5

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3f-2fhx-9r3x

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2j3c-m8j3-c8j2

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3c-jv49-w6c7

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j39-qcjm-428w

Apache Struts vulnerable to path traversal

CVSS3: 9.8
93%
Критический
около 2 лет назад
github логотип
GHSA-2j39-6c38-r3mx

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS3: 7.2
88%
Высокий
больше 3 лет назад
github логотип
GHSA-2j39-64q5-rjfv

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2j38-xhmg-c3g9

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

21%
Средний
больше 3 лет назад
github логотип
GHSA-2j38-pmwm-2h3f

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j38-64p3-w8wc

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2j38-53q9-crr9

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j37-h336-4w29

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

6%
Низкий
больше 3 лет назад
github логотип
GHSA-2j35-5wj8-vcv8

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j33-qvm8-55q5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress allows Stored XSS. This issue affects VoucherPress: from n/a through 1.5.7.

CVSS3: 5.9
0%
Низкий
5 месяцев назад

Уязвимостей на страницу