Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2j4p-2hc9-62f4

почти 3 года назад

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j4j-cgfm-hpg2

почти 4 года назад

SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

EPSS: Низкий
github логотип

GHSA-2j4h-qfp4-82q7

почти 4 года назад

Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

EPSS: Высокий
github логотип

GHSA-2j4h-p58q-g7mp

больше 3 лет назад

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.

EPSS: Низкий
github логотип

GHSA-2j4h-mgwq-9x58

больше 3 лет назад

The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.

EPSS: Низкий
github логотип

GHSA-2j4h-cjgh-659v

больше 3 лет назад

Reflected XSS vulnerability in Jenkins VncViewer Plugin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j4h-89r3-h3f3

почти 4 года назад

The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

EPSS: Низкий
github логотип

GHSA-2j4h-4639-xjfj

9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2j4g-v4fv-rhwg

почти 2 года назад

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-2j4g-q4pc-fmcw

больше 3 лет назад

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j4g-7q2x-6pmv

больше 3 лет назад

Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Install - Configuration). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j4f-52m8-xq9h

почти 3 года назад

The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j4c-pqxj-mfqh

почти 4 года назад

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j4c-9qqq-896r

5 месяцев назад

web3-core-method is vulnerable to prototype pollution

EPSS: Низкий
github логотип

GHSA-2j4c-6m6h-f5hg

почти 4 года назад

suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

EPSS: Низкий
github логотип

GHSA-2j4c-4vw2-9r77

больше 3 лет назад

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j49-q898-whm9

больше 3 лет назад

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2j49-6mmc-22jj

больше 3 лет назад

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2j49-4qxc-q53v

больше 3 лет назад

Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2j49-3cqv-33p2

почти 4 года назад

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j4p-2hc9-62f4

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2j4j-cgfm-hpg2

SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2j4h-qfp4-82q7

Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

80%
Высокий
почти 4 года назад
github логотип
GHSA-2j4h-p58q-g7mp

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4h-mgwq-9x58

The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4h-cjgh-659v

Reflected XSS vulnerability in Jenkins VncViewer Plugin

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4h-89r3-h3f3

The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2j4h-4639-xjfj

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2j4g-v4fv-rhwg

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability

CVSS3: 7.2
87%
Высокий
почти 2 года назад
github логотип
GHSA-2j4g-q4pc-fmcw

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4g-7q2x-6pmv

Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Install - Configuration). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4f-52m8-xq9h

The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2j4c-pqxj-mfqh

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2j4c-9qqq-896r

web3-core-method is vulnerable to prototype pollution

0%
Низкий
5 месяцев назад
github логотип
GHSA-2j4c-6m6h-f5hg

suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2j4c-4vw2-9r77

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-q898-whm9

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-6mmc-22jj

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-4qxc-q53v

Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-3cqv-33p2

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу