Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2gxj-qrp2-53jv

около 4 лет назад

Incorrect reliance on Trait memory layout in mopa

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gxj-8gvj-cpww

больше 3 лет назад

Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gxh-75jp-99gc

больше 3 лет назад

Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.

EPSS: Низкий
github логотип

GHSA-2gxh-5pgf-vmgr

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2gxg-v6j4-qrcm

больше 3 лет назад

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.

EPSS: Низкий
github логотип

GHSA-2gxg-pvm2-2p6x

4 месяца назад

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

EPSS: Низкий
github логотип

GHSA-2gxf-v2x6-xmcm

около 2 лет назад

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2gxf-qq7x-x832

почти 3 года назад

A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2gxf-f3cr-5m3p

почти 4 года назад

Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.

EPSS: Низкий
github логотип

GHSA-2gxf-82cx-67jf

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

EPSS: Низкий
github логотип

GHSA-2gx9-pfxr-fgh5

больше 3 лет назад

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gx8-xhw2-36fx

больше 3 лет назад

HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gx8-cvf4-pwjh

больше 3 лет назад

A vulnerability has been identified in LOGO! Soft Comfort (All versions). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead to a takeover of the system where the software is installed.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2gx7-rx3r-f497

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gx6-qrpp-c4p3

около 1 года назад

Ant-Media-Server vulnerable to Improper Output Neutralization for Logs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gx6-jx5p-qgh2

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2gx6-hp98-v3j4

больше 3 лет назад

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gx5-q2jh-jjv8

почти 4 года назад

SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

EPSS: Низкий
github логотип

GHSA-2gx5-p7gf-5xrc

почти 4 года назад

Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2gx5-g66v-9rrc

почти 4 года назад

checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a running process.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gxj-qrp2-53jv

Incorrect reliance on Trait memory layout in mopa

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gxj-8gvj-cpww

Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gxh-75jp-99gc

Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gxh-5pgf-vmgr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2gxg-v6j4-qrcm

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gxg-pvm2-2p6x

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

1%
Низкий
4 месяца назад
github логотип
GHSA-2gxf-v2x6-xmcm

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2gxf-qq7x-x832

A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2gxf-f3cr-5m3p

Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2gxf-82cx-67jf

Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gx9-pfxr-fgh5

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gx8-xhw2-36fx

HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gx8-cvf4-pwjh

A vulnerability has been identified in LOGO! Soft Comfort (All versions). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead to a takeover of the system where the software is installed.

CVSS3: 8.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gx7-rx3r-f497

Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2gx6-qrpp-c4p3

Ant-Media-Server vulnerable to Improper Output Neutralization for Logs

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2gx6-jx5p-qgh2

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gx6-hp98-v3j4

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gx5-q2jh-jjv8

SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gx5-p7gf-5xrc

Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability.

CVSS3: 8.1
4%
Низкий
почти 4 года назад
github логотип
GHSA-2gx5-g66v-9rrc

checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a running process.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу