Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2gmf-964r-8w6g

около 3 лет назад

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gm9-vfwg-p8x2

больше 3 лет назад

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gm9-phpp-rvm3

больше 1 года назад

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gm9-mv2m-44mx

больше 3 лет назад

SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gm8-jj36-c9vw

около 4 лет назад

Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.

EPSS: Низкий
github логотип

GHSA-2gm7-4g69-r63q

больше 3 лет назад

A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2gm6-qg2v-w98r

больше 3 лет назад

The 7-ELEVEN (aka ecowork.seven) application 2.08.000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2gm6-cf3j-36f9

3 месяца назад

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'rp_save_property_settings' function in versions 0.1 to 0.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gm5-h3fj-mwv3

почти 4 года назад

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

EPSS: Низкий
github логотип

GHSA-2gm5-2gjp-759h

больше 3 лет назад

Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.

EPSS: Низкий
github логотип

GHSA-2gm3-gg3v-jmmf

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

EPSS: Низкий
github логотип

GHSA-2gjx-c22x-h568

больше 3 лет назад

The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.

EPSS: Средний
github логотип

GHSA-2gjv-8mpf-hmgr

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider - Slider for your block editor allows Stored XSS.This issue affects B Slider - Slider for your block editor: from n/a through 1.1.12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gjq-ggr9-9f3w

около 2 лет назад

Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the right shift operation.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2gjq-7pvc-8hj3

больше 1 года назад

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it possible for unauthenticated attackers to update an API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2gjq-2933-hpjg

11 месяцев назад

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2gjp-pxq3-jj7r

почти 4 года назад

Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.

EPSS: Низкий
github логотип

GHSA-2gjm-hvmq-383v

больше 3 лет назад

dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gjj-x74c-fh87

почти 4 года назад

recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.

EPSS: Низкий
github логотип

GHSA-2gjj-cf6j-4c9p

больше 3 лет назад

SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gmf-964r-8w6g

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 210323.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-2gm9-vfwg-p8x2

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gm9-phpp-rvm3

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2gm9-mv2m-44mx

SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2gm8-jj36-c9vw

Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2gm7-4g69-r63q

A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gm6-qg2v-w98r

The 7-ELEVEN (aka ecowork.seven) application 2.08.000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gm6-cf3j-36f9

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'rp_save_property_settings' function in versions 0.1 to 0.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2gm5-h3fj-mwv3

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2gm5-2gjp-759h

Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-2gm3-gg3v-jmmf

Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gjx-c22x-h568

The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.

57%
Средний
больше 3 лет назад
github логотип
GHSA-2gjv-8mpf-hmgr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider - Slider for your block editor allows Stored XSS.This issue affects B Slider - Slider for your block editor: from n/a through 1.1.12.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2gjq-ggr9-9f3w

Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the right shift operation.

CVSS3: 7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2gjq-7pvc-8hj3

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it possible for unauthenticated attackers to update an API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gjq-2933-hpjg

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

CVSS3: 2.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-2gjp-pxq3-jj7r

Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gjm-hvmq-383v

dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gjj-x74c-fh87

recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gjj-cf6j-4c9p

SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу