Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-29c2-jq97-8pp8

почти 4 года назад

tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29c2-7qg3-7c74

около 1 месяца назад

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29c2-6v7h-58vc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.

EPSS: Низкий
github логотип

GHSA-29c2-65rj-h343

около 2 лет назад

Nervos CKB Permit load cell data from memory

EPSS: Низкий
github логотип

GHSA-299x-crmv-p4vf

почти 4 года назад

Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-299w-wrq3-r3wf

больше 3 лет назад

Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

EPSS: Низкий
github логотип

GHSA-299w-p965-fx3w

10 месяцев назад

A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affects some unknown processing of the component Login. The manipulation of the argument Str1 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-299w-hrvh-ccqx

почти 4 года назад

Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-299w-8x68-px6h

9 месяцев назад

Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-299v-fghf-v92x

больше 1 года назад

A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file edit_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268868.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-299v-6gmm-7q85

почти 4 года назад

Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-299r-wvhm-rv9x

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771.

EPSS: Низкий
github логотип

GHSA-299r-q2gj-44gj

больше 2 лет назад

The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-299r-j638-g338

больше 3 лет назад

A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the internal network of the device. The vulnerability is due to an incorrect firewall rule on the device. The misconfiguration could allow traffic sent to the public interface of the device to be forwarded to the internal virtual network of the APIC-EM. An attacker that is logically adjacent to the network on which the public interface of the affected APIC-EM resides could leverage this behavior to gain access to services listening on the internal network with elevated privileges. This vulnerability affects appliances or virtual devices running Cisco Application Policy Infrastructure Controller Enterprise Module prior to version 1.5. Cisco Bug IDs: CSCve89638.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-299q-fv2g-6cv8

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Site Table of Contents allows Stored XSS. This issue affects Site Table of Contents: from n/a through 0.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-299q-4mvc-qfhj

больше 3 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.

EPSS: Низкий
github логотип

GHSA-299q-3p96-5898

почти 2 года назад

Apache Superset Incorrect Authorization vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-299q-28qj-ch6v

больше 3 лет назад

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

EPSS: Низкий
github логотип

GHSA-299p-3cm6-p6fg

больше 1 года назад

Uncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-299m-fx62-r98p

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29c2-jq97-8pp8

tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-29c2-7qg3-7c74

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-29c2-6v7h-58vc

Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29c2-65rj-h343

Nervos CKB Permit load cell data from memory

около 2 лет назад
github логотип
GHSA-299x-crmv-p4vf

Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-299w-wrq3-r3wf

Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-299w-p965-fx3w

A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affects some unknown processing of the component Login. The manipulation of the argument Str1 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-299w-hrvh-ccqx

Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."

56%
Средний
почти 4 года назад
github логотип
GHSA-299w-8x68-px6h

Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS3: 6.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-299v-fghf-v92x

A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file edit_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268868.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-299v-6gmm-7q85

Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-299r-wvhm-rv9x

Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-299r-q2gj-44gj

The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-299r-j638-g338

A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the internal network of the device. The vulnerability is due to an incorrect firewall rule on the device. The misconfiguration could allow traffic sent to the public interface of the device to be forwarded to the internal virtual network of the APIC-EM. An attacker that is logically adjacent to the network on which the public interface of the affected APIC-EM resides could leverage this behavior to gain access to services listening on the internal network with elevated privileges. This vulnerability affects appliances or virtual devices running Cisco Application Policy Infrastructure Controller Enterprise Module prior to version 1.5. Cisco Bug IDs: CSCve89638.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-299q-fv2g-6cv8

Cross-Site Request Forgery (CSRF) vulnerability in Site Table of Contents allows Stored XSS. This issue affects Site Table of Contents: from n/a through 0.3.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-299q-4mvc-qfhj

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-299q-3p96-5898

Apache Superset Incorrect Authorization vulnerability

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-299q-28qj-ch6v

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-299p-3cm6-p6fg

Uncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-299m-fx62-r98p

Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу