Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-26v6-h3rv-wj58

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26v6-42cg-wj34

около 4 лет назад

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

EPSS: Низкий
github логотип

GHSA-26v6-3ggr-9jj5

больше 3 лет назад

Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

EPSS: Средний
github логотип

GHSA-26v5-wxrq-v623

больше 3 лет назад

Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-26v5-q2r5-7mv2

больше 3 лет назад

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-26v4-wj6c-25pg

больше 3 лет назад

In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-26v4-vq66-h2r9

больше 3 лет назад

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Memory Corruption Vulnerability."

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-26v4-7jhr-3827

почти 3 года назад

A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221732.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26v4-76jx-c7r4

больше 3 лет назад

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26v4-3ghx-vmrv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26v2-rqv8-w34m

больше 3 лет назад

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.

EPSS: Низкий
github логотип

GHSA-26v2-hwwj-jjg2

почти 4 года назад

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-26v2-gx3h-2xg7

почти 4 года назад

Multiple directory traversal vulnerabilities in PHPBuilder 0.0.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) lib/htm2php.php and (2) sitetools/htm2php.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-26rx-x3cw-r9p9

почти 4 года назад

Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.

EPSS: Низкий
github логотип

GHSA-26rx-wm6q-f3g4

больше 2 лет назад

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26rx-w6fm-4p9v

4 месяца назад

Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low-privilege user to elevate privileges within the application. This issue affects Flipper: 3.1.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26rx-mmh7-vvg6

почти 4 года назад

Havalite CMS 1.1.7 has a stored XSS vulnerability

EPSS: Низкий
github логотип

GHSA-26rw-w7w7-gjpm

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DZS Ajaxer Lite allows Stored XSS. This issue affects DZS Ajaxer Lite: from n/a through 1.04.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26rw-chjx-9xgj

больше 3 лет назад

A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

EPSS: Низкий
github логотип

GHSA-26rw-7v38-gcgj

больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A local attacker may be able to elevate their privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26v6-h3rv-wj58

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 .

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26v6-42cg-wj34

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

3%
Низкий
около 4 лет назад
github логотип
GHSA-26v6-3ggr-9jj5

Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

61%
Средний
больше 3 лет назад
github логотип
GHSA-26v5-wxrq-v623

Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v5-q2r5-7mv2

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.

CVSS3: 7.2
4%
Низкий
больше 3 лет назад
github логотип
GHSA-26v4-wj6c-25pg

In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v4-vq66-h2r9

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Memory Corruption Vulnerability."

CVSS3: 7.8
20%
Средний
больше 3 лет назад
github логотип
GHSA-26v4-7jhr-3827

A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221732.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-26v4-76jx-c7r4

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v4-3ghx-vmrv

Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v2-rqv8-w34m

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26v2-hwwj-jjg2

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.

CVSS3: 8.8
36%
Средний
почти 4 года назад
github логотип
GHSA-26v2-gx3h-2xg7

Multiple directory traversal vulnerabilities in PHPBuilder 0.0.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) lib/htm2php.php and (2) sitetools/htm2php.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26rx-x3cw-r9p9

Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26rx-wm6q-f3g4

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26rx-w6fm-4p9v

Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low-privilege user to elevate privileges within the application. This issue affects Flipper: 3.1.2.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-26rx-mmh7-vvg6

Havalite CMS 1.1.7 has a stored XSS vulnerability

0%
Низкий
почти 4 года назад
github логотип
GHSA-26rw-w7w7-gjpm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DZS Ajaxer Lite allows Stored XSS. This issue affects DZS Ajaxer Lite: from n/a through 1.04.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-26rw-chjx-9xgj

A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26rw-7v38-gcgj

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A local attacker may be able to elevate their privileges.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу