Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 049

Количество 313 049

github логотип

GHSA-23p9-49c6-fm5w

больше 3 лет назад

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

EPSS: Низкий
github логотип

GHSA-23p7-2cxv-3gpw

10 месяцев назад

A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23p6-m374-wpr8

почти 4 года назад

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23p6-gh9w-qhrf

почти 4 года назад

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

EPSS: Низкий
github логотип

GHSA-23p5-23pm-xvp3

больше 1 года назад

The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-23p4-xxgc-xqvf

около 2 лет назад

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-23p4-qm9x-842q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23p4-5ppc-536p

почти 4 года назад

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

EPSS: Низкий
github логотип

GHSA-23p3-vg9x-qw6p

больше 3 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

EPSS: Низкий
github логотип

GHSA-23p3-vcf6-94xq

больше 2 лет назад

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23p3-rx33-wm34

больше 3 лет назад

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

EPSS: Низкий
github логотип

GHSA-23p3-9m3p-qpwp

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23p2-2jrp-5wcp

больше 1 года назад

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23mx-m43g-r4fh

8 месяцев назад

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-23mw-hwq9-w4q8

больше 2 лет назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mr-m7vf-wgmp

больше 3 лет назад

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-23mr-c4wx-m5rr

больше 3 лет назад

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23mm-fp65-w636

больше 2 лет назад

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23mm-62vv-wv83

больше 3 лет назад

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-23mj-f5f2-4h46

около 1 года назад

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23p9-49c6-fm5w

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23p7-2cxv-3gpw

A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-23p6-m374-wpr8

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-23p6-gh9w-qhrf

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

1%
Низкий
почти 4 года назад
github логотип
GHSA-23p5-23pm-xvp3

The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-23p4-xxgc-xqvf

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-23p4-qm9x-842q

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p4-5ppc-536p

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

2%
Низкий
почти 4 года назад
github логотип
GHSA-23p3-vg9x-qw6p

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p3-vcf6-94xq

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23p3-rx33-wm34

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23p3-9m3p-qpwp

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-23p2-2jrp-5wcp

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-23mx-m43g-r4fh

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-23mw-hwq9-w4q8

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23mr-m7vf-wgmp

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-23mr-c4wx-m5rr

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23mm-fp65-w636

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23mm-62vv-wv83

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
86%
Высокий
больше 3 лет назад
github логотип
GHSA-23mj-f5f2-4h46

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу