Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-24r6-29j2-hrjv

почти 4 года назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

EPSS: Низкий
github логотип

GHSA-24r5-xw2j-9h9x

около 2 лет назад

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24r3-rx3r-wgvw

больше 1 года назад

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24r3-qrv6-6jx6

больше 3 лет назад

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-24r2-2rf2-whfq

9 месяцев назад

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24qx-986r-jvf4

больше 3 лет назад

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qw-g5w5-55fm

больше 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-24qw-797r-8hmj

больше 3 лет назад

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24qv-pghr-gg8x

почти 4 года назад

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

EPSS: Низкий
github логотип

GHSA-24qv-j57w-wmcf

6 месяцев назад

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-24qv-68gq-r7hr

почти 4 года назад

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

EPSS: Низкий
github логотип

GHSA-24qv-6795-29jh

больше 3 лет назад

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24qq-8vc9-wp3m

больше 1 года назад

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-24qp-pvw9-442x

больше 3 лет назад

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

EPSS: Средний
github логотип

GHSA-24qp-4xx8-3jvj

11 месяцев назад

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

CVSS3: 3.2
EPSS: Низкий
github логотип

GHSA-24qm-h8fv-cv5c

больше 3 лет назад

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qh-qr2h-95xw

почти 4 года назад

Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24qh-92m3-q3jj

8 месяцев назад

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-24qh-5jcc-qhqq

почти 4 года назад

The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

EPSS: Средний
github логотип

GHSA-24qg-x6r4-72m5

почти 4 года назад

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24r6-29j2-hrjv

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

4%
Низкий
почти 4 года назад
github логотип
GHSA-24r5-xw2j-9h9x

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-24r3-rx3r-wgvw

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-24r3-qrv6-6jx6

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

23%
Средний
больше 3 лет назад
github логотип
GHSA-24r2-2rf2-whfq

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-24qx-986r-jvf4

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24qw-g5w5-55fm

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
21%
Средний
больше 3 лет назад
github логотип
GHSA-24qw-797r-8hmj

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24qv-pghr-gg8x

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-24qv-j57w-wmcf

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-24qv-68gq-r7hr

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

0%
Низкий
почти 4 года назад
github логотип
GHSA-24qv-6795-29jh

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24qq-8vc9-wp3m

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
3%
Низкий
больше 1 года назад
github логотип
GHSA-24qp-pvw9-442x

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

10%
Средний
больше 3 лет назад
github логотип
GHSA-24qp-4xx8-3jvj

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

CVSS3: 3.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-24qm-h8fv-cv5c

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24qh-qr2h-95xw

Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-24qh-92m3-q3jj

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-24qh-5jcc-qhqq

The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

15%
Средний
почти 4 года назад
github логотип
GHSA-24qg-x6r4-72m5

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.

30%
Средний
почти 4 года назад

Уязвимостей на страницу