Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-236q-7g5g-vj7x

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-236p-gvjj-h5mq

почти 4 года назад

A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-236p-442f-j636

около 1 месяца назад

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-236p-2rjr-h84v

почти 4 года назад

Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."

EPSS: Низкий
github логотип

GHSA-236p-2grx-xqc3

больше 2 лет назад

Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-236j-rfx5-wq38

больше 3 лет назад

OpenCart SQL injection vulnerability

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-236h-rqv8-8q73

больше 5 лет назад

GraphQL: Security breach on Viewer query

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-236h-r3w7-c85c

больше 3 лет назад

Cross-site Scripting in Apache Atlas

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-236h-5c6c-jrfx

больше 3 лет назад

userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-236g-v823-mwh3

больше 1 года назад

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236g-r9c7-hmw7

больше 3 лет назад

Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-236g-7xc8-897f

почти 4 года назад

Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."

EPSS: Низкий
github логотип

GHSA-236g-4rjq-c23m

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-236f-wx7r-xqwv

почти 4 года назад

eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.

EPSS: Низкий
github логотип

GHSA-236f-m6gm-vp93

около 1 года назад

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-236f-jwrv-vrp5

около 3 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd_generic.lua plugin for the xupnpd service, which listens on TCP port 4044 by default. When parsing the feed parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15906.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236c-vhj4-gfxg

больше 3 лет назад

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236c-rp7g-fqf2

больше 3 лет назад

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

EPSS: Низкий
github логотип

GHSA-236c-jvm7-g9g6

больше 3 лет назад

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-236c-586c-7q48

6 месяцев назад

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-236q-7g5g-vj7x

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-236p-gvjj-h5mq

A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-236p-442f-j636

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-236p-2rjr-h84v

Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."

7%
Низкий
почти 4 года назад
github логотип
GHSA-236p-2grx-xqc3

Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-236j-rfx5-wq38

OpenCart SQL injection vulnerability

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-236h-rqv8-8q73

GraphQL: Security breach on Viewer query

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-236h-r3w7-c85c

Cross-site Scripting in Apache Atlas

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-236h-5c6c-jrfx

userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-236g-v823-mwh3

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-236g-r9c7-hmw7

Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-236g-7xc8-897f

Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."

1%
Низкий
почти 4 года назад
github логотип
GHSA-236g-4rjq-c23m

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-236f-wx7r-xqwv

eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-236f-m6gm-vp93

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-236f-jwrv-vrp5

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd_generic.lua plugin for the xupnpd service, which listens on TCP port 4044 by default. When parsing the feed parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-15906.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-236c-vhj4-gfxg

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-236c-rp7g-fqf2

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-236c-jvm7-g9g6

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-236c-586c-7q48

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
0%
Низкий
6 месяцев назад

Уязвимостей на страницу