Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 185

Количество 326 185

github логотип

GHSA-2gxm-4cm6-2hf9

4 месяца назад

A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing manipulation of the argument keyWord results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2gxj-qrp2-53jv

больше 4 лет назад

Incorrect reliance on Trait memory layout in mopa

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gxj-8gvj-cpww

почти 4 года назад

Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gxh-75jp-99gc

почти 4 года назад

Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.

EPSS: Низкий
github логотип

GHSA-2gxh-5pgf-vmgr

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2gxg-v6j4-qrcm

почти 4 года назад

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.

EPSS: Низкий
github логотип

GHSA-2gxg-pvm2-2p6x

7 месяцев назад

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

EPSS: Низкий
github логотип

GHSA-2gxf-v2x6-xmcm

больше 2 лет назад

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2gxf-qq7x-x832

около 3 лет назад

A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2gxf-f3cr-5m3p

почти 4 года назад

Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.

EPSS: Низкий
github логотип

GHSA-2gxf-82cx-67jf

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

EPSS: Низкий
github логотип

GHSA-2gxf-3x35-2g93

9 дней назад

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the application.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2gx9-pfxr-fgh5

почти 4 года назад

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gx8-xhw2-36fx

почти 4 года назад

HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gx8-cvf4-pwjh

почти 4 года назад

A vulnerability has been identified in LOGO! Soft Comfort (All versions). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead to a takeover of the system where the software is installed.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2gx7-rx3r-f497

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gx6-qrpp-c4p3

больше 1 года назад

Ant-Media-Server vulnerable to Improper Output Neutralization for Logs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gx6-jx5p-qgh2

почти 4 года назад

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2gx6-hp98-v3j4

почти 4 года назад

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gx5-q2jh-jjv8

почти 4 года назад

SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gxm-4cm6-2hf9

A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing manipulation of the argument keyWord results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-2gxj-qrp2-53jv

Incorrect reliance on Trait memory layout in mopa

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2gxj-8gvj-cpww

Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gxh-75jp-99gc

Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gxh-5pgf-vmgr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2gxg-v6j4-qrcm

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gxg-pvm2-2p6x

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

2%
Низкий
7 месяцев назад
github логотип
GHSA-2gxf-v2x6-xmcm

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2gxf-qq7x-x832

A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2gxf-f3cr-5m3p

Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2gxf-82cx-67jf

Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gxf-3x35-2g93

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the application.

CVSS3: 6.2
0%
Низкий
9 дней назад
github логотип
GHSA-2gx9-pfxr-fgh5

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gx8-xhw2-36fx

HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gx8-cvf4-pwjh

A vulnerability has been identified in LOGO! Soft Comfort (All versions). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead to a takeover of the system where the software is installed.

CVSS3: 8.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gx7-rx3r-f497

Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2gx6-qrpp-c4p3

Ant-Media-Server vulnerable to Improper Output Neutralization for Logs

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gx6-jx5p-qgh2

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gx6-hp98-v3j4

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gx5-q2jh-jjv8

SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу