Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 632

Количество 325 632

github логотип

GHSA-2f29-629x-3r89

почти 4 года назад

An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.

EPSS: Низкий
github логотип

GHSA-2f28-fj6q-q44h

почти 4 года назад

Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.

EPSS: Низкий
github логотип

GHSA-2f28-f6j6-pc52

почти 4 года назад

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."

EPSS: Низкий
github логотип

GHSA-2f28-c6gf-w62p

больше 2 лет назад

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f28-7x9r-f2vq

10 месяцев назад

A missing protection against path traversal allows to access any file on the server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f28-69j7-85hf

8 месяцев назад

Easy!Appointments SQL injection vulnerability

EPSS: Низкий
github логотип

GHSA-2f28-6595-fhpf

почти 4 года назад

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f28-2fwm-699f

почти 4 года назад

The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.

EPSS: Низкий
github логотип

GHSA-2f26-8mf8-c9rf

почти 4 года назад

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.

EPSS: Низкий
github логотип

GHSA-2f25-w84f-mrg4

почти 4 года назад

The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL.

EPSS: Низкий
github логотип

GHSA-2f25-c9pg-f9fc

почти 4 года назад

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2f25-5j7h-v943

почти 4 года назад

A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.

EPSS: Низкий
github логотип

GHSA-2f24-xxx5-4354

10 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2f24-pwmq-42fq

почти 4 года назад

SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.

EPSS: Низкий
github логотип

GHSA-2f24-mg4x-534q

28 дней назад

TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2f24-2p7m-g432

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elliot Sowersby, RelyWP Coupon Affiliates allows Reflected XSS.This issue affects Coupon Affiliates: from n/a through 5.12.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2f23-9vw3-564h

больше 1 года назад

Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2f22-cxqh-52w2

около 3 лет назад

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240267890

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2f22-97gm-hw85

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section.

EPSS: Низкий
github логотип

GHSA-2f22-7m2c-fwgc

почти 4 года назад

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2f29-629x-3r89

An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f28-fj6q-q44h

Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2f28-f6j6-pc52

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."

1%
Низкий
почти 4 года назад
github логотип
GHSA-2f28-c6gf-w62p

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-2f28-7x9r-f2vq

A missing protection against path traversal allows to access any file on the server.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2f28-69j7-85hf

Easy!Appointments SQL injection vulnerability

0%
Низкий
8 месяцев назад
github логотип
GHSA-2f28-6595-fhpf

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2f28-2fwm-699f

The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f26-8mf8-c9rf

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2f25-w84f-mrg4

The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f25-c9pg-f9fc

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2f25-5j7h-v943

A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2f24-xxx5-4354

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2f24-pwmq-42fq

SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2f24-mg4x-534q

TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete

CVSS3: 8.4
0%
Низкий
28 дней назад
github логотип
GHSA-2f24-2p7m-g432

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elliot Sowersby, RelyWP Coupon Affiliates allows Reflected XSS.This issue affects Coupon Affiliates: from n/a through 5.12.7.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2f23-9vw3-564h

Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.

CVSS3: 8.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2f22-cxqh-52w2

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240267890

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2f22-97gm-hw85

Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f22-7m2c-fwgc

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

89%
Высокий
почти 4 года назад

Уязвимостей на страницу