Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c45-fqp9-5vw6

почти 4 года назад

Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

EPSS: Низкий
github логотип

GHSA-2c45-cjxr-vcxq

больше 1 года назад

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /kortex_lite/control/edit_profile.php of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2c44-v444-62h2

больше 2 лет назад

User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c44-c825-pqp7

больше 2 лет назад

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c42-f2qj-vh3h

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2c42-4jvc-gq6p

почти 4 года назад

The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.

EPSS: Низкий
github логотип

GHSA-2c3x-rrq4-j7xg

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ironfit ironfit allows PHP Local File Inclusion.This issue affects Ironfit: from n/a through <= 1.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2c3x-qj3p-24h2

почти 4 года назад

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118492282

EPSS: Низкий
github логотип

GHSA-2c3x-jq52-4hfg

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c3x-j794-4c74

почти 4 года назад

Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.

EPSS: Низкий
github логотип

GHSA-2c3w-hjxh-5rqg

почти 4 года назад

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.

EPSS: Низкий
github логотип

GHSA-2c3v-6gcr-6f8h

около 2 лет назад

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c3r-p6wr-mq42

3 месяца назад

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2c3r-m2jh-rjmh

около 1 года назад

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2c3p-p5cx-vpxj

почти 4 года назад

SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2c3p-p4pf-5q6h

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri allows PHP Local File Inclusion. This issue affects Indutri: from n/a through n/a.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2c3p-9j5f-33g3

почти 4 года назад

Apache OpenMeetings responds to insecure HTTP methods

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c3p-6xp9-52hq

около 4 лет назад

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c3m-gh26-vh52

больше 3 лет назад

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c3m-f6hh-4v8q

почти 4 года назад

A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or reload an affected device.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c45-fqp9-5vw6

Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c45-cjxr-vcxq

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /kortex_lite/control/edit_profile.php of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c44-v444-62h2

User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c44-c825-pqp7

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c42-f2qj-vh3h

Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c42-4jvc-gq6p

The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c3x-rrq4-j7xg

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ironfit ironfit allows PHP Local File Inclusion.This issue affects Ironfit: from n/a through <= 1.5.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2c3x-qj3p-24h2

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118492282

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c3x-jq52-4hfg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2c3x-j794-4c74

Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c3w-hjxh-5rqg

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c3v-6gcr-6f8h

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c3r-p6wr-mq42

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame

CVSS3: 7.4
0%
Низкий
3 месяца назад
github логотип
GHSA-2c3r-m2jh-rjmh

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2c3p-p5cx-vpxj

SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary code via unspecified vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c3p-p4pf-5q6h

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri allows PHP Local File Inclusion. This issue affects Indutri: from n/a through n/a.

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-2c3p-9j5f-33g3

Apache OpenMeetings responds to insecure HTTP methods

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c3p-6xp9-52hq

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2c3m-gh26-vh52

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2c3m-f6hh-4v8q

A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or reload an affected device.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу