Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c2h-jfwm-5f64

почти 4 года назад

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157110.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2c2h-2855-mf97

около 1 года назад

Apache Camel: Camel Message Header Injection via Improper Filtering

EPSS: Средний
github логотип

GHSA-2c2g-g7mc-jv23

почти 4 года назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.

EPSS: Низкий
github логотип

GHSA-2c2c-vqcm-ccr6

почти 4 года назад

Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c2c-mqw3-8m8q

почти 4 года назад

translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

EPSS: Низкий
github логотип

GHSA-2c2c-jmpq-rphg

почти 4 года назад

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c29-wc65-4cx9

почти 4 года назад

linux-cmdline is vulnerable to Prototype Pollution via the constructor

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c29-h3hm-8953

около 3 лет назад

A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.1, 7.0.0 through 7.0.7, 2.0.0 through 2.0.10, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 may allow an authenticated and remote attacker to perform an HTTP request splitting attack which gives attackers control of the remaining headers and body of the response.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2c29-84m2-9q27

почти 4 года назад

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715.

EPSS: Низкий
github логотип

GHSA-2c28-wpp9-3fwq

больше 2 лет назад

Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c28-m2m7-mf55

больше 2 лет назад

Pleroma Path Traversal vulnerability

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-2c28-f73p-mgcc

почти 4 года назад

A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2c28-7gwv-cpgf

почти 4 года назад

Mediawiki tarball is missing .htaccess files

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c27-grr5-3w2g

почти 4 года назад

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-2c27-5cx3-qcjh

почти 4 года назад

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.

EPSS: Низкий
github логотип

GHSA-2c25-xfpq-8w9r

больше 4 лет назад

Cross-site scripting in jfinal

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2c24-v83q-9pwp

10 месяцев назад

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c24-m9rj-gq8m

больше 3 лет назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c24-45x7-qrmp

почти 4 года назад

SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.

EPSS: Низкий
github логотип

GHSA-2c22-7f4c-fw6q

почти 4 года назад

Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c2h-jfwm-5f64

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157110.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c2h-2855-mf97

Apache Camel: Camel Message Header Injection via Improper Filtering

48%
Средний
около 1 года назад
github логотип
GHSA-2c2g-g7mc-jv23

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c2c-vqcm-ccr6

Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-2c2c-mqw3-8m8q

translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c2c-jmpq-rphg

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c29-wc65-4cx9

linux-cmdline is vulnerable to Prototype Pollution via the constructor

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-2c29-h3hm-8953

A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.1, 7.0.0 through 7.0.7, 2.0.0 through 2.0.10, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 may allow an authenticated and remote attacker to perform an HTTP request splitting attack which gives attackers control of the remaining headers and body of the response.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-2c29-84m2-9q27

IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c28-wpp9-3fwq

Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2c28-m2m7-mf55

Pleroma Path Traversal vulnerability

CVSS3: 2.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2c28-f73p-mgcc

A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c28-7gwv-cpgf

Mediawiki tarball is missing .htaccess files

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c27-grr5-3w2g

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

CVSS3: 8.8
87%
Высокий
почти 4 года назад
github логотип
GHSA-2c27-5cx3-qcjh

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c25-xfpq-8w9r

Cross-site scripting in jfinal

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2c24-v83q-9pwp

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2c24-m9rj-gq8m

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c24-45x7-qrmp

SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c22-7f4c-fw6q

Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.

7%
Низкий
почти 4 года назад

Уязвимостей на страницу