Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-2928-6w5x-9xm3

почти 4 года назад

i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2927-hv3p-f3vp

почти 4 года назад

Open redirect in caddy

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2926-f789-68jv

14 дней назад

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2924-xwpv-8gcj

почти 4 года назад

IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2924-mp4r-x286

почти 4 года назад

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2924-9cv7-3gpq

почти 4 года назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.

EPSS: Низкий
github логотип

GHSA-2924-22w3-7pm7

почти 4 года назад

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.

EPSS: Низкий
github логотип

GHSA-2923-vx22-37wp

3 месяца назад

Memory corruption while passing pages to DSP with an unaligned starting address.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2923-cx8w-xvxh

почти 4 года назад

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

EPSS: Низкий
github логотип

GHSA-28xx-8j99-m32j

больше 5 лет назад

Malicious Package in nginxbeautifier

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28xx-6gh9-8gp4

почти 4 года назад

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Средний
github логотип

GHSA-28xx-46x6-h92x

около 2 лет назад

A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-28xw-m7jp-89ch

почти 4 года назад

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28xv-h724-wvrh

около 1 года назад

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28xv-77rw-c8pr

почти 4 года назад

NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.

EPSS: Низкий
github логотип

GHSA-28xr-x3rf-rhgr

почти 4 года назад

A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

EPSS: Низкий
github логотип

GHSA-28xr-rgjv-2mgp

около 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Средний
github логотип

GHSA-28xr-mwxg-3qc8

около 4 лет назад

Command injection in simple-git

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28xq-f23c-p68m

11 месяцев назад

Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28xq-93rr-jp78

почти 4 года назад

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2928-6w5x-9xm3

i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2927-hv3p-f3vp

Open redirect in caddy

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2926-f789-68jv

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

CVSS3: 9.1
0%
Низкий
14 дней назад
github логотип
GHSA-2924-xwpv-8gcj

IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2924-mp4r-x286

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2924-9cv7-3gpq

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2924-22w3-7pm7

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.

8%
Низкий
почти 4 года назад
github логотип
GHSA-2923-vx22-37wp

Memory corruption while passing pages to DSP with an unaligned starting address.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2923-cx8w-xvxh

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

6%
Низкий
почти 4 года назад
github логотип
GHSA-28xx-8j99-m32j

Malicious Package in nginxbeautifier

CVSS3: 9.8
больше 5 лет назад
github логотип
GHSA-28xx-6gh9-8gp4

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

21%
Средний
почти 4 года назад
github логотип
GHSA-28xx-46x6-h92x

A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-28xw-m7jp-89ch

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-28xv-h724-wvrh

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-28xv-77rw-c8pr

NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.

1%
Низкий
почти 4 года назад
github логотип
GHSA-28xr-x3rf-rhgr

A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28xr-rgjv-2mgp

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
49%
Средний
около 3 лет назад
github логотип
GHSA-28xr-mwxg-3qc8

Command injection in simple-git

CVSS3: 8.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-28xq-f23c-p68m

Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-28xq-93rr-jp78

EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.

CVSS3: 9.8
8%
Низкий
почти 4 года назад

Уязвимостей на страницу