Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-28wv-5cj3-9qg6

почти 2 года назад

SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28wv-3g38-px4r

почти 4 года назад

The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-28wv-3f44-9j22

около 3 лет назад

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28wr-vmq3-227j

8 месяцев назад

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-28wr-h897-6hmv

около 1 года назад

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28wq-pxv7-mr7m

почти 4 года назад

In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-28wq-p9hh-3w4h

почти 4 года назад

Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-28wp-2xch-xmx5

почти 4 года назад

The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.

EPSS: Низкий
github логотип

GHSA-28wh-pr48-2cq7

25 дней назад

iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-28wh-2mp5-4gp8

больше 1 года назад

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28wg-r79p-3484

почти 4 года назад

Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.

EPSS: Низкий
github логотип

GHSA-28wg-8gv4-mpjf

больше 2 лет назад

Broken access control in Silverpeas

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-28wg-555g-fr2v

почти 4 года назад

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28wf-q2m6-rjgv

10 месяцев назад

Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-28wf-jx5m-6fhg

больше 2 лет назад

An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28wf-973p-g3gx

около 4 лет назад

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

EPSS: Низкий
github логотип

GHSA-28wc-7mwv-p5h3

почти 4 года назад

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28w9-vf5c-mw9p

почти 4 года назад

E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

EPSS: Низкий
github логотип

GHSA-28w9-qhgf-j4rh

8 месяцев назад

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28w9-f394-mqfw

почти 4 года назад

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28wv-5cj3-9qg6

SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.

CVSS3: 8.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-28wv-3g38-px4r

The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-28wv-3f44-9j22

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-28wr-vmq3-227j

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-28wr-h897-6hmv

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-28wq-pxv7-mr7m

In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.

CVSS3: 7.5
15%
Средний
почти 4 года назад
github логотип
GHSA-28wq-p9hh-3w4h

Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-28wp-2xch-xmx5

The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28wh-pr48-2cq7

iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information.

CVSS3: 8.2
0%
Низкий
25 дней назад
github логотип
GHSA-28wh-2mp5-4gp8

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-28wg-r79p-3484

Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28wg-8gv4-mpjf

Broken access control in Silverpeas

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28wg-555g-fr2v

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-28wf-q2m6-rjgv

Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-28wf-jx5m-6fhg

An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28wf-973p-g3gx

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

0%
Низкий
около 4 лет назад
github логотип
GHSA-28wc-7mwv-p5h3

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-28w9-vf5c-mw9p

E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28w9-qhgf-j4rh

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-28w9-f394-mqfw

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

8%
Низкий
почти 4 года назад

Уязвимостей на страницу