Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-28q2-r9rp-jg2h

почти 4 года назад

Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.

EPSS: Низкий
github логотип

GHSA-28q2-9f7f-9rrv

10 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28q2-45j8-5c44

почти 4 года назад

Unspecified vulnerability in the Oracle Text component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to CTXSYS.DRVDISP.

EPSS: Низкий
github логотип

GHSA-28q2-24p4-9j92

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection.This issue affects Yordam Library Automation System: from 21.5 & 21.6 before 21.7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28px-j7x8-c96q

4 месяца назад

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28px-82cg-wrw5

почти 4 года назад

PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter.

EPSS: Низкий
github логотип

GHSA-28pw-f2p6-x4fr

почти 4 года назад

Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username or (3) Password.

EPSS: Низкий
github логотип

GHSA-28pw-7j9h-792w

почти 4 года назад

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-28pw-27gw-65v8

больше 1 года назад

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 allows authenticated user to read files

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28pv-xxcq-fr89

около 3 лет назад

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28pv-f4g7-364j

6 месяцев назад

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthorized access in applications that rely on python-jose for token validation. This issue is exploitable unless developers explicitly reject 'alg=none' tokens, which is not enforced by the library.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28pv-2j2h-fmhc

почти 4 года назад

TeamPass Cross-Site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28pp-6j97-mmc8

больше 1 года назад

IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-28pp-675x-rf35

больше 1 года назад

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28pm-frw8-mr59

около 2 лет назад

SQL injection vulnerability exists in GetDIAE_slogListParameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28pm-98wm-6937

почти 4 года назад

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.

EPSS: Низкий
github логотип

GHSA-28pj-7rwg-vxrf

около 1 месяца назад

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28ph-pmjh-gwg9

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yooslider Yoo Slider allows Reflected XSS.This issue affects Yoo Slider: from n/a through 2.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-28ph-f7gx-fqj8

больше 4 лет назад

Data races in rusqlite

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28ph-8qph-7chx

около 4 лет назад

An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28q2-r9rp-jg2h

Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-28q2-9f7f-9rrv

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-28q2-45j8-5c44

Unspecified vulnerability in the Oracle Text component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to CTXSYS.DRVDISP.

1%
Низкий
почти 4 года назад
github логотип
GHSA-28q2-24p4-9j92

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection.This issue affects Yordam Library Automation System: from 21.5 & 21.6 before 21.7.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-28px-j7x8-c96q

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-28px-82cg-wrw5

PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_dir parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-28pw-f2p6-x4fr

Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username or (3) Password.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28pw-7j9h-792w

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

2%
Низкий
почти 4 года назад
github логотип
GHSA-28pw-27gw-65v8

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 allows authenticated user to read files

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-28pv-xxcq-fr89

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-28pv-f4g7-364j

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthorized access in applications that rely on python-jose for token validation. This issue is exploitable unless developers explicitly reject 'alg=none' tokens, which is not enforced by the library.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-28pv-2j2h-fmhc

TeamPass Cross-Site Scripting (XSS)

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-28pp-6j97-mmc8

IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-28pp-675x-rf35

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-28pm-frw8-mr59

SQL injection vulnerability exists in GetDIAE_slogListParameters.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-28pm-98wm-6937

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28pj-7rwg-vxrf

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-28ph-pmjh-gwg9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yooslider Yoo Slider allows Reflected XSS.This issue affects Yoo Slider: from n/a through 2.1.1.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-28ph-f7gx-fqj8

Data races in rusqlite

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-28ph-8qph-7chx

An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.

CVSS3: 7.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу