Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52vr-h4mx-5468

больше 4 лет назад

The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.

EPSS: Низкий
github логотип

GHSA-52vq-vh7q-45mc

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.

EPSS: Низкий
github логотип

GHSA-52vq-78w6-2cp5

больше 4 лет назад

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-52vp-j58h-c47p

больше 4 лет назад

Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php.

EPSS: Низкий
github логотип

GHSA-52vm-mxx8-f227

3 месяца назад

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-52vm-8f6x-7r3p

около 2 лет назад

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-52vj-mr2j-f8jh

больше 4 лет назад

Server-Side Template Injection in formio

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52vj-mgh7-f6r4

больше 4 лет назад

A password for accessing a WWW URL is guessable.

EPSS: Низкий
github логотип

GHSA-52vj-fvrv-7q82

6 месяцев назад

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-52vj-cjhg-wpwv

больше 4 лет назад

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.

EPSS: Низкий
github логотип

GHSA-52vj-8j6v-c3r7

больше 4 лет назад

suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52vj-66ff-3q3r

больше 4 лет назад

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

EPSS: Низкий
github логотип

GHSA-52vj-29px-76m7

больше 4 лет назад

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-52vg-wv9p-8vc3

больше 4 лет назад

Paint 3D Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31946, CVE-2021-31983.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52vf-xjg9-pg5p

2 месяца назад

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-52vf-jcf5-9pjc

около 1 месяца назад

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-52vf-hvv3-98h7

больше 3 лет назад

xwiki vulnerable to Improper Handling of Exceptional Conditions

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52vc-rjmg-f24r

больше 4 лет назад

Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data. CVSS v3.0 Base Score 4.3 (Integrity impacts).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-52vc-m88w-prhq

больше 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel Zones.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-52vc-cwqw-grg3

больше 4 лет назад

The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing functions (the rfc2047 function in mbox.c). An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. This action could cause a buffer overflow condition when ClamAV scans the malicious email, allowing the attacker to potentially cause a DoS condition on an affected device.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52vr-h4mx-5468

The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52vq-vh7q-45mc

Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vq-78w6-2cp5

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vp-j58h-c47p

Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vm-mxx8-f227

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

CVSS3: 7.7
3 месяца назад
github логотип
GHSA-52vm-8f6x-7r3p

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-52vj-mr2j-f8jh

Server-Side Template Injection in formio

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vj-mgh7-f6r4

A password for accessing a WWW URL is guessable.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vj-fvrv-7q82

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

CVSS3: 5.6
1%
Низкий
6 месяцев назад
github логотип
GHSA-52vj-cjhg-wpwv

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-52vj-8j6v-c3r7

suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52vj-66ff-3q3r

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52vj-29px-76m7

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

CVSS3: 7.5
25%
Средний
больше 4 лет назад
github логотип
GHSA-52vg-wv9p-8vc3

Paint 3D Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31946, CVE-2021-31983.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vf-xjg9-pg5p

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-52vf-jcf5-9pjc

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-52vf-hvv3-98h7

xwiki vulnerable to Improper Handling of Exceptional Conditions

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-52vc-rjmg-f24r

Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data. CVSS v3.0 Base Score 4.3 (Integrity impacts).

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vc-m88w-prhq

Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel Zones.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52vc-cwqw-grg3

The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing functions (the rfc2047 function in mbox.c). An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. This action could cause a buffer overflow condition when ClamAV scans the malicious email, allowing the attacker to potentially cause a DoS condition on an affected device.

CVSS3: 7.5
6%
Низкий
больше 4 лет назад

Уязвимостей на страницу