Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4x38-3vm4-2pv5

около 1 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-4x37-wc67-gqjf

больше 4 лет назад

MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4x37-hw65-52w8

4 месяца назад

Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4x37-644q-76x6

2 месяца назад

Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4x37-5rh2-hp8c

около 8 лет назад

node-opencv is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4x36-p66f-4f99

больше 4 лет назад

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

EPSS: Низкий
github логотип

GHSA-4x35-vr82-xvj6

больше 3 лет назад

SQL Injection in AssetController

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4x35-v2c7-mwxv

больше 4 лет назад

Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.

EPSS: Средний
github логотип

GHSA-4x35-gq92-53gx

около 1 года назад

Insertion of Sensitive Information Into Sent Data vulnerability in Saeed Sattar Beglou Hesabfa Accounting allows Retrieve Embedded Sensitive Data. This issue affects Hesabfa Accounting: from n/a through 2.2.4.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4x35-7764-9cfw

больше 4 лет назад

UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.

EPSS: Низкий
github логотип

GHSA-4x34-x52v-9q9x

больше 4 лет назад

An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x34-w43g-2cfc

больше 4 лет назад

** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server. NOTE: the vendor states "This was a flaw for the developer/debugging devices, and was fixed in production version about 3 years ago."

EPSS: Низкий
github логотип

GHSA-4x34-chg5-mwjj

3 месяца назад

chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4x34-82r8-65cf

23 дня назад

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4x34-22jv-cj7q

больше 4 лет назад

PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.

EPSS: Низкий
github логотип

GHSA-4x33-wj73-4gxp

больше 4 лет назад

The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4x33-rw6q-ch5p

около 4 лет назад

Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x33-fm36-xfq9

больше 3 лет назад

Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x33-7vp7-cq3r

больше 4 лет назад

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x33-566w-9pg7

7 месяцев назад

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4x38-3vm4-2pv5

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 1 месяца назад
github логотип
GHSA-4x37-wc67-gqjf

MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4x37-hw65-52w8

Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4x37-644q-76x6

Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-4x37-5rh2-hp8c

node-opencv is malware

CVSS3: 7.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-4x36-p66f-4f99

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4x35-vr82-xvj6

SQL Injection in AssetController

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4x35-v2c7-mwxv

Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.

10%
Средний
больше 4 лет назад
github логотип
GHSA-4x35-gq92-53gx

Insertion of Sensitive Information Into Sent Data vulnerability in Saeed Sattar Beglou Hesabfa Accounting allows Retrieve Embedded Sensitive Data. This issue affects Hesabfa Accounting: from n/a through 2.2.4.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4x35-7764-9cfw

UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4x34-x52v-9q9x

An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x34-w43g-2cfc

** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server. NOTE: the vendor states "This was a flaw for the developer/debugging devices, and was fixed in production version about 3 years ago."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x34-chg5-mwjj

chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4x34-82r8-65cf

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.

CVSS3: 7.7
0%
Низкий
23 дня назад
github логотип
GHSA-4x34-22jv-cj7q

PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4x33-wj73-4gxp

The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4x33-rw6q-ch5p

Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4x33-fm36-xfq9

Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4x33-7vp7-cq3r

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x33-566w-9pg7

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.

CVSS3: 6.2
0%
Низкий
7 месяцев назад

Уязвимостей на страницу