Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w5x-gxff-8vr4

почти 4 года назад

A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w5x-gf9f-6rv2

больше 4 лет назад

Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w5x-6pmj-4m2q

больше 4 лет назад

NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.

EPSS: Низкий
github логотип

GHSA-4w5w-mw5m-24wp

13 дней назад

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w5w-4fhm-q483

3 месяца назад

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4w5w-4c66-6rx9

больше 4 лет назад

SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leading to Information Disclosure.

EPSS: Низкий
github логотип

GHSA-4w5v-j6gh-h3v3

почти 3 года назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4w5r-xgqv-25rr

больше 4 лет назад

Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-4w5r-2wjg-hq97

больше 4 лет назад

Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-4w5q-x8gv-qmwx

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4w5q-r88j-fm53

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w5q-gccf-crf5

больше 4 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

EPSS: Низкий
github логотип

GHSA-4w5p-qwh4-xc23

больше 1 года назад

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w5p-p8f5-x7m9

около 1 месяца назад

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w5p-7c62-6g92

больше 3 лет назад

A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-4w5m-vg96-g85c

больше 4 лет назад

Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

EPSS: Низкий
github логотип

GHSA-4w5m-3w7v-8phf

больше 4 лет назад

An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.

EPSS: Низкий
github логотип

GHSA-4w5j-fgfj-644h

больше 4 лет назад

Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.

EPSS: Низкий
github логотип

GHSA-4w5j-8ww7-64rx

больше 4 лет назад

Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.

EPSS: Низкий
github логотип

GHSA-4w5h-pwr8-qh64

больше 4 лет назад

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w5x-gxff-8vr4

A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-4w5x-gf9f-6rv2

Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5x-6pmj-4m2q

NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5w-mw5m-24wp

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

CVSS3: 7.5
0%
Низкий
13 дней назад
github логотип
GHSA-4w5w-4fhm-q483

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

CVSS3: 5.5
1%
Низкий
3 месяца назад
github логотип
GHSA-4w5w-4c66-6rx9

SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leading to Information Disclosure.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5v-j6gh-h3v3

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4w5r-xgqv-25rr

Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.

CVSS3: 7.2
59%
Средний
больше 4 лет назад
github логотип
GHSA-4w5r-2wjg-hq97

Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5q-x8gv-qmwx

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.

CVSS3: 7.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4w5q-r88j-fm53

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-4w5q-gccf-crf5

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5p-qwh4-xc23

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4w5p-p8f5-x7m9

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4w5p-7c62-6g92

A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

CVSS3: 3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4w5m-vg96-g85c

Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5m-3w7v-8phf

An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5j-fgfj-644h

Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5j-8ww7-64rx

Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4w5h-pwr8-qh64

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу