Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4vf7-8qf6-f3f9

больше 3 лет назад

A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site scripting. The attack can be initiated remotely. The name of the patch is fb6fae2f8a9b146471450b5b0281046a17d1ac8d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-220204.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vf6-mq7w-3hp6

больше 2 лет назад

Zend_Filter_StripTags vulnerable to Cross-site Scripting when comments allowed

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vf6-j45c-9rc5

больше 4 лет назад

The Horoscopes and Dreams (aka com.horoscopesanddreams) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4vf6-f9c7-q6rp

2 месяца назад

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vf6-2rmx-fgqx

больше 2 лет назад

Gila CMS SQL Injection vulnerability

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-4vf6-2fhm-2c5g

больше 4 лет назад

Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.

EPSS: Низкий
github логотип

GHSA-4vf5-wq63-5f76

больше 4 лет назад

Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

EPSS: Низкий
github логотип

GHSA-4vf5-v3wq-vqr9

больше 4 лет назад

Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4vf4-qmvg-mh7h

больше 4 лет назад

Cookie Prefix Spoofing in CGI::Cookie.parse

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vf4-9x77-q598

больше 4 лет назад

Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.

EPSS: Низкий
github логотип

GHSA-4vf4-955g-vxp2

почти 4 года назад

OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-4vf3-h7wh-ppjc

больше 4 лет назад

A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4vf3-fc4g-3xvj

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4vf3-57vh-hmm8

почти 3 года назад

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data as well as unauthorized read access to a subset of Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4vf2-qfg3-7598

больше 2 лет назад

symfony/validator XML Entity Expansion vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vf2-hvg4-5qq2

3 месяца назад

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vf2-cm23-rf4c

больше 4 лет назад

Incorrect Authorization in Jenkins Gerrit Trigger Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4vf2-4xcg-65cx

больше 5 лет назад

Division by 0 in `Conv2D`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-4vcx-3pj3-44m7

11 месяцев назад

Dosage vulnerable to a Directory Traversal through crafted HTTP responses

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vcw-h879-447q

26 дней назад

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vf7-8qf6-f3f9

A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site scripting. The attack can be initiated remotely. The name of the patch is fb6fae2f8a9b146471450b5b0281046a17d1ac8d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-220204.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4vf6-mq7w-3hp6

Zend_Filter_StripTags vulnerable to Cross-site Scripting when comments allowed

CVSS3: 6.1
больше 2 лет назад
github логотип
GHSA-4vf6-j45c-9rc5

The Horoscopes and Dreams (aka com.horoscopesanddreams) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf6-f9c7-q6rp

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4vf6-2rmx-fgqx

Gila CMS SQL Injection vulnerability

CVSS3: 3.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vf6-2fhm-2c5g

Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf5-wq63-5f76

Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf5-v3wq-vqr9

Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

CVSS3: 9.8
92%
Критический
больше 4 лет назад
github логотип
GHSA-4vf4-qmvg-mh7h

Cookie Prefix Spoofing in CGI::Cookie.parse

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf4-9x77-q598

Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf4-955g-vxp2

OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration

CVSS3: 6.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-4vf3-h7wh-ppjc

A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf3-fc4g-3xvj

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-4vf3-57vh-hmm8

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data as well as unauthorized read access to a subset of Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-4vf2-qfg3-7598

symfony/validator XML Entity Expansion vulnerability

CVSS3: 7.5
больше 2 лет назад
github логотип
GHSA-4vf2-hvg4-5qq2

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4vf2-cm23-rf4c

Incorrect Authorization in Jenkins Gerrit Trigger Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vf2-4xcg-65cx

Division by 0 in `Conv2D`

CVSS3: 2.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-4vcx-3pj3-44m7

Dosage vulnerable to a Directory Traversal through crafted HTTP responses

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-4vcw-h879-447q

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

CVSS3: 8.6
0%
Низкий
26 дней назад

Уязвимостей на страницу