Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v9x-cqc5-j645

5 месяцев назад

Codechecker has an authentication bypass for certain API calls

EPSS: Низкий
github логотип

GHSA-4v9w-wpw8-v5mc

около 1 месяца назад

A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v9w-q9gr-w477

больше 4 лет назад

Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v9w-pvwr-38h3

больше 4 лет назад

OS Command Injection in strong-nginx-controller

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4v9w-chqg-3pgp

больше 2 лет назад

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obtained by dumping the process memory and parsing it.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v9v-p32w-h449

больше 4 лет назад

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32658595. References: QC-CR#1103099.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4v9v-hfq4-rm2v

больше 1 года назад

webpack-dev-server users' source code may be stolen when they access a malicious web site

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4v9v-4x57-7wc8

около 1 года назад

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-subscription.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4v9r-hr3m-4m95

больше 4 лет назад

Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted argument.

EPSS: Низкий
github логотип

GHSA-4v9q-rjxq-3952

больше 4 лет назад

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

EPSS: Низкий
github логотип

GHSA-4v9q-rfjv-2646

8 месяцев назад

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v9q-p283-qc2m

5 дней назад

Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4v9q-hm2p-68c4

около 6 лет назад

Spoofing attack due to unvalidated KDC in node-krb5

EPSS: Низкий
github логотип

GHSA-4v9q-cgpw-cf38

больше 4 лет назад

Multiple evaluation of contract address in call in vyper

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v9q-9vcj-g43w

больше 4 лет назад

A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v9q-9v9j-rwrc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT Related Posts With Thumb Image After Posts allows Stored XSS. This issue affects IGIT Related Posts With Thumb Image After Posts: from n/a through 4.5.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v9q-5fxh-7fph

2 месяца назад

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Costing Transaction Errors). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v9p-8xxf-6hpj

больше 4 лет назад

Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

EPSS: Средний
github логотип

GHSA-4v9p-4wgj-v3f6

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-4v9p-4hw8-6h36

больше 1 года назад

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affects an unknown part of the file /view_drive.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v9x-cqc5-j645

Codechecker has an authentication bypass for certain API calls

0%
Низкий
5 месяцев назад
github логотип
GHSA-4v9w-wpw8-v5mc

A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4v9w-q9gr-w477

Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9w-pvwr-38h3

OS Command Injection in strong-nginx-controller

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9w-chqg-3pgp

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obtained by dumping the process memory and parsing it.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4v9v-p32w-h449

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32658595. References: QC-CR#1103099.

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9v-hfq4-rm2v

webpack-dev-server users' source code may be stolen when they access a malicious web site

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4v9v-4x57-7wc8

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-subscription.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4v9r-hr3m-4m95

Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted argument.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9q-rjxq-3952

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9q-rfjv-2646

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4v9q-p283-qc2m

Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

CVSS3: 5.9
0%
Низкий
5 дней назад
github логотип
GHSA-4v9q-hm2p-68c4

Spoofing attack due to unvalidated KDC in node-krb5

около 6 лет назад
github логотип
GHSA-4v9q-cgpw-cf38

Multiple evaluation of contract address in call in vyper

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9q-9vcj-g43w

A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9q-9v9j-rwrc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT Related Posts With Thumb Image After Posts allows Stored XSS. This issue affects IGIT Related Posts With Thumb Image After Posts: from n/a through 4.5.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v9q-5fxh-7fph

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Costing Transaction Errors). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4v9p-8xxf-6hpj

Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

23%
Средний
больше 4 лет назад
github логотип
GHSA-4v9p-4wgj-v3f6

An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9p-4hw8-6h36

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affects an unknown part of the file /view_drive.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад

Уязвимостей на страницу