Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v38-rxj3-wf34

больше 4 лет назад

SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.

EPSS: Низкий
github логотип

GHSA-4v38-964c-xjmw

больше 3 лет назад

Code injection via unescaped translations in xwiki-platform

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-4v38-4r78-53pv

больше 4 лет назад

Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.

EPSS: Средний
github логотип

GHSA-4v37-24gm-h554

больше 4 лет назад

Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4v36-9pjv-6h63

больше 4 лет назад

The New Beginnings CFC (aka com.goodbarber.nbcfc) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4v36-7w47-pxwg

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ip: Fix data-races around sysctl_ip_fwd_update_priority. While reading sysctl_ip_fwd_update_priority, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4v36-769x-7cpq

больше 4 лет назад

cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v35-rh24-xvq6

больше 4 лет назад

The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v35-78jc-648r

2 месяца назад

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

EPSS: Низкий
github логотип

GHSA-4v35-68f6-rfpq

больше 2 лет назад

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4v34-q2vw-9m7j

больше 4 лет назад

Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v34-gm3m-8x92

больше 4 лет назад

groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4v34-9x49-p452

около 3 лет назад

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4v32-vrp2-28jp

около 1 месяца назад

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4v32-6xw7-c96f

около 1 года назад

The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session checks), an unauthenticated attacker can use that parameter to execute arbitrary OS commands.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v2x-jqm6-7wqw

11 месяцев назад

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v2w-h9jm-mqjg

почти 6 лет назад

Prototype Pollution in systeminformation

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4v2w-2wqp-mc85

3 месяца назад

OpenAM OAuth Authorization Bypass via PKCE Challenge

EPSS: Низкий
github логотип

GHSA-4v2v-p6m7-q4jj

больше 4 лет назад

MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4v2v-7w44-wqvx

больше 4 лет назад

IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v38-rxj3-wf34

SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v38-964c-xjmw

Code injection via unescaped translations in xwiki-platform

CVSS3: 9.9
2%
Низкий
больше 3 лет назад
github логотип
GHSA-4v38-4r78-53pv

Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.

12%
Средний
больше 4 лет назад
github логотип
GHSA-4v37-24gm-h554

Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v36-9pjv-6h63

The New Beginnings CFC (aka com.goodbarber.nbcfc) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v36-7w47-pxwg

In the Linux kernel, the following vulnerability has been resolved: ip: Fix data-races around sysctl_ip_fwd_update_priority. While reading sysctl_ip_fwd_update_priority, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v36-769x-7cpq

cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v35-rh24-xvq6

The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v35-78jc-648r

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

2 месяца назад
github логотип
GHSA-4v35-68f6-rfpq

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4v34-q2vw-9m7j

Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v34-gm3m-8x92

groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v34-9x49-p452

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVSS3: 7.8
28%
Средний
около 3 лет назад
github логотип
GHSA-4v32-vrp2-28jp

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4v32-6xw7-c96f

The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session checks), an unauthenticated attacker can use that parameter to execute arbitrary OS commands.

CVSS3: 6.5
6%
Низкий
около 1 года назад
github логотип
GHSA-4v2x-jqm6-7wqw

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-4v2w-h9jm-mqjg

Prototype Pollution in systeminformation

CVSS3: 8.1
2%
Низкий
почти 6 лет назад
github логотип
GHSA-4v2w-2wqp-mc85

OpenAM OAuth Authorization Bypass via PKCE Challenge

0%
Низкий
3 месяца назад
github логотип
GHSA-4v2v-p6m7-q4jj

MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v2v-7w44-wqvx

IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу