Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4rjc-mr4g-cqp6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

EPSS: Низкий
github логотип

GHSA-4rjc-jcg6-mw6m

больше 4 лет назад

SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a tnews action.

EPSS: Низкий
github логотип

GHSA-4rjc-gpxw-9fr5

7 месяцев назад

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rjc-g85j-x387

19 дней назад

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4rjc-5c34-442m

больше 4 лет назад

Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.

EPSS: Низкий
github логотип

GHSA-4rj9-gmxf-4rcf

больше 2 лет назад

An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rj9-473r-rjfw

почти 2 года назад

Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rj8-p259-7652

больше 4 лет назад

Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4rj8-hc4w-2f6v

больше 4 лет назад

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-4rj7-cpc6-mqf7

12 месяцев назад

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an use of a Broken or Risky Cryptographic Algorithm vulnerability in the Authentication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rj7-74q2-rgpc

8 месяцев назад

A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rj6-vrwv-wr8m

около 2 месяцев назад

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

EPSS: Низкий
github логотип

GHSA-4rj6-rcx3-jvm9

больше 4 лет назад

A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of ARP packets received by the management interface of an affected device. An attacker could exploit this vulnerability by sending a series of unicast ARP packets in a short timeframe that would reach the management interface of an affected device. A successful exploit could allow the attacker to consume resources on an affected device, which would prevent the device from sending internal system keepalives and eventually cause the device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4rj6-jmxc-fw7q

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.

EPSS: Низкий
github логотип

GHSA-4rj6-gcf8-wchc

почти 4 года назад

A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rj6-9pjh-882r

больше 4 лет назад

Improper Restriction of XML External Entity Reference in Jenkins JUnit Plugin

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4rj6-94pr-r3h5

3 месяца назад

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4rj5-hv6x-v84g

больше 2 лет назад

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4rj5-2rf5-h49c

больше 4 лет назад

search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-4rj5-2227-9wgc

6 месяцев назад

Heap-based Buffer Overflow in JSON_SCHEMA_VALID()

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rjc-mr4g-cqp6

Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4rjc-jcg6-mw6m

SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a tnews action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rjc-gpxw-9fr5

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-4rjc-g85j-x387

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

CVSS3: 5.9
0%
Низкий
19 дней назад
github логотип
GHSA-4rjc-5c34-442m

Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj9-gmxf-4rcf

An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4rj9-473r-rjfw

Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4rj8-p259-7652

Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj8-hc4w-2f6v

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj7-cpc6-mqf7

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an use of a Broken or Risky Cryptographic Algorithm vulnerability in the Authentication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-4rj7-74q2-rgpc

A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-4rj6-vrwv-wr8m

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4rj6-rcx3-jvm9

A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect processing of ARP packets received by the management interface of an affected device. An attacker could exploit this vulnerability by sending a series of unicast ARP packets in a short timeframe that would reach the management interface of an affected device. A successful exploit could allow the attacker to consume resources on an affected device, which would prevent the device from sending internal system keepalives and eventually cause the device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj6-jmxc-fw7q

Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj6-gcf8-wchc

A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4rj6-9pjh-882r

Improper Restriction of XML External Entity Reference in Jenkins JUnit Plugin

CVSS3: 8.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj6-94pr-r3h5

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4rj5-hv6x-v84g

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4rj5-2rf5-h49c

search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj5-2227-9wgc

Heap-based Buffer Overflow in JSON_SCHEMA_VALID()

CVSS3: 8.5
1%
Низкий
6 месяцев назад

Уязвимостей на страницу