Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 341 844

Количество 341 844

github логотип

GHSA-32fm-h45j-grpv

9 месяцев назад

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32fm-h2hh-vxjg

почти 4 года назад

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthorized users may view or execute programs illegally.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32fj-r8qw-r8w8

около 2 лет назад

MindsDB Cross-site Scripting vulnerability

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-32fh-gwcr-7pmx

больше 4 лет назад

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-32fg-mvv7-ppfg

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32fg-cv9g-c28f

больше 4 лет назад

I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32fg-c88m-mcrv

7 месяцев назад

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-32ff-4g79-vgfc

около 4 лет назад

Flask-AppBuilder before v4.1.3 allows inference of sensitive information through query strings

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-32f9-rqvx-v6wh

больше 4 лет назад

Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-32f8-xfvp-9m45

4 месяца назад

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32f8-hmr3-7vxg

больше 2 лет назад

Azure Storage Movement Client Library Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32f7-x79r-fq9w

почти 4 года назад

The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32f7-fg59-hr8r

около 1 года назад

A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/completed-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-32f7-cmr3-vpjv

больше 7 лет назад

Moderate severity vulnerability that affects aioxmpp

EPSS: Низкий
github логотип

GHSA-32f6-jrx4-x77h

11 месяцев назад

Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32f3-8mjf-7qcp

6 месяцев назад

Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table names and sensitive information from the database.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-32f3-6f6j-9xc3

больше 4 лет назад

Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message.

EPSS: Низкий
github логотип

GHSA-32f2-v4v8-76vw

больше 4 лет назад

An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.

EPSS: Низкий
github логотип

GHSA-32f2-r7gj-x2hp

больше 4 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.

EPSS: Низкий
github логотип

GHSA-32f2-chgf-rf94

больше 4 лет назад

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32fm-h45j-grpv

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-32fm-h2hh-vxjg

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthorized users may view or execute programs illegally.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-32fj-r8qw-r8w8

MindsDB Cross-site Scripting vulnerability

CVSS3: 9
0%
Низкий
около 2 лет назад
github логотип
GHSA-32fh-gwcr-7pmx

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-32fg-mvv7-ppfg

Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-32fg-cv9g-c28f

I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-32fg-c88m-mcrv

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems.

CVSS3: 9.1
1%
Низкий
7 месяцев назад
github логотип
GHSA-32ff-4g79-vgfc

Flask-AppBuilder before v4.1.3 allows inference of sensitive information through query strings

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-32f9-rqvx-v6wh

Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-32f8-xfvp-9m45

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-32f8-hmr3-7vxg

Azure Storage Movement Client Library Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-32f7-x79r-fq9w

The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-32f7-fg59-hr8r

A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/completed-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-32f7-cmr3-vpjv

Moderate severity vulnerability that affects aioxmpp

больше 7 лет назад
github логотип
GHSA-32f6-jrx4-x77h

Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-32f3-8mjf-7qcp

Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table names and sensitive information from the database.

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-32f3-6f6j-9xc3

Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-32f2-v4v8-76vw

An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-32f2-r7gj-x2hp

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-32f2-chgf-rf94

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

CVSS3: 10
5%
Низкий
больше 4 лет назад

Уязвимостей на страницу