Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-4jhm-crx9-7qmm

больше 4 лет назад

Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.08, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to OLAPSYS.CWM2_OLAP_AW_AWUTIL, a different vulnerability than CVE-2008-3991.

EPSS: Низкий
github логотип

GHSA-4jhm-9928-rqx4

3 месяца назад

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4jhm-5f7g-75fp

больше 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Jenkins

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4jhj-rw84-72pf

11 месяцев назад

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read access. Exploitation of this issue does not require user interaction.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4jhj-g9wr-f89q

больше 2 лет назад

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52329.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jhj-88x4-5xw5

больше 1 года назад

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /ajax.php?action=save_member. The manipulation of the argument umember_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4jhj-3gv3-c3gr

больше 2 лет назад

CLI for Vela Insecure Variable Substitution

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4jhh-wmhx-r4j7

больше 4 лет назад

The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.

EPSS: Низкий
github логотип

GHSA-4jhh-v38r-h7q8

2 месяца назад

Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4jhh-q54m-vmvv

почти 3 года назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4jhg-wfq8-3vgm

больше 4 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

EPSS: Низкий
github логотип

GHSA-4jhg-h526-7c6c

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Stored XSS.This issue affects All In One Redirection: from n/a through 2.2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4jhg-2qv9-4jqw

больше 4 лет назад

VNC server on the AK-Systems Windows Terminal 1.2.5 ExVLP is not password protected, which allows remote attackers to login and view RDP or Citrix sessions.

EPSS: Низкий
github логотип

GHSA-4jhf-wc6q-v8gq

больше 4 лет назад

index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.

EPSS: Низкий
github логотип

GHSA-4jhf-jqwp-72jc

около 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Assaf Parag Poll, Survey & Quiz Maker Plugin by Opinion Stage allows PHP Local File Inclusion. This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through 19.11.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4jhf-c33f-vgvg

больше 4 лет назад

Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jhc-wjr3-pwh2

больше 4 лет назад

An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4jhc-h5c6-rr3m

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4jhc-354h-v589

больше 4 лет назад

channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel.

EPSS: Низкий
github логотип

GHSA-4jh9-8gvv-965j

больше 4 лет назад

The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jhm-crx9-7qmm

Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.08, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to OLAPSYS.CWM2_OLAP_AW_AWUTIL, a different vulnerability than CVE-2008-3991.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhm-9928-rqx4

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4jhm-5f7g-75fp

Improper Limitation of a Pathname to a Restricted Directory in Jenkins

CVSS3: 8.2
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhj-rw84-72pf

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read access. Exploitation of this issue does not require user interaction.

CVSS3: 5.3
11 месяцев назад
github логотип
GHSA-4jhj-g9wr-f89q

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52329.

CVSS3: 6.1
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4jhj-88x4-5xw5

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /ajax.php?action=save_member. The manipulation of the argument umember_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4jhj-3gv3-c3gr

CLI for Vela Insecure Variable Substitution

CVSS3: 7.7
больше 2 лет назад
github логотип
GHSA-4jhh-wmhx-r4j7

The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhh-v38r-h7q8

Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4jhh-q54m-vmvv

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-4jhg-wfq8-3vgm

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhg-h526-7c6c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Stored XSS.This issue affects All In One Redirection: from n/a through 2.2.0.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4jhg-2qv9-4jqw

VNC server on the AK-Systems Windows Terminal 1.2.5 ExVLP is not password protected, which allows remote attackers to login and view RDP or Citrix sessions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhf-wc6q-v8gq

index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhf-jqwp-72jc

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Assaf Parag Poll, Survey & Quiz Maker Plugin by Opinion Stage allows PHP Local File Inclusion. This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through 19.11.0.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4jhf-c33f-vgvg

Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhc-wjr3-pwh2

An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhc-h5c6-rr3m

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jhc-354h-v589

channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh9-8gvv-965j

The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу