Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4gfg-qwj4-89qg

больше 4 лет назад

SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.

EPSS: Низкий
github логотип

GHSA-4gfg-32rq-7753

больше 4 лет назад

SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter.

EPSS: Низкий
github логотип

GHSA-4gff-x4ff-9qq7

почти 2 года назад

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request.  The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4gff-g5qg-73wc

около 2 месяцев назад

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-4gff-fjgq-76g6

около 3 лет назад

User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4gfc-72gw-v385

почти 3 года назад

Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4gf9-gwj2-w3rx

больше 4 лет назад

An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4gf9-6xwj-3w66

больше 4 лет назад

Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.

EPSS: Низкий
github логотип

GHSA-4gf8-cwcf-3hph

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Motacek ICS Button allows Stored XSS.This issue affects ICS Button: from n/a through 0.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4gf7-m762-7xq9

больше 4 лет назад

IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4gf7-ff8x-hq99

больше 1 года назад

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4gf7-cp73-grc5

больше 4 лет назад

Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4gf7-49hm-67v5

больше 4 лет назад

Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters.

EPSS: Низкий
github логотип

GHSA-4gf6-p85h-2wcf

9 месяцев назад

A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4gf4-qjr3-ppxj

больше 4 лет назад

Windows Geolocation Service Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4gf4-mg8f-6224

почти 4 года назад

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4gf4-5fpq-6cwc

больше 4 лет назад

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4gf4-55f6-hq4x

больше 4 лет назад

SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.

EPSS: Низкий
github логотип

GHSA-4gf2-xv97-63m2

почти 5 лет назад

Exposure of Sensitive Information in keycloak

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-4gf2-6j5v-x6gv

больше 4 лет назад

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4gfg-qwj4-89qg

SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gfg-32rq-7753

SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gff-x4ff-9qq7

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request.  The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-4gff-g5qg-73wc

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4gff-fjgq-76g6

User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-4gfc-72gw-v385

Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-4gf9-gwj2-w3rx

An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf9-6xwj-3w66

Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf8-cwcf-3hph

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Motacek ICS Button allows Stored XSS.This issue affects ICS Button: from n/a through 0.6.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4gf7-m762-7xq9

IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf7-ff8x-hq99

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4gf7-cp73-grc5

Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf7-49hm-67v5

Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf6-p85h-2wcf

A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 8.8
3%
Низкий
9 месяцев назад
github логотип
GHSA-4gf4-qjr3-ppxj

Windows Geolocation Service Remote Code Execution Vulnerability.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf4-mg8f-6224

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

CVSS3: 9.8
65%
Средний
почти 4 года назад
github логотип
GHSA-4gf4-5fpq-6cwc

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf4-55f6-hq4x

SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4gf2-xv97-63m2

Exposure of Sensitive Information in keycloak

CVSS3: 5.6
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4gf2-6j5v-x6gv

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

80%
Высокий
больше 4 лет назад

Уязвимостей на страницу