Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cc2-ww2m-x787

больше 4 лет назад

Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.

EPSS: Низкий
github логотип

GHSA-4cc2-g9w2-fhf6

3 месяца назад

Zeep: Server-Side Request Forgery (SSRF)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4cc2-25hc-9x3v

больше 4 лет назад

A Windows NT local user or administrator account has a default, null, blank, or missing password.

EPSS: Средний
github логотип

GHSA-4c9x-vhq3-f96q

больше 4 лет назад

An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to the use of an invalid pointer copy, resulting from a destructed string object.

EPSS: Низкий
github логотип

GHSA-4c9x-rrqj-4c82

больше 3 лет назад

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c9x-pr4f-c2j8

больше 4 лет назад

Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Interfaces). Supported versions that are affected are 10.2.x, 11.0.x, 12.0.x,12.1.x, 12.1.1.x,12.1.2.x and 13.1.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Retail-J. While the vulnerability is in MICROS Retail-J, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MICROS Retail-J accessible data. CVSS 3.0 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4c9x-jxrc-66h6

около 1 года назад

A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The manipulation of the argument profile name leads to cross site scripting. The attack may be launched remotely.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-4c9x-hwrm-39j5

больше 4 лет назад

Integer overflow in the jpc_pi_nextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified impact via a crafted file, which triggers use of an uninitialized value.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4c9w-mv22-7x5q

больше 2 лет назад

Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Product for WooCommerce: from n/a through 4.4.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4c9w-55qf-23v6

больше 4 лет назад

Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.

EPSS: Низкий
github логотип

GHSA-4c9v-w245-3ch6

больше 4 лет назад

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4c9v-rqpw-wrj7

около 1 года назад

Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4c9r-w43c-8v76

около 2 лет назад

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4c9r-p2x5-3f3m

около 1 года назад

Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the target server.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4c9r-jxqx-6hxv

2 месяца назад

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4c9r-fcrv-f86f

больше 4 лет назад

Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4c9q-86fx-4cv8

5 месяцев назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4c9q-7835-998j

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: libwx: properly reset Rx ring descriptor When device reset is triggered by feature changes such as toggling Rx VLAN offload, wx->do_reset() is called to reinitialize Rx rings. The hardware descriptor ring may retain stale values from previous sessions. And only set the length to 0 in rx_desc[0] would result in building malformed SKBs. Fix it to ensure a clean slate after device reset. [ 549.186435] [ C16] ------------[ cut here ]------------ [ 549.186457] [ C16] kernel BUG at net/core/skbuff.c:2814! [ 549.186468] [ C16] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 549.186472] [ C16] CPU: 16 UID: 0 PID: 0 Comm: swapper/16 Kdump: loaded Not tainted 6.16.0-rc4+ #23 PREEMPT(voluntary) [ 549.186476] [ C16] Hardware name: Micro-Star International Co., Ltd. MS-7E16/X670E GAMING PLUS WIFI (MS-7E16), BIOS 1.90 12/31/2024 [ 549.186478] [ C16] RIP: 0010:__pskb_pull_tail+0x3ff/0x510 [ 549.1...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4c9q-64gq-xhx4

больше 4 лет назад

phpMyAdmin Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-4c9q-3pjj-52vf

6 месяцев назад

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.5.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cc2-ww2m-x787

Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4cc2-g9w2-fhf6

Zeep: Server-Side Request Forgery (SSRF)

CVSS3: 5.9
3 месяца назад
github логотип
GHSA-4cc2-25hc-9x3v

A Windows NT local user or administrator account has a default, null, blank, or missing password.

64%
Средний
больше 4 лет назад
github логотип
GHSA-4c9x-vhq3-f96q

An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to the use of an invalid pointer copy, resulting from a destructed string object.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c9x-rrqj-4c82

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4c9x-pr4f-c2j8

Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Interfaces). Supported versions that are affected are 10.2.x, 11.0.x, 12.0.x,12.1.x, 12.1.1.x,12.1.2.x and 13.1.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Retail-J. While the vulnerability is in MICROS Retail-J, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MICROS Retail-J accessible data. CVSS 3.0 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).

CVSS3: 7.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c9x-jxrc-66h6

A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The manipulation of the argument profile name leads to cross site scripting. The attack may be launched remotely.

CVSS3: 2.4
0%
Низкий
около 1 года назад
github логотип
GHSA-4c9x-hwrm-39j5

Integer overflow in the jpc_pi_nextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified impact via a crafted file, which triggers use of an uninitialized value.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c9w-mv22-7x5q

Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Product for WooCommerce: from n/a through 4.4.2.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4c9w-55qf-23v6

Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c9v-w245-3ch6

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c9v-rqpw-wrj7

Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4c9r-w43c-8v76

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

CVSS3: 9.8
11%
Средний
около 2 лет назад
github логотип
GHSA-4c9r-p2x5-3f3m

Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the target server.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-4c9r-jxqx-6hxv

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4c9r-fcrv-f86f

Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

CVSS3: 9.8
17%
Средний
больше 4 лет назад
github логотип
GHSA-4c9q-86fx-4cv8

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVSS3: 4.3
1%
Низкий
5 месяцев назад
github логотип
GHSA-4c9q-7835-998j

In the Linux kernel, the following vulnerability has been resolved: net: libwx: properly reset Rx ring descriptor When device reset is triggered by feature changes such as toggling Rx VLAN offload, wx->do_reset() is called to reinitialize Rx rings. The hardware descriptor ring may retain stale values from previous sessions. And only set the length to 0 in rx_desc[0] would result in building malformed SKBs. Fix it to ensure a clean slate after device reset. [ 549.186435] [ C16] ------------[ cut here ]------------ [ 549.186457] [ C16] kernel BUG at net/core/skbuff.c:2814! [ 549.186468] [ C16] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 549.186472] [ C16] CPU: 16 UID: 0 PID: 0 Comm: swapper/16 Kdump: loaded Not tainted 6.16.0-rc4+ #23 PREEMPT(voluntary) [ 549.186476] [ C16] Hardware name: Micro-Star International Co., Ltd. MS-7E16/X670E GAMING PLUS WIFI (MS-7E16), BIOS 1.90 12/31/2024 [ 549.186478] [ C16] RIP: 0010:__pskb_pull_tail+0x3ff/0x510 [ 549.1...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4c9q-64gq-xhx4

phpMyAdmin Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
10%
Средний
больше 4 лет назад
github логотип
GHSA-4c9q-3pjj-52vf

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.5.

CVSS3: 6.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу