Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-4c3c-8gp8-85c5

больше 4 лет назад

Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4c3c-6q2f-43vf

больше 4 лет назад

mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.

EPSS: Низкий
github логотип

GHSA-4c39-hj99-5h2r

больше 4 лет назад

OXID eShop user impersonation vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c39-fwgj-4vq7

3 месяца назад

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c39-f9c4-rh2h

4 месяца назад

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_customer. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4c39-5qhc-788c

больше 2 лет назад

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-4c39-4ccg-62r3

около 2 месяцев назад

Next.js: Unbounded Server Action payload in Edge runtime

EPSS: Низкий
github логотип

GHSA-4c38-w985-8624

25 дней назад

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4c38-fqqv-56cm

12 месяцев назад

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4c38-cvx5-fh22

больше 4 лет назад

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, debug policy can potentially be bypassed.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c37-p59v-2r8g

около 3 лет назад

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

CVSS3: 4.6
EPSS: Средний
github логотип

GHSA-4c37-hj7c-pvgr

26 дней назад

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4c37-7m5h-c8m9

больше 1 года назад

Apache Felix Webconsole: XSS in services console

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4c36-rwf6-qrpp

около 4 лет назад

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4c36-3whg-3ppx

больше 4 лет назад

A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4c35-xvpv-9965

3 месяца назад

An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c35-wcg5-mm9h

4 месяца назад

next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-4c35-hp54-r4m7

больше 4 лет назад

GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

EPSS: Низкий
github логотип

GHSA-4c35-cfrw-j59g

больше 4 лет назад

Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4c35-9qwv-fj5v

больше 4 лет назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4c3c-8gp8-85c5

Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c3c-6q2f-43vf

mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4c39-hj99-5h2r

OXID eShop user impersonation vulnerability

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c39-fwgj-4vq7

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-4c39-f9c4-rh2h

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_customer. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4c39-5qhc-788c

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.

CVSS3: 5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4c39-4ccg-62r3

Next.js: Unbounded Server Action payload in Edge runtime

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4c38-w985-8624

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.1
0%
Низкий
25 дней назад
github логотип
GHSA-4c38-fqqv-56cm

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-4c38-cvx5-fh22

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, debug policy can potentially be bypassed.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c37-p59v-2r8g

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

CVSS3: 4.6
56%
Средний
около 3 лет назад
github логотип
GHSA-4c37-hj7c-pvgr

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVSS3: 4.3
0%
Низкий
26 дней назад
github логотип
GHSA-4c37-7m5h-c8m9

Apache Felix Webconsole: XSS in services console

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-4c36-rwf6-qrpp

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-4c36-3whg-3ppx

A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4c35-xvpv-9965

An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-4c35-wcg5-mm9h

next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys

CVSS3: 4.2
4 месяца назад
github логотип
GHSA-4c35-hp54-r4m7

GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c35-cfrw-j59g

Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4c35-9qwv-fj5v

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу