Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-4c34-f6qc-56qv

около 2 лет назад

The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4c33-jjxv-7pfw

больше 4 лет назад

Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c33-h9j5-vmhj

больше 1 года назад

A vulnerability classified as critical has been found in 1000 Projects Daily College Class Work Report Book 1.0. Affected is an unknown function of the file /dcwr_entry.php. The manipulation of the argument Date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4c33-fwgf-qv6r

больше 4 лет назад

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4c33-2p78-4q5m

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aldo aldo allows PHP Local File Inclusion.This issue affects Aldo: from n/a through <= 1.0.10.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4c32-xmgj-2g98

почти 8 лет назад

High severity vulnerability that affects org.apache.pdfbox:pdfbox

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4c32-x28m-p8h3

больше 4 лет назад

Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.

EPSS: Низкий
github логотип

GHSA-4c32-w6c7-77x4

больше 3 лет назад

SQL injection when using MySQL/PostgreSQL data checking

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4c2x-v4q9-wm44

около 2 лет назад

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4c2x-qm74-54w5

больше 4 лет назад

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4c2x-qgm5-5mrh

больше 4 лет назад

The AnnotationX.AnnList.1 ActiveX control in Agilent Technologies Feature Extraction allows remote attackers to execute arbitrary code via a crafted object parameter in the Insert function, related to "Index Out-Of-Bounds."

EPSS: Низкий
github логотип

GHSA-4c2x-g299-mpv8

больше 4 лет назад

Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4c2w-x5ww-3v7m

больше 4 лет назад

Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4c2w-wcw4-8jv9

больше 4 лет назад

Jenkins Rundeck Plugin CSRF vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4c2w-v5rq-5mx7

больше 2 лет назад

eZ Platform Editor Cross-site Scripting (XSS)

EPSS: Низкий
github логотип

GHSA-4c2v-p982-wgvx

больше 4 лет назад

Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."

EPSS: Низкий
github логотип

GHSA-4c2v-95cv-xvxm

5 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4c2q-pqjh-9v54

около 2 месяцев назад

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4c2q-fwj9-cw6m

4 дня назад

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4c2q-9g38-8v79

4 месяца назад

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4c34-f6qc-56qv

The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-4c33-jjxv-7pfw

Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c33-h9j5-vmhj

A vulnerability classified as critical has been found in 1000 Projects Daily College Class Work Report Book 1.0. Affected is an unknown function of the file /dcwr_entry.php. The manipulation of the argument Date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4c33-fwgf-qv6r

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c33-2p78-4q5m

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aldo aldo allows PHP Local File Inclusion.This issue affects Aldo: from n/a through <= 1.0.10.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-4c32-xmgj-2g98

High severity vulnerability that affects org.apache.pdfbox:pdfbox

CVSS3: 7.8
4%
Низкий
почти 8 лет назад
github логотип
GHSA-4c32-x28m-p8h3

Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c32-w6c7-77x4

SQL injection when using MySQL/PostgreSQL data checking

CVSS3: 8.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4c2x-v4q9-wm44

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-4c2x-qm74-54w5

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c2x-qgm5-5mrh

The AnnotationX.AnnList.1 ActiveX control in Agilent Technologies Feature Extraction allows remote attackers to execute arbitrary code via a crafted object parameter in the Insert function, related to "Index Out-Of-Bounds."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4c2x-g299-mpv8

Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.

CVSS3: 6.4
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4c2w-x5ww-3v7m

Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c2w-wcw4-8jv9

Jenkins Rundeck Plugin CSRF vulnerability

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c2w-v5rq-5mx7

eZ Platform Editor Cross-site Scripting (XSS)

больше 2 лет назад
github логотип
GHSA-4c2v-p982-wgvx

Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c2v-95cv-xvxm

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-4c2q-pqjh-9v54

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4c2q-fwj9-cw6m

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
4 дня назад
github логотип
GHSA-4c2q-9g38-8v79

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 9.9
0%
Низкий
4 месяца назад

Уязвимостей на страницу