Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49mv-gc6x-96j3

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bainternet User Specific Content allows DOM-Based XSS.This issue affects User Specific Content: from n/a through 1.0.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-49mr-vrxv-hmwg

больше 4 лет назад

A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49mr-m45p-mv5c

больше 4 лет назад

SQL injection vulnerability in profile.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

EPSS: Низкий
github логотип

GHSA-49mq-v38m-66qv

больше 4 лет назад

The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."

EPSS: Средний
github логотип

GHSA-49mq-rqr9-cq6g

больше 4 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5098 and CVE-2015-5105.

EPSS: Низкий
github логотип

GHSA-49mq-hrjw-247h

больше 4 лет назад

The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49mq-fc6q-3h46

29 дней назад

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-49mq-f6v3-c6q2

больше 4 лет назад

BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49mq-c5mf-q7wc

почти 2 года назад

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49mq-82rx-mw6j

больше 4 лет назад

In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-116321860

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49mq-5g4x-p557

больше 4 лет назад

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49mp-2v92-m6vp

11 месяцев назад

Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-49mm-8468-22hq

больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-49mj-x8jp-qvfc

около 1 года назад

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-49mj-c4w2-5w8v

больше 4 лет назад

Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-49mj-77q5-qw5g

больше 4 лет назад

Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-49mj-5v2h-rj59

больше 4 лет назад

PHP remote file inclusion vulnerability in connected_users.lib.php3 in phpHeaven phpMyChat 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ChatPath parameter.

EPSS: Низкий
github логотип

GHSA-49mg-v9x7-jfqh

около 3 лет назад

Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affects Hitachi Device Manager: before 8.8.5-02.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-49mg-fmq8-qjx2

больше 2 лет назад

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-49mg-c54c-h35r

больше 4 лет назад

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49mv-gc6x-96j3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bainternet User Specific Content allows DOM-Based XSS.This issue affects User Specific Content: from n/a through 1.0.6.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-49mr-vrxv-hmwg

A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-49mr-m45p-mv5c

SQL injection vulnerability in profile.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-49mq-v38m-66qv

The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."

27%
Средний
больше 4 лет назад
github логотип
GHSA-49mq-rqr9-cq6g

Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5098 and CVE-2015-5105.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-49mq-hrjw-247h

The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-49mq-fc6q-3h46

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

CVSS3: 8.4
29 дней назад
github логотип
GHSA-49mq-f6v3-c6q2

BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-49mq-c5mf-q7wc

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-49mq-82rx-mw6j

In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-116321860

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49mq-5g4x-p557

A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49mp-2v92-m6vp

Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-49mm-8468-22hq

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-49mj-x8jp-qvfc

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

CVSS3: 8.8
21%
Средний
около 1 года назад
github логотип
GHSA-49mj-c4w2-5w8v

Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49mj-77q5-qw5g

Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49mj-5v2h-rj59

PHP remote file inclusion vulnerability in connected_users.lib.php3 in phpHeaven phpMyChat 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ChatPath parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-49mg-v9x7-jfqh

Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affects Hitachi Device Manager: before 8.8.5-02.

CVSS3: 5.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-49mg-fmq8-qjx2

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-49mg-c54c-h35r

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу