Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-454p-4wfm-4wpx

больше 2 лет назад

A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-454m-v4gh-w6c2

5 месяцев назад

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-454m-cf77-vmj9

больше 4 лет назад

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through routers that are running an affected version and have NBAR enabled. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-454h-8w2m-m624

около 3 лет назад

A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-454h-38w3-8j8m

около 1 года назад

A vulnerability has been found in PHPGurukul Hostel Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/students.php. The manipulation of the argument search_box leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-454g-wxrr-37fg

18 дней назад

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain. This issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-454g-cxf7-rrv8

больше 4 лет назад

Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-454g-5jw2-mrmh

больше 4 лет назад

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1560, CVE-2020-1574.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-454g-4qqq-2j4g

больше 2 лет назад

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-454f-rj63-3rwv

19 дней назад

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-454f-jj38-2865

больше 2 лет назад

Kofax Power PDF PNG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20388.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-454c-gxv7-hhvg

больше 4 лет назад

Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page.

EPSS: Низкий
github логотип

GHSA-454c-45cm-g8w3

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress allows SQL Injection. This issue affects BookingPress: from n/a through 1.1.28.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4549-74j3-3jwv

больше 4 лет назад

Unspecified vulnerability in Wireshark before 1.0.7 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-4549-5m2c-669v

около 4 лет назад

Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated attacker to alter the data of Bulletin.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4548-vg2j-q73g

больше 4 лет назад

Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name.

EPSS: Низкий
github логотип

GHSA-4548-gq2g-hw87

больше 4 лет назад

Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.

EPSS: Низкий
github логотип

GHSA-4547-6hfx-4h49

18 дней назад

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4546-p244-689v

6 месяцев назад

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-4546-m8q9-wx28

около 1 года назад

The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']['url'] parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-454p-4wfm-4wpx

A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-454m-v4gh-w6c2

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-454m-cf77-vmj9

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through routers that are running an affected version and have NBAR enabled. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 8.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-454h-8w2m-m624

A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-454h-38w3-8j8m

A vulnerability has been found in PHPGurukul Hostel Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/students.php. The manipulation of the argument search_box leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-454g-wxrr-37fg

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain. This issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

CVSS3: 2.7
0%
Низкий
18 дней назад
github логотип
GHSA-454g-cxf7-rrv8

Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-454g-5jw2-mrmh

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1560, CVE-2020-1574.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-454g-4qqq-2j4g

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-454f-rj63-3rwv

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.

CVSS3: 10
1%
Низкий
19 дней назад
github логотип
GHSA-454f-jj38-2865

Kofax Power PDF PNG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20388.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-454c-gxv7-hhvg

Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-454c-45cm-g8w3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress allows SQL Injection. This issue affects BookingPress: from n/a through 1.1.28.

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-4549-74j3-3jwv

Unspecified vulnerability in Wireshark before 1.0.7 has unknown impact and attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4549-5m2c-669v

Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated attacker to alter the data of Bulletin.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-4548-vg2j-q73g

Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4548-gq2g-hw87

Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4547-6hfx-4h49

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

CVSS3: 8.3
0%
Низкий
18 дней назад
github логотип
GHSA-4546-p244-689v

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

CVSS3: 9.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4546-m8q9-wx28

The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']['url'] parameter in all versions up to, and including, 1.0.1 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу