Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43x3-5v8m-8xf2

больше 4 лет назад

sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.

EPSS: Низкий
github логотип

GHSA-43x2-g84q-fmqx

3 месяца назад

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

EPSS: Низкий
github логотип

GHSA-43x2-3vw5-55c5

больше 4 лет назад

tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43x2-2pcr-g799

больше 4 лет назад

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-43ww-xqjh-ppmf

больше 4 лет назад

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

EPSS: Низкий
github логотип

GHSA-43ww-vg8r-97hv

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Zio Alberto zioalberto allows PHP Local File Inclusion.This issue affects Zio Alberto: from n/a through <= 1.2.2.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-43ww-hgjh-c9cg

больше 4 лет назад

Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-43ww-gwmw-f89v

3 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-43ww-866w-7xv9

больше 1 года назад

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-43ww-5h9q-8jh6

больше 4 лет назад

Unspecified vulnerability in the Solaris component in Oracle Sun Products Suite 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Remote Quota Server (rquotad).

EPSS: Низкий
github логотип

GHSA-43wv-w8q4-mcvr

около 2 лет назад

Windows MSHTML Platform Spoofing Vulnerability

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-43wv-g93j-pw44

больше 4 лет назад

Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.

EPSS: Низкий
github логотип

GHSA-43wv-9mh2-86p7

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.

EPSS: Низкий
github логотип

GHSA-43wv-9cr7-p3pg

больше 4 лет назад

DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-43wv-69rq-rx33

12 месяцев назад

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.6.9.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-43wr-9394-fxp2

больше 3 лет назад

OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43wr-5mwj-x7p2

больше 4 лет назад

IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.

EPSS: Низкий
github логотип

GHSA-43wq-xrcm-3vgr

около 2 лет назад

@discordjs/opus vulnerable to Denial of Service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43wq-xr5f-53ww

больше 4 лет назад

Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43wq-r34m-56ch

больше 4 лет назад

In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43x3-5v8m-8xf2

sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43x2-g84q-fmqx

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

3 месяца назад
github логотип
GHSA-43x2-3vw5-55c5

tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43x2-2pcr-g799

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 8.8
49%
Средний
больше 4 лет назад
github логотип
GHSA-43ww-xqjh-ppmf

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-43ww-vg8r-97hv

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Zio Alberto zioalberto allows PHP Local File Inclusion.This issue affects Zio Alberto: from n/a through <= 1.2.2.

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-43ww-hgjh-c9cg

Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43ww-gwmw-f89v

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

CVSS3: 7.7
0%
Низкий
3 месяца назад
github логотип
GHSA-43ww-866w-7xv9

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-43ww-5h9q-8jh6

Unspecified vulnerability in the Solaris component in Oracle Sun Products Suite 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Remote Quota Server (rquotad).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43wv-w8q4-mcvr

Windows MSHTML Platform Spoofing Vulnerability

CVSS3: 7.5
84%
Высокий
около 2 лет назад
github логотип
GHSA-43wv-g93j-pw44

Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43wv-9mh2-86p7

Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43wv-9cr7-p3pg

DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43wv-69rq-rx33

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.6.9.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-43wr-9394-fxp2

OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43wr-5mwj-x7p2

IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43wq-xrcm-3vgr

@discordjs/opus vulnerable to Denial of Service

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-43wq-xr5f-53ww

Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-43wq-r34m-56ch

In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу