Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-42vr-vvgx-qhgx

5 месяцев назад

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-42vr-p8c8-mj49

больше 4 лет назад

The cforms2 plugin before 14.6.10 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42vr-8wv2-vg62

больше 1 года назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42vr-5jh6-78jw

больше 4 лет назад

In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, code which handles close of a descriptor created by posix_openpt fails to undo a signal configuration. This causes an incorrect signal to be raised leading to a write after free of kernel memory allowing a malicious user to gain root privileges or escape a jail.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42vq-h95x-4x26

3 месяца назад

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-42vq-c86x-66jp

5 месяцев назад

Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42vq-3gw7-2qxj

около 3 лет назад

Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42vq-32v8-j5v7

почти 5 лет назад

An unspecified version of issabelPBX is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.

EPSS: Низкий
github логотип

GHSA-42vq-2xjj-6g8w

больше 4 лет назад

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

EPSS: Низкий
github логотип

GHSA-42vq-2prv-qxmf

больше 4 лет назад

Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42vm-5c82-p5wp

около 2 месяцев назад

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-42vj-qx64-fvc8

больше 4 лет назад

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.

EPSS: Низкий
github логотип

GHSA-42vh-q74p-v48f

больше 4 лет назад

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

EPSS: Низкий
github логотип

GHSA-42vg-q6mw-cfh5

больше 4 лет назад

dotCMS allows remote authenticated users to execute arbitrary Java code

EPSS: Низкий
github логотип

GHSA-42vg-2q93-fj6j

почти 4 года назад

LIEF vulnerable to heap based buffer overflow via print_binary function

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42vf-2jww-9pqr

почти 2 года назад

A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-42vc-wcrf-99q3

больше 4 лет назад

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

EPSS: Средний
github логотип

GHSA-42vc-w69w-ghg7

больше 1 года назад

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42vc-w257-pp26

больше 2 лет назад

The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42vc-vfqh-cr2x

больше 2 лет назад

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42vr-vvgx-qhgx

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVSS3: 5.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-42vr-p8c8-mj49

The cforms2 plugin before 14.6.10 for WordPress has SQL injection.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-42vr-8wv2-vg62

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-42vr-5jh6-78jw

In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, code which handles close of a descriptor created by posix_openpt fails to undo a signal configuration. This causes an incorrect signal to be raised leading to a write after free of kernel memory allowing a malicious user to gain root privileges or escape a jail.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-42vq-h95x-4x26

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-42vq-c86x-66jp

Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-42vq-3gw7-2qxj

Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.

CVSS3: 8.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-42vq-32v8-j5v7

An unspecified version of issabelPBX is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-42vq-2xjj-6g8w

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-42vq-2prv-qxmf

Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-42vm-5c82-p5wp

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 10
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-42vj-qx64-fvc8

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-42vh-q74p-v48f

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-42vg-q6mw-cfh5

dotCMS allows remote authenticated users to execute arbitrary Java code

2%
Низкий
больше 4 лет назад
github логотип
GHSA-42vg-2q93-fj6j

LIEF vulnerable to heap based buffer overflow via print_binary function

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-42vf-2jww-9pqr

A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
9%
Низкий
почти 2 года назад
github логотип
GHSA-42vc-wcrf-99q3

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

15%
Средний
больше 4 лет назад
github логотип
GHSA-42vc-w69w-ghg7

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-42vc-w257-pp26

The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42vc-vfqh-cr2x

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу