Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-42vc-95ph-qmgq

больше 4 лет назад

Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-42v9-rj5j-m2v5

больше 4 лет назад

A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-42v9-jcgw-cjx9

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule plugin <= 3.3.8 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42v8-53xx-p57h

больше 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-2404.

EPSS: Низкий
github логотип

GHSA-42v8-4p4g-32vh

больше 3 лет назад

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42v8-4h63-pf87

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42v5-vmqc-jx62

больше 1 года назад

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO &#8211; On-site SEO allows Privilege Escalation. This issue affects Rankology SEO &#8211; On-site SEO: from n/a through 2.2.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42v5-55fh-293w

больше 2 лет назад

Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42v5-23f7-54cx

почти 4 года назад

The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This would be highly complex to exploit as it would require the attacker to set the cookie a cookie for the targeted user.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-42v4-xpx8-cgxf

больше 4 лет назад

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

EPSS: Низкий
github логотип

GHSA-42v4-pqgp-hhp7

около 2 месяцев назад

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-42v4-cgq7-c8gf

больше 4 лет назад

A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42v4-3ghc-v5xh

больше 4 лет назад

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

EPSS: Низкий
github логотип

GHSA-42v3-rqf8-qxr6

больше 2 лет назад

A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250230 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-42v3-m5qw-hx2j

больше 3 лет назад

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239210579

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42v3-fjwf-6q83

больше 4 лет назад

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42v3-8vjx-xjp9

6 месяцев назад

A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unknown code of the file /manage_employee_deductions.php. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42v3-6whv-w2mm

около 3 лет назад

An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42v2-796f-qqmv

больше 4 лет назад

libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.

EPSS: Средний
github логотип

GHSA-42rx-hfpw-m45p

около 3 лет назад

An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42vc-95ph-qmgq

Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-42v9-rj5j-m2v5

A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.

CVSS3: 6.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-42v9-jcgw-cjx9

Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule plugin <= 3.3.8 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-42v8-53xx-p57h

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-2404.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-42v8-4p4g-32vh

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42v8-4h63-pf87

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-42v5-vmqc-jx62

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO &#8211; On-site SEO allows Privilege Escalation. This issue affects Rankology SEO &#8211; On-site SEO: from n/a through 2.2.3.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-42v5-55fh-293w

Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-42v5-23f7-54cx

The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This would be highly complex to exploit as it would require the attacker to set the cookie a cookie for the targeted user.

CVSS3: 4.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-42v4-xpx8-cgxf

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-42v4-pqgp-hhp7

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

CVSS3: 9.1
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-42v4-cgq7-c8gf

A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-42v4-3ghc-v5xh

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-42v3-rqf8-qxr6

A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250230 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-42v3-m5qw-hx2j

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239210579

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-42v3-fjwf-6q83

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-42v3-8vjx-xjp9

A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unknown code of the file /manage_employee_deductions.php. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-42v3-6whv-w2mm

An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-42v2-796f-qqmv

libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.

43%
Средний
больше 4 лет назад
github логотип
GHSA-42rx-hfpw-m45p

An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.

CVSS3: 5.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу