Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-3r77-fgcp-4m6g

2 месяца назад

Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3r77-48qc-c242

больше 4 лет назад

Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.

EPSS: Низкий
github логотип

GHSA-3r76-7gpf-jq4w

около 2 лет назад

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3r75-xc34-5f44

3 месяца назад

Crawlee for Python: SSRF via sitemap-derived URLs

EPSS: Низкий
github логотип

GHSA-3r75-wcfw-gxm8

9 дней назад

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3r75-2r54-55vx

почти 4 года назад

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3r74-v83p-f4f4

около 2 лет назад

Trufflehog vulnerable to Blind SSRF in some Detectors

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-3r74-6x6g-cp8v

больше 4 лет назад

An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r74-3v78-7856

больше 4 лет назад

SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

EPSS: Низкий
github логотип

GHSA-3r73-wrgm-c3rm

больше 4 лет назад

The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.

EPSS: Низкий
github логотип

GHSA-3r73-v5gv-2jmq

около 1 года назад

A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r73-959g-g38r

больше 4 лет назад

SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.

EPSS: Низкий
github логотип

GHSA-3r72-p59x-qr4h

больше 4 лет назад

The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r72-j9f5-r8j5

больше 4 лет назад

In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3r72-fp6h-25pg

больше 4 лет назад

Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r6x-wmfj-r38f

9 месяцев назад

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r6x-hxgf-2vcw

около 1 месяца назад

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3r6x-7c69-fjhx

около 1 месяца назад

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data as well as unauthorized read access to a subset of Oracle Marketing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Marketing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3r6x-6cp5-6575

2 месяца назад

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r6w-qw5h-chw4

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r77-fgcp-4m6g

Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-3r77-48qc-c242

Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3r76-7gpf-jq4w

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.

CVSS3: 3.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-3r75-xc34-5f44

Crawlee for Python: SSRF via sitemap-derived URLs

0%
Низкий
3 месяца назад
github логотип
GHSA-3r75-wcfw-gxm8

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
1%
Низкий
9 дней назад
github логотип
GHSA-3r75-2r54-55vx

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3r74-v83p-f4f4

Trufflehog vulnerable to Blind SSRF in some Detectors

CVSS3: 3.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3r74-6x6g-cp8v

An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3r74-3v78-7856

SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3r73-wrgm-c3rm

The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3r73-v5gv-2jmq

A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3r73-959g-g38r

SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r72-p59x-qr4h

The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

CVSS3: 5.4
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3r72-j9f5-r8j5

In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r72-fp6h-25pg

Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r6x-wmfj-r38f

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3r6x-hxgf-2vcw

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r6x-7c69-fjhx

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data as well as unauthorized read access to a subset of Oracle Marketing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Marketing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r6x-6cp5-6575

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.

CVSS3: 8.8
2%
Низкий
2 месяца назад
github логотип
GHSA-3r6w-qw5h-chw4

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу