Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3px8-gf2c-qqrh

около 1 года назад

The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. There is no impact on integrity or availability of the application

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3px8-7pj4-m3r5

больше 4 лет назад

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

EPSS: Низкий
github логотип

GHSA-3px8-2p4q-xpwm

больше 1 года назад

Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3px7-w424-22rw

больше 4 лет назад

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3px7-qfpp-9fx8

больше 4 лет назад

Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

EPSS: Низкий
github логотип

GHSA-3px7-mx75-562c

больше 4 лет назад

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.

EPSS: Средний
github логотип

GHSA-3px7-jm2p-6h2c

почти 3 года назад

encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3px7-c4j3-576r

около 1 года назад

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3px7-9cxh-c3q3

больше 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3px6-x742-ffjj

больше 4 лет назад

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.

EPSS: Низкий
github логотип

GHSA-3px6-98xq-7ggw

больше 4 лет назад

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3px5-wjh3-9x6r

больше 4 лет назад

Mautic stored Cross-site Scripting (XSS)

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3px5-66w8-x4q8

больше 1 года назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3px5-5wr3-7444

больше 4 лет назад

Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Gateway for Mobile Devices accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Gateway for Mobile Devices accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-3px4-cc65-vwjj

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: venus: protect against spurious interrupts during probe Make sure the interrupt handler is initialized before the interrupt is registered. If the IRQ is registered before hfi_create(), it's possible that an interrupt fires before the handler setup is complete, leading to a NULL dereference. This error condition has been observed during system boot on Rb3Gen2.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3px4-37qg-4m28

около 2 лет назад

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272621 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3px4-28qc-4f47

3 месяца назад

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3px3-34w3-c9jf

больше 4 лет назад

PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

EPSS: Низкий
github логотип

GHSA-3px2-4mjj-vhr8

5 месяцев назад

A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3px2-2xc4-mxr2

6 месяцев назад

Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148 and Firefox ESR < 140.8.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3px8-gf2c-qqrh

The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. There is no impact on integrity or availability of the application

CVSS3: 5.6
0%
Низкий
около 1 года назад
github логотип
GHSA-3px8-7pj4-m3r5

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3px8-2p4q-xpwm

Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3px7-w424-22rw

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3px7-qfpp-9fx8

Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3px7-mx75-562c

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.

12%
Средний
больше 4 лет назад
github логотип
GHSA-3px7-jm2p-6h2c

encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3px7-c4j3-576r

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

CVSS3: 8.3
1%
Низкий
около 1 года назад
github логотип
GHSA-3px7-9cxh-c3q3

Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3px6-x742-ffjj

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3px6-98xq-7ggw

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3px5-wjh3-9x6r

Mautic stored Cross-site Scripting (XSS)

CVSS3: 9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3px5-66w8-x4q8

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3px5-5wr3-7444

Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Gateway for Mobile Devices accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Gateway for Mobile Devices accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3px4-cc65-vwjj

In the Linux kernel, the following vulnerability has been resolved: media: venus: protect against spurious interrupts during probe Make sure the interrupt handler is initialized before the interrupt is registered. If the IRQ is registered before hfi_create(), it's possible that an interrupt fires before the handler setup is complete, leading to a NULL dereference. This error condition has been observed during system boot on Rb3Gen2.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3px4-37qg-4m28

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272621 was assigned to this vulnerability.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3px4-28qc-4f47

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3px3-34w3-c9jf

PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3px2-4mjj-vhr8

A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3px2-2xc4-mxr2

Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148 and Firefox ESR < 140.8.

CVSS3: 9.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу