Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3pq7-6jpj-cm4p

3 месяца назад

A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3pq5-xxv9-fj58

больше 4 лет назад

Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI.

EPSS: Низкий
github логотип

GHSA-3pq5-r3xm-vfqc

больше 4 лет назад

Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17044, CVE-2020-17055.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pq5-p8h5-jfr8

больше 4 лет назад

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions via vectors involving the "lowest security level interface," aka Bug ID CSCsv40504.

EPSS: Низкий
github логотип

GHSA-3pq5-82wc-xqgh

больше 1 года назад

Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3pq4-wgqv-gq3h

7 месяцев назад

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial of service (DoS) condition on the affected product by sending a specially crafted packet containing a specific command to the affected product.

EPSS: Низкий
github логотип

GHSA-3pq4-c488-v2m4

больше 4 лет назад

Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

EPSS: Низкий
github логотип

GHSA-3pq4-7fhq-j4xr

больше 4 лет назад

The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service (message loss or delay).

EPSS: Низкий
github логотип

GHSA-3pq3-cxgx-g86g

почти 2 года назад

Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The specific flaw exists within the loadFieldMatch method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE. Was ZDI-CAN-22506.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pq2-h22c-p37g

больше 1 года назад

A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources\mapper\sys\SysLogDao.xml. The manipulation of the argument order leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3ppx-w77w-7jj2

больше 2 лет назад

Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component in at utils/os_file.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ppx-frr2-xwmr

больше 4 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3ppx-8h63-84vp

10 месяцев назад

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3ppw-4jp4-5852

больше 1 года назад

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3ppv-wqrq-v3rc

больше 4 лет назад

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3ppr-72x5-x67q

больше 3 лет назад

XML external entity vulnerability on agents in Jenkins MSTest Plugin

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3ppr-6h5r-qm4p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.

EPSS: Низкий
github логотип

GHSA-3ppq-w2m7-6qvc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.

EPSS: Низкий
github логотип

GHSA-3ppq-p8g9-x6rg

больше 4 лет назад

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

EPSS: Низкий
github логотип

GHSA-3ppq-5wmg-wx3m

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads allows Stored XSS.This issue affects Z-Downloads: from n/a through 1.11.7.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pq7-6jpj-cm4p

A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3pq5-xxv9-fj58

Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3pq5-r3xm-vfqc

Windows Remote Access Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17044, CVE-2020-17055.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pq5-p8h5-jfr8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions via vectors involving the "lowest security level interface," aka Bug ID CSCsv40504.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pq5-82wc-xqgh

Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pq4-wgqv-gq3h

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the affected product, write device data in the affected product, or cause a denial of service (DoS) condition on the affected product by sending a specially crafted packet containing a specific command to the affected product.

1%
Низкий
7 месяцев назад
github логотип
GHSA-3pq4-c488-v2m4

Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pq4-7fhq-j4xr

The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service (message loss or delay).

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pq3-cxgx-g86g

Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The specific flaw exists within the loadFieldMatch method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE. Was ZDI-CAN-22506.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3pq2-h22c-p37g

A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources\mapper\sys\SysLogDao.xml. The manipulation of the argument order leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3ppx-w77w-7jj2

Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component in at utils/os_file.c.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3ppx-frr2-xwmr

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ppx-8h63-84vp

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3ppw-4jp4-5852

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3ppv-wqrq-v3rc

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

CVSS3: 7.5
16%
Средний
больше 4 лет назад
github логотип
GHSA-3ppr-72x5-x67q

XML external entity vulnerability on agents in Jenkins MSTest Plugin

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ppr-6h5r-qm4p

Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3ppq-w2m7-6qvc

Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ppq-p8g9-x6rg

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-3ppq-5wmg-wx3m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads allows Stored XSS.This issue affects Z-Downloads: from n/a through 1.11.7.

CVSS3: 5.9
0%
Низкий
больше 1 года назад

Уязвимостей на страницу