Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hgq-hmm8-5vx3

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a name in the call administrator feature, (2) unspecified vectors to the admins visitor information panel, or (3) a text message in a chat session, which is saved in the archive section.

EPSS: Низкий
github логотип

GHSA-3hgq-g7f9-2qxc

больше 4 лет назад

MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hgp-xx2v-3v84

больше 4 лет назад

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hgm-r654-2phm

больше 4 лет назад

WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.

EPSS: Низкий
github логотип

GHSA-3hgm-7fqq-m4fp

3 месяца назад

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3hgj-xg7g-48mq

больше 3 лет назад

When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hgj-mv27-wj4g

больше 4 лет назад

SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in interface/super/edit_globals.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hgj-m5jv-4cfj

больше 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.27 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3hgh-vjm9-7xwp

больше 4 лет назад

Stack-based buffer overflow in Namazu before 2.0.20 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted request containing an empty uri field.

EPSS: Низкий
github логотип

GHSA-3hgh-j2c9-7c7j

больше 4 лет назад

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

EPSS: Низкий
github логотип

GHSA-3hgg-j739-jpxx

больше 4 лет назад

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hgg-2mhh-39vr

больше 4 лет назад

Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hgf-vchh-55wf

больше 4 лет назад

Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP code via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hgc-wjh7-g8wr

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an add action to admin/index.php or (2) conduct static PHP code injection attacks via the themes_editor parameter in an edit_template action to admin/index.php.

EPSS: Низкий
github логотип

GHSA-3hgc-rfpq-fm5j

13 дней назад

Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

EPSS: Низкий
github логотип

GHSA-3hgc-5x5v-4fp3

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks – Gutenberg based Page Builder allows Stored XSS. This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 2.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hgc-3p3q-4m9q

около 3 лет назад

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file admin\user\manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-231018 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3hg9-j6q2-m4g8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

EPSS: Средний
github логотип

GHSA-3hg9-f2mv-c9rx

около 4 лет назад

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181857.

EPSS: Низкий
github логотип

GHSA-3hg8-693h-38cx

около 3 лет назад

Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Essbase Administration Services executes to compromise Oracle Hyperion Essbase Administration Services. While the vulnerability is in Oracle Hyperion Essbase Administration Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Essbase Administration Services accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hgq-hmm8-5vx3

Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a name in the call administrator feature, (2) unspecified vectors to the admins visitor information panel, or (3) a text message in a chat session, which is saved in the archive section.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgq-g7f9-2qxc

MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgp-xx2v-3v84

Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgm-r654-2phm

WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgm-7fqq-m4fp

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3hgj-xg7g-48mq

When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hgj-mv27-wj4g

SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in interface/super/edit_globals.php.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgj-m5jv-4cfj

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.27 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgh-vjm9-7xwp

Stack-based buffer overflow in Namazu before 2.0.20 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted request containing an empty uri field.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgh-j2c9-7c7j

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgg-j739-jpxx

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgg-2mhh-39vr

Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgf-vchh-55wf

Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP code via unspecified vectors.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgc-wjh7-g8wr

Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an add action to admin/index.php or (2) conduct static PHP code injection attacks via the themes_editor parameter in an edit_template action to admin/index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgc-rfpq-fm5j

Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

0%
Низкий
13 дней назад
github логотип
GHSA-3hgc-5x5v-4fp3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks – Gutenberg based Page Builder allows Stored XSS. This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 2.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hgc-3p3q-4m9q

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file admin\user\manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-231018 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-3hg9-j6q2-m4g8

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

11%
Средний
больше 4 лет назад
github логотип
GHSA-3hg9-f2mv-c9rx

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181857.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3hg8-693h-38cx

Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Essbase Administration Services executes to compromise Oracle Hyperion Essbase Administration Services. While the vulnerability is in Oracle Hyperion Essbase Administration Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Essbase Administration Services accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 6
0%
Низкий
около 3 лет назад

Уязвимостей на страницу