Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 328

Количество 362 328

github логотип

GHSA-3h4p-g442-4q4v

больше 1 года назад

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h4p-c4mx-3p28

4 месяца назад

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h4m-m55v-gx4m

около 3 лет назад

Apache Airflow Improper Input Validation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4j-qhvh-q69x

почти 4 года назад

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4h-w66g-8c4g

больше 4 лет назад

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."

EPSS: Средний
github логотип

GHSA-3h4h-g6p9-v72m

больше 1 года назад

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h4h-fp54-55h6

около 2 месяцев назад

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3h4g-vcc2-xxf3

больше 1 года назад

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4g-q9gm-hwvc

около 4 лет назад

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.

EPSS: Низкий
github логотип

GHSA-3h4g-986f-gvf8

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-3h4g-2mjp-7xfp

больше 4 лет назад

Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

EPSS: Низкий
github логотип

GHSA-3h4f-jgvh-wjvm

больше 4 лет назад

src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3h4f-76g6-g5wc

около 4 лет назад

In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive.

EPSS: Низкий
github логотип

GHSA-3h49-gmxg-3c7g

больше 1 года назад

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-3h49-76hw-pv6f

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path Dan Carpenter reported a Smack static checker warning: fs/smb/client/cifsfs.c:1981 init_cifs() error: we previously assumed 'serverclose_wq' could be null (see line 1895) The patch which introduced the serverclose workqueue used the wrong oredering in error paths in init_cifs() for freeing it on errors.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h47-gjh4-rmq3

4 месяца назад

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h47-86qq-gprm

больше 4 лет назад

Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

EPSS: Низкий
github логотип

GHSA-3h45-h6mj-8qm2

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3h45-5qrh-cg5g

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Driving Directions allows Reflected XSS. This issue affects Driving Directions: from n/a through 1.4.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3h3x-2hwv-hr52

почти 2 года назад

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h4p-g442-4q4v

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h4p-c4mx-3p28

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 8.8
1%
Низкий
4 месяца назад
github логотип
GHSA-3h4m-m55v-gx4m

Apache Airflow Improper Input Validation vulnerability

CVSS3: 6.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-3h4j-qhvh-q69x

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3h4h-w66g-8c4g

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."

21%
Средний
больше 4 лет назад
github логотип
GHSA-3h4h-g6p9-v72m

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h4h-fp54-55h6

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2272130b. Applying a patch is advised to resolve this issue.

CVSS3: 3.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3h4g-vcc2-xxf3

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.

CVSS3: 6.5
6%
Низкий
больше 1 года назад
github логотип
GHSA-3h4g-q9gm-hwvc

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h4g-986f-gvf8

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h4g-2mjp-7xfp

Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h4f-jgvh-wjvm

src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h4f-76g6-g5wc

In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h49-gmxg-3c7g

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

CVSS3: 3.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h49-76hw-pv6f

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path Dan Carpenter reported a Smack static checker warning: fs/smb/client/cifsfs.c:1981 init_cifs() error: we previously assumed 'serverclose_wq' could be null (see line 1895) The patch which introduced the serverclose workqueue used the wrong oredering in error paths in init_cifs() for freeing it on errors.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h47-gjh4-rmq3

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3h47-86qq-gprm

Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h45-h6mj-8qm2

A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3h45-5qrh-cg5g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Driving Directions allows Reflected XSS. This issue affects Driving Directions: from n/a through 1.4.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h3x-2hwv-hr52

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу