Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 078

Количество 362 078

github логотип

GHSA-3gh8-3438-mqwv

больше 1 года назад

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gh7-q58j-c4hg

больше 4 лет назад

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-3109.

EPSS: Низкий
github логотип

GHSA-3gh7-m3jw-66v6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3gh7-cv65-5fg2

больше 4 лет назад

PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-3gh7-cjxx-xcjw

9 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3gh7-9gp9-47r9

больше 1 года назад

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /controllers/updatesettings.php of the component Setting Handler. The manipulation of the argument firstname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3gh6-v5v9-6v9j

почти 3 года назад

Jetty vulnerable to errant command quoting in CGI Servlet

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3gh6-9qjr-2jmg

больше 4 лет назад

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, and CVE-2014-0545.

EPSS: Низкий
github логотип

GHSA-3gh6-67w4-wv53

больше 4 лет назад

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.

EPSS: Низкий
github логотип

GHSA-3gh6-5qqw-c955

больше 3 лет назад

A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor flap of auto-discovery sessions for any reason. This is a race condition which is outside of an attackers direct control and it depends on system internal timing whether this issue occurs. This issue affects Juniper Networks Junos OS Evolved: 21.3 versions prior to 21.3R3-EVO; 21.4 versions prior to 21.4R2-EVO; 22.1 versions prior to 22.1R2-EVO; 22.2 versions prior to 22.2R1-S1-EVO, 22.2R2-EVO.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3gh5-wq3g-32vj

больше 4 лет назад

An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gh5-8j6v-4qqc

больше 4 лет назад

An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3gh4-p862-rqm3

около 4 лет назад

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1011, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1016, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3gh3-jjwq-mp73

около 2 лет назад

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers to modify the theme's settings, including enabling a setting which allows lower-privileged users such as contributors to perform code execution, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gh3-crhx-q3jq

больше 4 лет назад

A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.

EPSS: Низкий
github логотип

GHSA-3gh3-7v6r-4q8w

7 месяцев назад

Tanium addressed an improper access controls vulnerability in Reputation.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gh2-xw74-jmcw

около 6 лет назад

SQL injection in Django

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3gh2-jcxp-2335

около 4 лет назад

Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.

EPSS: Низкий
github логотип

GHSA-3gh2-h77w-4jgw

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3gh2-3c3q-2933

7 месяцев назад

A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gh8-3438-mqwv

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3gh7-q58j-c4hg

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-3109.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh7-m3jw-66v6

Cross-site scripting (XSS) vulnerability in the web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh7-cv65-5fg2

PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh7-cjxx-xcjw

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-3gh7-9gp9-47r9

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /controllers/updatesettings.php of the component Setting Handler. The manipulation of the argument firstname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gh6-v5v9-6v9j

Jetty vulnerable to errant command quoting in CGI Servlet

CVSS3: 3.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3gh6-9qjr-2jmg

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, and CVE-2014-0545.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh6-67w4-wv53

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh6-5qqw-c955

A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor flap of auto-discovery sessions for any reason. This is a race condition which is outside of an attackers direct control and it depends on system internal timing whether this issue occurs. This issue affects Juniper Networks Junos OS Evolved: 21.3 versions prior to 21.3R3-EVO; 21.4 versions prior to 21.4R2-EVO; 22.1 versions prior to 22.1R2-EVO; 22.2 versions prior to 22.2R1-S1-EVO, 22.2R2-EVO.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gh5-wq3g-32vj

An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh5-8j6v-4qqc

An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh4-p862-rqm3

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1011, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1016, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.

CVSS3: 5.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-3gh3-jjwq-mp73

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers to modify the theme's settings, including enabling a setting which allows lower-privileged users such as contributors to perform code execution, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3gh3-crhx-q3jq

A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3gh3-7v6r-4q8w

Tanium addressed an improper access controls vulnerability in Reputation.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3gh2-xw74-jmcw

SQL injection in Django

CVSS3: 8.8
23%
Средний
около 6 лет назад
github логотип
GHSA-3gh2-jcxp-2335

Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3gh2-h77w-4jgw

Rejected reason: Not used

7 месяцев назад
github логотип
GHSA-3gh2-3c3q-2933

A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.

CVSS3: 5.3
0%
Низкий
7 месяцев назад

Уязвимостей на страницу