Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 895

Количество 361 895

github логотип

GHSA-3g2h-7hrx-ghf6

около 2 лет назад

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The manipulation of the argument fullname/address/phonenumber/sex/email/city/comment leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269805 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3g2g-x5j3-6xwc

больше 4 лет назад

apertium 3.0.7 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####.lex.cc, (b) /tmp/#####.deformat.l, (c) /tmp/#####.reformat.l, (d) /tmp/#####docxorig, (e) /tmp/#####docxsalida.zip, (f) /tmp/#####xlsxembed, (g) /tmp/#####xlsxorig, and (h) /tmp/#####xslxsalida.zip temporary files, related to the (1) apertium-gen-deformat, (2) apertium-gen-reformat, and (3) apertium scripts.

EPSS: Низкий
github логотип

GHSA-3g2g-rcm6-rrq2

больше 3 лет назад

Cleartext Transmission of Sensitive Information in Jenkins JIRA Pipeline Steps Plugin

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g2g-jmh9-pfcp

больше 1 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g2f-v3cg-vqjp

около 4 лет назад

A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

EPSS: Низкий
github логотип

GHSA-3g2f-4rjg-9385

7 месяцев назад

Weblate leaks information via screenshots

EPSS: Низкий
github логотип

GHSA-3g2c-jgm5-pwjh

около 1 года назад

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g29-4vmj-wp8h

около 4 лет назад

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

EPSS: Низкий
github логотип

GHSA-3g28-v7g2-x3c3

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API function, an array out-of-bounds index can occur.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g28-3cvr-qv6w

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco DNA Center versions prior to 1.2.5 are affected.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g28-22mv-7m5h

больше 4 лет назад

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

EPSS: Низкий
github логотип

GHSA-3g27-vf65-96xv

10 дней назад

Rejected reason: This CVE ID has been rejected.

EPSS: Низкий
github логотип

GHSA-3g27-fg6w-fm64

8 месяцев назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through <= 5.0.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3g26-4vjw-j4m6

около 2 лет назад

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3g26-4c95-5p36

больше 2 лет назад

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249778 is the identifier assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3g25-4wwf-w245

3 дня назад

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-3g25-46v4-h26c

больше 4 лет назад

** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g24-rv7h-5xh5

почти 4 года назад

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g24-mff9-8mv9

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ]

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g24-jm9m-c47r

больше 4 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g2h-7hrx-ghf6

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The manipulation of the argument fullname/address/phonenumber/sex/email/city/comment leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269805 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-3g2g-x5j3-6xwc

apertium 3.0.7 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####.lex.cc, (b) /tmp/#####.deformat.l, (c) /tmp/#####.reformat.l, (d) /tmp/#####docxorig, (e) /tmp/#####docxsalida.zip, (f) /tmp/#####xlsxembed, (g) /tmp/#####xlsxorig, and (h) /tmp/#####xslxsalida.zip temporary files, related to the (1) apertium-gen-deformat, (2) apertium-gen-reformat, and (3) apertium scripts.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3g2g-rcm6-rrq2

Cleartext Transmission of Sensitive Information in Jenkins JIRA Pipeline Steps Plugin

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g2g-jmh9-pfcp

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3g2f-v3cg-vqjp

A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3g2f-4rjg-9385

Weblate leaks information via screenshots

0%
Низкий
7 месяцев назад
github логотип
GHSA-3g2c-jgm5-pwjh

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-3g29-4vmj-wp8h

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3g28-v7g2-x3c3

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API function, an array out-of-bounds index can occur.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g28-3cvr-qv6w

A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco DNA Center versions prior to 1.2.5 are affected.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g28-22mv-7m5h

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3g27-vf65-96xv

Rejected reason: This CVE ID has been rejected.

10 дней назад
github логотип
GHSA-3g27-fg6w-fm64

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through <= 5.0.3.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3g26-4vjw-j4m6

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

CVSS3: 7.5
36%
Средний
около 2 лет назад
github логотип
GHSA-3g26-4c95-5p36

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249778 is the identifier assigned to this vulnerability.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3g25-4wwf-w245

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 8.7
0%
Низкий
3 дня назад
github логотип
GHSA-3g25-46v4-h26c

** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g24-rv7h-5xh5

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3g24-mff9-8mv9

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ]

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-3g24-jm9m-c47r

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу