Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-3f84-j5xw-c967

больше 4 лет назад

UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f84-gf8q-ggcq

больше 4 лет назад

IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-3f84-67w6-pvm9

больше 4 лет назад

The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.

EPSS: Средний
github логотип

GHSA-3f83-v3jg-8cf4

больше 4 лет назад

PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

EPSS: Низкий
github логотип

GHSA-3f82-v3qw-53q7

около 4 лет назад

Passwords transmitted in plain text by Jenkins Stash Branch Parameter Plugin

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3f7x-wq77-2867

больше 4 лет назад

Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.

EPSS: Средний
github логотип

GHSA-3f7x-wmqw-jp3f

почти 3 года назад

In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3f7x-rf2q-c7q4

больше 4 лет назад

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.

EPSS: Средний
github логотип

GHSA-3f7x-qm4p-6qjv

около 4 лет назад

cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).

EPSS: Низкий
github логотип

GHSA-3f7x-m7w7-vqr9

4 месяца назад

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f7x-cmp2-m6m3

больше 4 лет назад

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f7x-84v6-xqm2

больше 1 года назад

Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3f7x-5hc9-j6v5

10 месяцев назад

URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.

EPSS: Низкий
github логотип

GHSA-3f7x-54cr-7w35

больше 1 года назад

Koha <= 21.11 is contains a SQL Injection vulnerability in /serials/lateissues-export.pl via the supplierid parameter.

CVSS3: 5
EPSS: Средний
github логотип

GHSA-3f7x-25p9-vp9m

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.

EPSS: Низкий
github логотип

GHSA-3f7w-p8vr-4v5f

больше 2 лет назад

pyLoad allows upload to arbitrary folder lead to RCE

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3f7w-jxww-c39p

около 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3f7w-8rr8-f37f

17 дней назад

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3f7w-7j77-73m5

около 2 лет назад

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to, and including, 7.11.0. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The plugin allows administrators (via its settings) to extend the ability to submit events to unauthenticated users, which would allow unauthenticated attackers to exploit this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f7v-qx94-666m

больше 1 года назад

DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f84-j5xw-c967

UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3f84-gf8q-ggcq

IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f84-67w6-pvm9

The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.

18%
Средний
больше 4 лет назад
github логотип
GHSA-3f83-v3jg-8cf4

PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3f82-v3qw-53q7

Passwords transmitted in plain text by Jenkins Stash Branch Parameter Plugin

CVSS3: 3.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3f7x-wq77-2867

Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.

10%
Средний
больше 4 лет назад
github логотип
GHSA-3f7x-wmqw-jp3f

In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-3f7x-rf2q-c7q4

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.

15%
Средний
больше 4 лет назад
github логотип
GHSA-3f7x-qm4p-6qjv

cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).

1%
Низкий
около 4 лет назад
github логотип
GHSA-3f7x-m7w7-vqr9

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3f7x-cmp2-m6m3

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3f7x-84v6-xqm2

Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f7x-5hc9-j6v5

URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.

0%
Низкий
10 месяцев назад
github логотип
GHSA-3f7x-54cr-7w35

Koha <= 21.11 is contains a SQL Injection vulnerability in /serials/lateissues-export.pl via the supplierid parameter.

CVSS3: 5
26%
Средний
больше 1 года назад
github логотип
GHSA-3f7x-25p9-vp9m

PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3f7w-p8vr-4v5f

pyLoad allows upload to arbitrary folder lead to RCE

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3f7w-jxww-c39p

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-3f7w-8rr8-f37f

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

CVSS3: 8.1
17 дней назад
github логотип
GHSA-3f7w-7j77-73m5

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to, and including, 7.11.0. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The plugin allows administrators (via its settings) to extend the ability to submit events to unauthenticated users, which would allow unauthenticated attackers to exploit this vulnerability.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3f7v-qx94-666m

DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу