Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-3cvj-x7f9-wmv2

2 месяца назад

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3cvh-w666-7794

около 4 лет назад

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cvg-mw7q-93pw

около 4 лет назад

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin level access in the cloud controller.

EPSS: Низкий
github логотип

GHSA-3cvg-mp22-q8rc

почти 3 года назад

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7. A user may be able to elevate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3cvg-jfmm-2mw4

около 3 лет назад

Missing Authorization in GitHub repository hamza417/inure prior to build88.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3cvg-j39v-pqwx

почти 3 года назад

A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cvf-rq6j-j34q

больше 3 лет назад

This candidate was in a CNA pool that was not assigned to any issues during 2021.

EPSS: Низкий
github логотип

GHSA-3cvf-fpq3-c29m

больше 3 лет назад

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3cvf-6w83-9rc3

почти 4 года назад

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cvf-5chq-5r99

9 месяцев назад

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cvc-f83h-vhvc

больше 4 лет назад

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3cv9-jw4h-8r53

почти 2 года назад

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3cv9-2r4x-c3c5

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-3cv8-m6fw-pjg4

больше 4 лет назад

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3cv8-hffv-cwf4

около 4 лет назад

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205815.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cv8-f86g-8p35

больше 4 лет назад

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-3cv8-cqpx-wc6m

больше 2 лет назад

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cv7-mfff-4c27

больше 2 лет назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3cv7-5j4c-h696

больше 4 лет назад

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.

EPSS: Низкий
github логотип

GHSA-3cv6-xr26-rj48

больше 4 лет назад

The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cvj-x7f9-wmv2

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

CVSS3: 9.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3cvh-w666-7794

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

CVSS3: 6.5
9%
Низкий
около 4 лет назад
github логотип
GHSA-3cvg-mw7q-93pw

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin level access in the cloud controller.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3cvg-mp22-q8rc

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7. A user may be able to elevate privileges.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3cvg-jfmm-2mw4

Missing Authorization in GitHub repository hamza417/inure prior to build88.

CVSS3: 5.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3cvg-j39v-pqwx

A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3cvf-rq6j-j34q

This candidate was in a CNA pool that was not assigned to any issues during 2021.

больше 3 лет назад
github логотип
GHSA-3cvf-fpq3-c29m

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cvf-6w83-9rc3

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3cvf-5chq-5r99

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3cvc-f83h-vhvc

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3cv9-jw4h-8r53

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3cv9-2r4x-c3c5

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 1 года назад
github логотип
GHSA-3cv8-m6fw-pjg4

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.

CVSS3: 6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3cv8-hffv-cwf4

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205815.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3cv8-f86g-8p35

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3cv8-cqpx-wc6m

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3cv7-mfff-4c27

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3cv7-5j4c-h696

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3cv6-xr26-rj48

The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу