Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-382r-w7px-7vf7

больше 4 лет назад

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server, a different vulnerability than CVE-2015-4880.

EPSS: Низкий
github логотип

GHSA-382q-fpqh-29f7

6 месяцев назад

`polymarket-clients-sdk` was removed from crates.io for malicious code

EPSS: Низкий
github логотип

GHSA-382q-3qj5-29mx

около 4 лет назад

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-382p-crwp-jf65

около 4 лет назад

Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-382m-qj75-vx5v

больше 4 лет назад

inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-382m-fgqc-gfhw

около 2 лет назад

A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46. This issue affects some unknown processing of the file functionalities.global.php of the component Global Options Page. The manipulation of the argument site-logo-text leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268823. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-382m-5w7j-w5pf

больше 4 лет назад

Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.

EPSS: Низкий
github логотип

GHSA-382j-8mxh-c7x2

около 2 месяцев назад

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

EPSS: Низкий
github логотип

GHSA-382j-74x3-hwj5

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File Inclusion.This issue affects Omnipress: from n/a through <= 1.6.6.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-382h-mgg9-q9m2

5 месяцев назад

A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-382h-7ph3-qx8r

больше 4 лет назад

Multiple unspecified vulnerabilities in Oracle Database Server 8i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB09 in Export, (2) DB11 in Materialized Views, and (3) DB16 in Security Service.

EPSS: Низкий
github логотип

GHSA-382h-3vwf-5x2j

больше 4 лет назад

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-382g-xjr7-3hcp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75165.

EPSS: Низкий
github логотип

GHSA-382g-wcph-26j3

18 дней назад

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-382f-7w2w-v6qr

больше 2 лет назад

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-382c-wf23-2vph

больше 2 лет назад

Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-382c-vx95-w3p5

около 1 месяца назад

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-382c-r87v-m473

3 месяца назад

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-382c-gf8c-2jc8

больше 4 лет назад

Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

EPSS: Низкий
github логотип

GHSA-3829-wxq6-hmw8

около 4 лет назад

An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-382r-w7px-7vf7

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server, a different vulnerability than CVE-2015-4880.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-382q-fpqh-29f7

`polymarket-clients-sdk` was removed from crates.io for malicious code

6 месяцев назад
github логотип
GHSA-382q-3qj5-29mx

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-382p-crwp-jf65

Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-382m-qj75-vx5v

inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-382m-fgqc-gfhw

A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46. This issue affects some unknown processing of the file functionalities.global.php of the component Global Options Page. The manipulation of the argument site-logo-text leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268823. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-382m-5w7j-w5pf

Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-382j-8mxh-c7x2

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-382j-74x3-hwj5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File Inclusion.This issue affects Omnipress: from n/a through <= 1.6.6.

CVSS3: 7.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-382h-mgg9-q9m2

A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-382h-7ph3-qx8r

Multiple unspecified vulnerabilities in Oracle Database Server 8i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB09 in Export, (2) DB11 in Materialized Views, and (3) DB16 in Security Service.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-382h-3vwf-5x2j

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-382g-xjr7-3hcp

Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75165.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-382g-wcph-26j3

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

CVSS3: 9.4
0%
Низкий
18 дней назад
github логотип
GHSA-382f-7w2w-v6qr

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

CVSS3: 8.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-382c-wf23-2vph

Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-382c-vx95-w3p5

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

CVSS3: 6.5
около 1 месяца назад
github логотип
GHSA-382c-r87v-m473

in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-382c-gf8c-2jc8

Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3829-wxq6-hmw8

An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу