Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-xr93-pcq3-pxf8

5 месяцев назад

Zebra: addr/addrv2 Deserialization Resource Exhaustion

EPSS: Низкий
github логотип

GHSA-xr92-vpvx-mm24

24 дня назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-xr92-rw38-fmg9

больше 4 лет назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

EPSS: Низкий
github логотип

GHSA-xr92-q26v-hcvr

больше 4 лет назад

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

EPSS: Низкий
github логотип

GHSA-xr8x-pxm6-prjg

больше 3 лет назад

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xr8x-f92g-w7rv

больше 2 лет назад

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr8x-5cxm-p785

больше 4 лет назад

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

EPSS: Низкий
github логотип

GHSA-xr8x-4mg2-g4gr

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr8x-4f65-m34g

больше 2 лет назад

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr8x-2h22-4fr9

больше 4 лет назад

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <iframe> sandbox via a crafted HTML page.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xr8w-5325-33v3

около 1 года назад

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xr8v-mf39-c8v7

больше 4 лет назад

PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

EPSS: Низкий
github логотип

GHSA-xr8r-7f7p-x5r5

больше 4 лет назад

A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

EPSS: Низкий
github логотип

GHSA-xr8r-2cxg-2rgp

больше 4 лет назад

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr8q-7c6p-2wcx

больше 4 лет назад

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr8m-fvm3-765w

больше 4 лет назад

rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error.

EPSS: Низкий
github логотип

GHSA-xr8m-4hqr-4c6p

больше 3 лет назад

Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr8m-38f7-mvq7

больше 3 лет назад

A vulnerability was found in Editorial Calendar Plugin up to 2.6. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched remotely. Upgrading to version 2.7 is able to address this issue. The name of the patch is a9277f13781187daee760b4dfd052b1b68e101cc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-225151.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr8j-gg22-3pqg

около 3 лет назад

IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xr8h-wj4v-rx7f

больше 3 лет назад

Missing permission check in Jenkins TestQuality Updater Plugin

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr93-pcq3-pxf8

Zebra: addr/addrv2 Deserialization Resource Exhaustion

0%
Низкий
5 месяцев назад
github логотип
GHSA-xr92-vpvx-mm24

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

24 дня назад
github логотип
GHSA-xr92-rw38-fmg9

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr92-q26v-hcvr

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8x-pxm6-prjg

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CVSS3: 9.1
больше 3 лет назад
github логотип
GHSA-xr8x-f92g-w7rv

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xr8x-5cxm-p785

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8x-4mg2-g4gr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-xr8x-4f65-m34g

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xr8x-2h22-4fr9

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <iframe> sandbox via a crafted HTML page.

CVSS3: 9.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8w-5325-33v3

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xr8v-mf39-c8v7

PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8r-7f7p-x5r5

A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory access, potentially resulting in code execution in the context of the current user.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8r-2cxg-2rgp

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8q-7c6p-2wcx

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8m-fvm3-765w

rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xr8m-4hqr-4c6p

Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xr8m-38f7-mvq7

A vulnerability was found in Editorial Calendar Plugin up to 2.6. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched remotely. Upgrading to version 2.7 is able to address this issue. The name of the patch is a9277f13781187daee760b4dfd052b1b68e101cc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-225151.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xr8j-gg22-3pqg

IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.

CVSS3: 5.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-xr8h-wj4v-rx7f

Missing permission check in Jenkins TestQuality Updater Plugin

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу