Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-37x6-m83p-f654

больше 3 лет назад

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37x6-cjg4-grcf

больше 4 лет назад

The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-37x6-37vf-qf3r

3 месяца назад

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37x5-qpm8-53rq

почти 3 года назад

Google Sheets data source plugin for Grafana information disclosure vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37x5-q2m2-89q6

больше 3 лет назад

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthorized attacker to disclose sensitive information. As a result, unauthorized users could access to MELSEC safety CPU modules illgally.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37x5-49h8-fjqq

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chart Builder Team Chartify allows Reflected XSS.This issue affects Chartify: from n/a through 2.7.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-37x4-xj4c-pcwm

больше 4 лет назад

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37x4-xj4c-2664

больше 4 лет назад

SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter.

EPSS: Низкий
github логотип

GHSA-37x4-rhq4-f92v

больше 4 лет назад

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37x4-2mr4-hj45

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37x3-r4vm-9pqj

больше 4 лет назад

Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37x3-j9jq-vrjx

больше 1 года назад

Dcat-Admin Cross-Site Scripting (XSS) vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-37x3-hqf8-5w7p

больше 2 лет назад

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-37x2-4f2v-4ggg

больше 4 лет назад

Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-37wx-r6q9-6fhj

около 1 месяца назад

OAuth2 silent verify_none fallback for JWKS fetch

EPSS: Низкий
github логотип

GHSA-37wx-px9v-xhhf

больше 4 лет назад

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

EPSS: Низкий
github логотип

GHSA-37ww-cvhx-x8p9

4 месяца назад

Microsoft Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause the application to crash.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-37wv-xpm8-wf7h

почти 2 года назад

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-37wv-74x7-5f3m

2 месяца назад

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions), SIPROTEC 5 7SJ8...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37wr-4wrp-xh2r

больше 4 лет назад

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the weblink module.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37x6-m83p-f654

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-37x6-cjg4-grcf

The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37x6-37vf-qf3r

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-37x5-qpm8-53rq

Google Sheets data source plugin for Grafana information disclosure vulnerability

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-37x5-q2m2-89q6

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthorized attacker to disclose sensitive information. As a result, unauthorized users could access to MELSEC safety CPU modules illgally.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-37x5-49h8-fjqq

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chart Builder Team Chartify allows Reflected XSS.This issue affects Chartify: from n/a through 2.7.6.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-37x4-xj4c-pcwm

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-37x4-xj4c-2664

SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37x4-rhq4-f92v

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37x4-2mr4-hj45

A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-37x3-r4vm-9pqj

Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-37x3-j9jq-vrjx

Dcat-Admin Cross-Site Scripting (XSS) vulnerability

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-37x3-hqf8-5w7p

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-37x2-4f2v-4ggg

Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37wx-r6q9-6fhj

OAuth2 silent verify_none fallback for JWKS fetch

около 1 месяца назад
github логотип
GHSA-37wx-px9v-xhhf

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-37ww-cvhx-x8p9

Microsoft Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause the application to crash.

CVSS3: 6.2
0%
Низкий
4 месяца назад
github логотип
GHSA-37wv-xpm8-wf7h

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-37wv-74x7-5f3m

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions), SIPROTEC 5 7SJ8...

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-37wr-4wrp-xh2r

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the weblink module.

CVSS3: 3.3
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу