Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-367v-52gr-ccrc

больше 4 лет назад

Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.

EPSS: Низкий
github логотип

GHSA-367q-qqwh-pw9w

около 4 лет назад

The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-367q-prcf-2r3g

больше 4 лет назад

In Bftpd before 4.7, there is a memory leak in the file rename function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-367q-j23v-q67j

больше 4 лет назад

Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.

EPSS: Низкий
github логотип

GHSA-367q-hhvx-9x63

9 месяцев назад

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-367q-63cf-925j

больше 3 лет назад

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-367p-r6p3-qqmv

27 дней назад

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. The patch is named 017601354be38cb027ff3ffb01aed79bd5d12610. Applying a patch is the recommended action to fix this issue.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-367p-mrph-mgh2

почти 3 года назад

Information disclosure in Automotive multimedia due to buffer over-read.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-367p-3wqr-p598

больше 4 лет назад

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-367m-r4wp-v752

около 3 лет назад

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-367j-phrj-8hv2

больше 4 лет назад

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

EPSS: Низкий
github логотип

GHSA-367h-9ph3-3jv2

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-367h-9jj5-w29f

19 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-367h-866v-prvm

около 4 лет назад

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

EPSS: Низкий
github логотип

GHSA-367f-x5pr-rh7f

около 4 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-367f-4w4m-gh7p

больше 4 лет назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.

EPSS: Низкий
github логотип

GHSA-367f-3f3f-6cpx

больше 4 лет назад

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

EPSS: Низкий
github логотип

GHSA-367c-j2f5-vj73

около 4 лет назад

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

EPSS: Низкий
github логотип

GHSA-367c-cgj5-h4gx

около 4 лет назад

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3679-w9pg-j7j7

больше 4 лет назад

An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-367v-52gr-ccrc

Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-367q-qqwh-pw9w

The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-367q-prcf-2r3g

In Bftpd before 4.7, there is a memory leak in the file rename function.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-367q-j23v-q67j

Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-367q-hhvx-9x63

A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-367q-63cf-925j

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-367p-r6p3-qqmv

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. The patch is named 017601354be38cb027ff3ffb01aed79bd5d12610. Applying a patch is the recommended action to fix this issue.

CVSS3: 5.6
0%
Низкий
27 дней назад
github логотип
GHSA-367p-mrph-mgh2

Information disclosure in Automotive multimedia due to buffer over-read.

CVSS3: 5.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-367p-3wqr-p598

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-367m-r4wp-v752

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

CVSS3: 5.4
2%
Низкий
около 3 лет назад
github логотип
GHSA-367j-phrj-8hv2

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-367h-9ph3-3jv2

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
около 4 лет назад
github логотип
GHSA-367h-9jj5-w29f

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 9.1
0%
Низкий
19 дней назад
github логотип
GHSA-367h-866v-prvm

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

1%
Низкий
около 4 лет назад
github логотип
GHSA-367f-x5pr-rh7f

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.

CVSS3: 6.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-367f-4w4m-gh7p

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-367f-3f3f-6cpx

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-367c-j2f5-vj73

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

1%
Низкий
около 4 лет назад
github логотип
GHSA-367c-cgj5-h4gx

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-3679-w9pg-j7j7

An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу