Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35w5-h9v9-m2qp

почти 2 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Vasilis Kerasiotis Affiliator allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through 2.1.3.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-35w5-c9v9-6575

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS. This issue affects WP Content Protection: from n/a through 1.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35w5-2xwx-jpp4

больше 4 лет назад

HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.

EPSS: Низкий
github логотип

GHSA-35w4-w34h-84qw

около 4 лет назад

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35w4-5hgf-f56q

больше 3 лет назад

An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local storage after logout.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35w3-pjm6-wj95

около 2 месяцев назад

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

EPSS: Низкий
github логотип

GHSA-35w3-9295-x8r4

около 4 лет назад

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-35w3-85xv-8x6w

больше 4 лет назад

WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.

EPSS: Низкий
github логотип

GHSA-35w3-6qhc-474v

больше 2 лет назад

@workos-inc/authkit-nextjs session replay vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-35w2-q5f9-8244

около 1 года назад

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be done within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35w2-gj48-j2p3

около 1 месяца назад

A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-35w2-fcvf-666f

около 4 лет назад

The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-35vx-vx6v-j9x7

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35vx-q8fx-9jg2

больше 4 лет назад

Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

EPSS: Низкий
github логотип

GHSA-35vv-xp9m-c452

больше 4 лет назад

An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35vv-8xvm-74jp

около 4 лет назад

Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35vr-x655-89wj

почти 3 года назад

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-35vq-jv5m-667c

около 4 лет назад

The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.

EPSS: Низкий
github логотип

GHSA-35vq-2ggj-6fwg

больше 4 лет назад

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

EPSS: Низкий
github логотип

GHSA-35vp-x4m3-rrq9

5 месяцев назад

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element. The injected payload is stored in the database and subsequently rendered in the Administration panel's "Comments" section when administrators review submitted comments. Importantly, the malicious script is not reflected in the public-facing comments interface, but only within the backend administration view. Alternatively, users of Administrator, Moderator, Manager roles can also directly input crafted payloads into existing comments. This makes the vulnerability a persistent XSS issue targeting administrative users. This affects /core/admin/comments.php, while CVE-2022-24585 affects /core/admin/comment.php, a uniquely distinct vulnerability.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35w5-h9v9-m2qp

Unrestricted Upload of File with Dangerous Type vulnerability in Vasilis Kerasiotis Affiliator allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through 2.1.3.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-35w5-c9v9-6575

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS. This issue affects WP Content Protection: from n/a through 1.3.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-35w5-2xwx-jpp4

HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35w4-w34h-84qw

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

CVSS3: 7.2
5%
Низкий
около 4 лет назад
github логотип
GHSA-35w4-5hgf-f56q

An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local storage after logout.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35w3-pjm6-wj95

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-35w3-9295-x8r4

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-35w3-85xv-8x6w

WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35w3-6qhc-474v

@workos-inc/authkit-nextjs session replay vulnerability

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35w2-q5f9-8244

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be done within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
1%
Низкий
около 1 года назад
github логотип
GHSA-35w2-gj48-j2p3

A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-35w2-fcvf-666f

The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.

CVSS3: 3.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-35vx-vx6v-j9x7

Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35vx-q8fx-9jg2

Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vv-xp9m-c452

An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35vv-8xvm-74jp

Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-35vr-x655-89wj

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

CVSS3: 8.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-35vq-jv5m-667c

The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35vq-2ggj-6fwg

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vp-x4m3-rrq9

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element. The injected payload is stored in the database and subsequently rendered in the Administration panel's "Comments" section when administrators review submitted comments. Importantly, the malicious script is not reflected in the public-facing comments interface, but only within the backend administration view. Alternatively, users of Administrator, Moderator, Manager roles can also directly input crafted payloads into existing comments. This makes the vulnerability a persistent XSS issue targeting administrative users. This affects /core/admin/comments.php, while CVE-2022-24585 affects /core/admin/comment.php, a uniquely distinct vulnerability.

CVSS3: 6.1
0%
Низкий
5 месяцев назад

Уязвимостей на страницу