Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34m8-w8w3-m7v4

около 4 лет назад

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34m8-5x3c-2ccr

больше 2 лет назад

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account. IBM X-Force ID: 275938.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34m8-5pc6-8fvm

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team WebinarIgnition.This issue affects WebinarIgnition: from n/a through 3.05.8.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34m7-mp8x-ggjm

около 4 лет назад

Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item & BOM).

EPSS: Низкий
github логотип

GHSA-34m7-5gf2-rcmj

около 4 лет назад

RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34m5-x2xp-x8mh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.

EPSS: Низкий
github логотип

GHSA-34m5-gjm5-2c83

около 4 лет назад

SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Низкий
github логотип

GHSA-34m5-cpcv-cf78

больше 4 лет назад

Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-34m5-796p-mjcp

больше 3 лет назад

Apache UIMA DUCC allows remote code execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34m5-2946-52jc

больше 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34m4-9vvp-p7j9

больше 1 года назад

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/updateroutine.php. The manipulation of the argument tid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34m3-97v7-926m

около 4 лет назад

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-34m2-qrpf-6v7q

4 месяца назад

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-34jx-wx69-9x8v

больше 4 лет назад

Symlink Attack in kubectl cp

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-34jx-q9xg-rr5x

больше 2 лет назад

Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-34jw-rm7g-hph4

около 1 месяца назад

Super-stream HTTP creation skips configure-permission check

EPSS: Низкий
github логотип

GHSA-34jw-gf29-7x45

11 месяцев назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jv-w46c-36jr

больше 4 лет назад

Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jv-m534-q8qr

больше 4 лет назад

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34jv-9f93-hq2f

больше 4 лет назад

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability."

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34m8-w8w3-m7v4

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-34m8-5x3c-2ccr

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account. IBM X-Force ID: 275938.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34m8-5pc6-8fvm

Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team WebinarIgnition.This issue affects WebinarIgnition: from n/a through 3.05.8.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34m7-mp8x-ggjm

Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item & BOM).

1%
Низкий
около 4 лет назад
github логотип
GHSA-34m7-5gf2-rcmj

RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-34m5-x2xp-x8mh

Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34m5-gjm5-2c83

SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34m5-cpcv-cf78

Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-34m5-796p-mjcp

Apache UIMA DUCC allows remote code execution

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-34m5-2946-52jc

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34m4-9vvp-p7j9

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/updateroutine.php. The manipulation of the argument tid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-34m3-97v7-926m

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

CVSS3: 8.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-34m2-qrpf-6v7q

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.

CVSS3: 9.9
16%
Средний
4 месяца назад
github логотип
GHSA-34jx-wx69-9x8v

Symlink Attack in kubectl cp

CVSS3: 5.5
13%
Средний
больше 4 лет назад
github логотип
GHSA-34jx-q9xg-rr5x

Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34jw-rm7g-hph4

Super-stream HTTP creation skips configure-permission check

около 1 месяца назад
github логотип
GHSA-34jw-gf29-7x45

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-34jv-w46c-36jr

Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-34jv-m534-q8qr

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34jv-9f93-hq2f

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability."

28%
Средний
больше 4 лет назад

Уязвимостей на страницу