Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-32f2-v4v8-76vw

около 4 лет назад

An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.

EPSS: Низкий
github логотип

GHSA-32f2-r7gj-x2hp

около 4 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.

EPSS: Низкий
github логотип

GHSA-32f2-chgf-rf94

около 4 лет назад

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-32cw-wqcr-7m6r

больше 1 года назад

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32cw-v82j-575w

около 4 лет назад

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32cw-qm55-8qj6

11 месяцев назад

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-32cw-gjpg-49hh

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpexpertsio WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management allows Reflected XSS.This issue affects WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management: from n/a through 4.2.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-32cw-4h2j-22vc

больше 4 лет назад

Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.

EPSS: Средний
github логотип

GHSA-32cv-rh96-xx2f

3 месяца назад

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32cr-574m-fmxq

около 4 лет назад

Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32cq-h35v-hv9g

больше 4 лет назад

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

EPSS: Низкий
github логотип

GHSA-32cp-f6vp-4m5h

около 4 лет назад

The Stickman Ski Racer (aka com.djinnworks.StickmanSkiRacer.free) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-32cp-9h8g-xvhr

больше 1 года назад

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-32cm-387p-hxf5

больше 3 лет назад

An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-32cj-5wx4-gq8p

около 2 лет назад

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-32ch-w695-p5qw

около 4 лет назад

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-32ch-hx5j-xxhq

больше 4 лет назад

in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."

EPSS: Низкий
github логотип

GHSA-32ch-6x54-q4h9

больше 2 лет назад

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32cf-974m-jh3r

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32cf-6454-vhqx

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: media: [next] staging: media: atomisp: fix memory leak of object flash In the case where the call to lm3554_platform_data_func returns an error there is a memory leak on the error return path of object flash. Fix this by adding an error return path that will free flash and rename labels fail2 to fail3 and fail1 to fail2.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32f2-v4v8-76vw

An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.

1%
Низкий
около 4 лет назад
github логотип
GHSA-32f2-r7gj-x2hp

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.

1%
Низкий
около 4 лет назад
github логотип
GHSA-32f2-chgf-rf94

Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

CVSS3: 10
5%
Низкий
около 4 лет назад
github логотип
GHSA-32cw-wqcr-7m6r

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-32cw-v82j-575w

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-32cw-qm55-8qj6

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

CVSS3: 6.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-32cw-gjpg-49hh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpexpertsio WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management allows Reflected XSS.This issue affects WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management: from n/a through 4.2.9.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32cw-4h2j-22vc

Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.

35%
Средний
больше 4 лет назад
github логотип
GHSA-32cv-rh96-xx2f

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-32cr-574m-fmxq

Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-32cq-h35v-hv9g

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-32cp-f6vp-4m5h

The Stickman Ski Racer (aka com.djinnworks.StickmanSkiRacer.free) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-32cp-9h8g-xvhr

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.

CVSS3: 5.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-32cm-387p-hxf5

An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32cj-5wx4-gq8p

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

CVSS3: 2.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-32ch-w695-p5qw

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

CVSS3: 7.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-32ch-hx5j-xxhq

in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-32ch-6x54-q4h9

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-32cf-974m-jh3r

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-32cf-6454-vhqx

In the Linux kernel, the following vulnerability has been resolved: media: [next] staging: media: atomisp: fix memory leak of object flash In the case where the call to lm3554_platform_data_func returns an error there is a memory leak on the error return path of object flash. Fix this by adding an error return path that will free flash and rename labels fail2 to fail3 and fail1 to fail2.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу