Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-3v74-qmfm-rv65

больше 4 лет назад

SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.

EPSS: Низкий
github логотип

GHSA-3v74-q4mq-26hx

12 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS.This issue affects Netigma: from 6.3.3 before 6.3.5 V8.

CVSS3: 8.9
EPSS: Низкий
github логотип

GHSA-3v74-hwwq-cx56

больше 4 лет назад

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3v74-fj6r-9qvp

8 месяцев назад

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v74-7fxr-9p4j

больше 1 года назад

A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3v72-5557-rmpc

12 дней назад

Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3v72-4xqg-8rpf

больше 4 лет назад

Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.

EPSS: Низкий
github логотип

GHSA-3v6x-x9qx-ccmh

около 1 года назад

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/create.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v6x-g643-6gw7

больше 4 лет назад

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-3v6x-9mfm-xp5x

больше 4 лет назад

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when handling malformed TIFF images. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v6x-9jmh-gp3w

больше 4 лет назад

Windows Mobile Device Management Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v6w-vg3j-g58f

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pdfcrowd Save as Image plugin by Pdfcrowd plugin <= 2.16.0 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3v6w-rf9f-2qhg

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3v6w-73q2-w9pg

больше 3 лет назад

In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v6v-w2x6-55vq

больше 4 лет назад

Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.

EPSS: Низкий
github логотип

GHSA-3v6v-6vwq-2h95

около 1 месяца назад

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3v6v-2x6p-32mc

почти 4 года назад

pgadmin4 vulnerable to Code Injection

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-3v6r-vhg4-9m9j

больше 4 лет назад

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v6r-pw5p-6hc2

больше 4 лет назад

An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v6q-chwv-xhhp

больше 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v74-qmfm-rv65

SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v74-q4mq-26hx

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS.This issue affects Netigma: from 6.3.3 before 6.3.5 V8.

CVSS3: 8.9
0%
Низкий
12 месяцев назад
github логотип
GHSA-3v74-hwwq-cx56

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.

CVSS3: 7.5
60%
Средний
больше 4 лет назад
github логотип
GHSA-3v74-fj6r-9qvp

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3v74-7fxr-9p4j

A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
2%
Низкий
больше 1 года назад
github логотип
GHSA-3v72-5557-rmpc

Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.

CVSS3: 5.7
1%
Низкий
12 дней назад
github логотип
GHSA-3v72-4xqg-8rpf

Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6x-x9qx-ccmh

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/create.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3v6x-g643-6gw7

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

23%
Средний
больше 4 лет назад
github логотип
GHSA-3v6x-9mfm-xp5x

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when handling malformed TIFF images. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6x-9jmh-gp3w

Windows Mobile Device Management Remote Code Execution Vulnerability.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6w-vg3j-g58f

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pdfcrowd Save as Image plugin by Pdfcrowd plugin <= 2.16.0 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-3v6w-rf9f-2qhg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3v6w-73q2-w9pg

In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3v6v-w2x6-55vq

Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6v-6vwq-2h95

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3v6v-2x6p-32mc

pgadmin4 vulnerable to Code Injection

CVSS3: 8.8
80%
Высокий
почти 4 года назад
github логотип
GHSA-3v6r-vhg4-9m9j

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6r-pw5p-6hc2

An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6q-chwv-xhhp

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу