Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-2r9r-8hr4-8x64

около 4 лет назад

The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).

EPSS: Низкий
github логотип

GHSA-2r9r-8fcg-m38g

больше 3 лет назад

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2r9r-8crm-q8p5

около 4 лет назад

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2r9r-3596-47c9

около 2 лет назад

Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Product Development accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Product Development accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2r9p-x5v3-jc5q

около 4 лет назад

IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2r9p-vqp7-xg3j

больше 4 лет назад

SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.

EPSS: Низкий
github логотип

GHSA-2r9p-58g6-hvj9

больше 4 лет назад

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.

EPSS: Низкий
github логотип

GHSA-2r9m-wg35-rfvc

больше 1 года назад

Moodle vulnerable to cache poisoning via injection into storage

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2r9m-fc3w-cxph

около 2 лет назад

HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r9m-635c-rmwj

почти 2 года назад

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insufficient resource management while establishing SSL VPN sessions. An attacker could exploit this vulnerability by sending a series of crafted HTTPS requests to the VPN server of an affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to stop accepting new connections, preventing new SSL VPN connections from being established. Existing SSL VPN sessions are not impacted. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers gracefully without requiring manual intervention.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-2r9m-48qp-xv3j

больше 4 лет назад

PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-2r9j-f6x6-6gpm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.

EPSS: Низкий
github логотип

GHSA-2r9j-8mjp-g9gw

около 1 года назад

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2r9j-2jrh-5rqj

около 4 лет назад

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-tunnelname variable in the pptp_client.lua file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2r9h-x757-8j9q

больше 1 года назад

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r9h-7mx9-fq3w

около 4 лет назад

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

EPSS: Низкий
github логотип

GHSA-2r9c-63hg-4rg2

5 месяцев назад

DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these parameters to extract or modify sensitive database information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2r9c-46v3-43fc

почти 8 лет назад

Downloads Resources over HTTP in haxe3

EPSS: Низкий
github логотип

GHSA-2r99-88xc-7qfg

около 4 лет назад

The Jian Ren (aka cn.sh.scustom.janren) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2r99-5vhm-3fpm

больше 2 лет назад

SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.php.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r9r-8hr4-8x64

The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).

1%
Низкий
около 4 лет назад
github логотип
GHSA-2r9r-8fcg-m38g

Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r9r-8crm-q8p5

IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileged user to access the application endpoints of high privileged users and also perform some state changing actions restricted to a high privileged user. IBM X-Force ID: 153119.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2r9r-3596-47c9

Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Product Development accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Product Development accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2r9p-x5v3-jc5q

IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2r9p-vqp7-xg3j

SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2r9p-58g6-hvj9

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2r9m-wg35-rfvc

Moodle vulnerable to cache poisoning via injection into storage

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2r9m-fc3w-cxph

HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2r9m-635c-rmwj

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insufficient resource management while establishing SSL VPN sessions. An attacker could exploit this vulnerability by sending a series of crafted HTTPS requests to the VPN server of an affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to stop accepting new connections, preventing new SSL VPN connections from being established. Existing SSL VPN sessions are not impacted. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers gracefully without requiring manual intervention.

CVSS3: 5.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-2r9m-48qp-xv3j

PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2r9j-f6x6-6gpm

Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2r9j-8mjp-g9gw

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2r9j-2jrh-5rqj

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-tunnelname variable in the pptp_client.lua file.

CVSS3: 7.2
4%
Низкий
около 4 лет назад
github логотип
GHSA-2r9h-x757-8j9q

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

CVSS3: 8.8
4%
Низкий
больше 1 года назад
github логотип
GHSA-2r9h-7mx9-fq3w

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

1%
Низкий
около 4 лет назад
github логотип
GHSA-2r9c-63hg-4rg2

DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these parameters to extract or modify sensitive database information.

CVSS3: 8.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-2r9c-46v3-43fc

Downloads Resources over HTTP in haxe3

2%
Низкий
почти 8 лет назад
github логотип
GHSA-2r99-88xc-7qfg

The Jian Ren (aka cn.sh.scustom.janren) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2r99-5vhm-3fpm

SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.php.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу