Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-2qq2-jxgg-2w76

6 месяцев назад

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability.

EPSS: Низкий
github логотип

GHSA-2qq2-3mq9-pfmj

около 4 лет назад

The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qpx-8vpw-42x9

около 4 лет назад

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qpw-jpx2-w9hr

больше 3 лет назад

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2qpw-f425-8j85

около 4 лет назад

Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php.

EPSS: Низкий
github логотип

GHSA-2qpw-94pp-r3cv

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2qpv-6w5r-q697

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area.

EPSS: Низкий
github логотип

GHSA-2qpr-jh9p-xf8p

около 1 года назад

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2qpq-x4m7-gjf3

больше 1 года назад

Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qpq-rm7r-m2pp

около 4 лет назад

In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qpq-mrrj-2hc9

больше 4 лет назад

The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain privileges via an HTML e-mail message or a web page.

EPSS: Низкий
github логотип

GHSA-2qpq-5447-wmrc

около 4 лет назад

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-search.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2qpp-9v9c-5979

около 1 года назад

A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qpp-8m4h-3vg9

около 4 лет назад

The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qpm-xf67-jj26

около 4 лет назад

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2qpj-g893-v358

больше 4 лет назад

SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-2qph-v9p2-q2gv

около 2 лет назад

Apache StreamPipes potentially allows creation of multiple identical accounts

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2qph-qpvm-2qf7

больше 2 лет назад

tls-listener affected by the slow loris vulnerability with default configuration

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qph-q8xw-gv7q

больше 1 года назад

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

EPSS: Низкий
github логотип

GHSA-2qph-mf22-rc4p

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML implementation, a different issue than CVE-2013-3603.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qq2-jxgg-2w76

Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2qq2-3mq9-pfmj

The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2qpx-8vpw-42x9

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.

CVSS3: 7.5
8%
Низкий
около 4 лет назад
github логотип
GHSA-2qpw-jpx2-w9hr

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qpw-f425-8j85

Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qpw-94pp-r3cv

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2qpv-6w5r-q697

Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2qpr-jh9p-xf8p

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
около 1 года назад
github логотип
GHSA-2qpq-x4m7-gjf3

Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qpq-rm7r-m2pp

In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2qpq-mrrj-2hc9

The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain privileges via an HTML e-mail message or a web page.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2qpq-5447-wmrc

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-search.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qpp-9v9c-5979

A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern.

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-2qpp-8m4h-3vg9

The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qpm-xf67-jj26

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.

CVSS3: 7
0%
Низкий
около 4 лет назад
github логотип
GHSA-2qpj-g893-v358

SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2qph-v9p2-q2gv

Apache StreamPipes potentially allows creation of multiple identical accounts

CVSS3: 3.7
1%
Низкий
около 2 лет назад
github логотип
GHSA-2qph-qpvm-2qf7

tls-listener affected by the slow loris vulnerability with default configuration

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2qph-q8xw-gv7q

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

1%
Низкий
больше 1 года назад
github логотип
GHSA-2qph-mf22-rc4p

Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML implementation, a different issue than CVE-2013-3603.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу