Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3qjr-xcph-fm5w

больше 4 лет назад

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3qjr-4g82-68jf

больше 2 лет назад

SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction. php?id=1 and /user/viewloantrans.php?id=1, id parameter) and retrieve the information stored in the database.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qjq-q9wp-57vc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EU DSGVO Helper allows Reflected XSS. This issue affects EU DSGVO Helper: from n/a through 1.0.6.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qjq-fqq3-9cxq

больше 2 лет назад

A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qjq-8563-xqpx

больше 1 года назад

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qjp-mpc4-r9xg

больше 4 лет назад

Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to execute arbitrary code via a (1) file or (2) socket that provides configuration data with many entries, leading to a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-3qjp-m28w-prvg

больше 4 лет назад

The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qjm-23v2-9v26

больше 4 лет назад

** DISPUTED ** Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qjj-xgvq-44qh

больше 1 года назад

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.8.41.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3qjj-8gwh-qxvc

почти 4 года назад

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qjj-487w-2xcf

5 месяцев назад

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3qjj-43rh-65fq

больше 4 лет назад

Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3qjh-r982-mhgp

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in rollbar Rollbar allows Cross Site Request Forgery. This issue affects Rollbar: from n/a through 2.7.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qjh-mq2f-vcvc

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qjg-v5jw-mj3f

больше 4 лет назад

Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21879.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3qjg-973r-4w6w

больше 4 лет назад

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.

EPSS: Средний
github логотип

GHSA-3qjf-w8wq-4wwh

больше 4 лет назад

Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."

EPSS: Средний
github логотип

GHSA-3qjf-qh38-x73v

больше 1 года назад

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qjf-f83f-x2pm

больше 4 лет назад

XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qjc-xccj-8hhf

21 день назад

Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qjr-xcph-fm5w

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjr-4g82-68jf

SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction. php?id=1 and /user/viewloantrans.php?id=1, id parameter) and retrieve the information stored in the database.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qjq-q9wp-57vc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EU DSGVO Helper allows Reflected XSS. This issue affects EU DSGVO Helper: from n/a through 1.0.6.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qjq-fqq3-9cxq

A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qjq-8563-xqpx

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qjp-mpc4-r9xg

Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to execute arbitrary code via a (1) file or (2) socket that provides configuration data with many entries, leading to a heap-based buffer overflow.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjp-m28w-prvg

The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjm-23v2-9v26

** DISPUTED ** Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjj-xgvq-44qh

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.8.41.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qjj-8gwh-qxvc

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.

CVSS3: 9.8
4%
Низкий
почти 4 года назад
github логотип
GHSA-3qjj-487w-2xcf

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 4.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-3qjj-43rh-65fq

Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjh-r982-mhgp

Cross-Site Request Forgery (CSRF) vulnerability in rollbar Rollbar allows Cross Site Request Forgery. This issue affects Rollbar: from n/a through 2.7.1.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qjh-mq2f-vcvc

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjg-v5jw-mj3f

Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21879.

CVSS3: 7.8
24%
Средний
больше 4 лет назад
github логотип
GHSA-3qjg-973r-4w6w

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.

21%
Средний
больше 4 лет назад
github логотип
GHSA-3qjf-w8wq-4wwh

Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."

13%
Средний
больше 4 лет назад
github логотип
GHSA-3qjf-qh38-x73v

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3qjf-f83f-x2pm

XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qjc-xccj-8hhf

Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 4.3
0%
Низкий
21 день назад

Уязвимостей на страницу