Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p5v-9pqp-m2pp

около 2 лет назад

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p5v-4gv6-58hf

больше 4 лет назад

Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Absence Management accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-3p5r-wcf3-c745

больше 4 лет назад

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

EPSS: Низкий
github логотип

GHSA-3p5r-7cw3-2m67

больше 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-3p5q-mj37-8frf

больше 4 лет назад

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

EPSS: Низкий
github логотип

GHSA-3p5q-gg9q-4336

24 дня назад

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.

EPSS: Низкий
github логотип

GHSA-3p5q-c694-c8q3

больше 1 года назад

A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p5q-8m4h-wr8g

больше 4 лет назад

Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

EPSS: Низкий
github логотип

GHSA-3p5q-5ghh-h456

больше 4 лет назад

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p5q-2rr6-m932

8 месяцев назад

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p5p-wf36-fw98

больше 4 лет назад

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3p5p-c5mc-jqg3

почти 2 года назад

Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p5p-863p-q64f

больше 4 лет назад

The Skinny channel driver (chan_skinny) in Asterisk Open Source before 1.4.10, AsteriskNOW before beta7, Appliance Developer Kit before 0.7.0, and Appliance s800i before 1.0.3 allows remote authenticated users to cause a denial of service (application crash) via a CAPABILITIES_RES_MESSAGE packet with a capabilities count larger than the capabilities_res_message array population.

EPSS: Низкий
github логотип

GHSA-3p5m-m447-4mm4

больше 4 лет назад

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p5m-j98p-c698

больше 4 лет назад

Stored cross site scripting in getgrav/grav

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p5j-pp53-5ghm

около 2 лет назад

An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3p5j-546v-q985

больше 4 лет назад

Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3p5h-w9pp-xh48

больше 4 лет назад

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3763.

EPSS: Низкий
github логотип

GHSA-3p5h-mwh8-3wx4

больше 4 лет назад

A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524, CVE-2018-8576.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3p5h-985r-gw4g

5 месяцев назад

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p5v-9pqp-m2pp

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-3p5v-4gv6-58hf

Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Absence Management accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5r-wcf3-c745

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5r-7cw3-2m67

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5q-mj37-8frf

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5q-gg9q-4336

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.

1%
Низкий
24 дня назад
github логотип
GHSA-3p5q-c694-c8q3

A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p5q-8m4h-wr8g

Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5q-5ghh-h456

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5q-2rr6-m932

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.

CVSS3: 9.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-3p5p-wf36-fw98

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5p-c5mc-jqg3

Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p5p-863p-q64f

The Skinny channel driver (chan_skinny) in Asterisk Open Source before 1.4.10, AsteriskNOW before beta7, Appliance Developer Kit before 0.7.0, and Appliance s800i before 1.0.3 allows remote authenticated users to cause a denial of service (application crash) via a CAPABILITIES_RES_MESSAGE packet with a capabilities count larger than the capabilities_res_message array population.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5m-m447-4mm4

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5m-j98p-c698

Stored cross site scripting in getgrav/grav

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5j-pp53-5ghm

An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3p5j-546v-q985

Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary files via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5h-w9pp-xh48

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3763.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5h-mwh8-3wx4

A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524, CVE-2018-8576.

CVSS3: 8.8
19%
Средний
больше 4 лет назад
github логотип
GHSA-3p5h-985r-gw4g

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 4.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу