Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2m4q-6966-v2q4

больше 3 лет назад

Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2m4q-2c6r-hmc3

больше 1 года назад

Solon Vulnerable to Path Traversal

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m4p-pvg2-r5cw

около 4 лет назад

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m4m-q2r2-j2j5

около 3 лет назад

OLE Automation Information Disclosure Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2m4m-482c-2rwp

около 4 лет назад

Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate Gateway. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Candidate Gateway accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Candidate Gateway accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-2m4j-g6x3-4mgf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.

EPSS: Низкий
github логотип

GHSA-2m4j-6gvx-869p

около 4 лет назад

An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and compromise underlying operating system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m4j-5h27-9q77

больше 1 года назад

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2m4h-vp37-6746

11 месяцев назад

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2m4h-q3xf-h83r

около 4 лет назад

The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."

EPSS: Низкий
github логотип

GHSA-2m4h-mq5r-2fgv

около 4 лет назад

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.

EPSS: Низкий
github логотип

GHSA-2m4h-74g6-655h

около 4 лет назад

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0330.

EPSS: Низкий
github логотип

GHSA-2m4g-v7v6-qq56

около 4 лет назад

SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs.html.

EPSS: Низкий
github логотип

GHSA-2m4g-hr2m-w586

больше 2 лет назад

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2m4g-hjc6-gj7h

около 4 лет назад

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2m4f-x8rf-mm6q

около 4 лет назад

The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information by reading this file, aka Android internal bug 28814213 and Qualcomm internal bug CR786116. NOTE: the permissions may be intentional in most non-Android contexts.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m4f-hqj2-29hr

7 месяцев назад

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2m4f-cg75-76w2

8 месяцев назад

NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m4f-9643-qqqq

почти 2 года назад

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m4f-546m-3phv

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tpd12s015: Drop buggy __exit annotation for remove function With tpd12s015_remove() marked with __exit this function is discarded when the driver is compiled as a built-in. The result is that when the driver unbinds there is no cleanup done which results in resource leakage or worse.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m4q-6966-v2q4

Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.

CVSS3: 9.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m4q-2c6r-hmc3

Solon Vulnerable to Path Traversal

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2m4p-pvg2-r5cw

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4m-q2r2-j2j5

OLE Automation Information Disclosure Vulnerability

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2m4m-482c-2rwp

Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate Gateway. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Candidate Gateway accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Candidate Gateway accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4j-g6x3-4mgf

Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2m4j-6gvx-869p

An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and compromise underlying operating system.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2m4j-5h27-9q77

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2m4h-vp37-6746

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

CVSS3: 9.8
20%
Средний
11 месяцев назад
github логотип
GHSA-2m4h-q3xf-h83r

The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4h-mq5r-2fgv

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4h-74g6-655h

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0330.

6%
Низкий
около 4 лет назад
github логотип
GHSA-2m4g-v7v6-qq56

SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs.html.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4g-hr2m-w586

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2m4g-hjc6-gj7h

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4f-x8rf-mm6q

The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information by reading this file, aka Android internal bug 28814213 and Qualcomm internal bug CR786116. NOTE: the permissions may be intentional in most non-Android contexts.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m4f-hqj2-29hr

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-2m4f-cg75-76w2

NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

CVSS3: 6.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-2m4f-9643-qqqq

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2m4f-546m-3phv

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tpd12s015: Drop buggy __exit annotation for remove function With tpd12s015_remove() marked with __exit this function is discarded when the driver is compiled as a built-in. The result is that when the driver unbinds there is no cleanup done which results in resource leakage or worse.

CVSS3: 5.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу