Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2jjq-x889-r334

около 4 лет назад

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

EPSS: Низкий
github логотип

GHSA-2jjq-x548-rhpv

почти 4 года назад

isolated-vm has vulnerable CachedDataOptions in API

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2jjq-jgq8-2h5h

около 4 лет назад

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jjq-jfw3-m48c

около 2 лет назад

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jjp-v4x9-55gm

около 4 лет назад

Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.

EPSS: Низкий
github логотип

GHSA-2jjp-c35x-v2v9

около 3 лет назад

Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2jjp-9wg8-3jxx

около 4 лет назад

Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2jjp-7rw3-8xf9

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be restricted on an affected system. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by using the web-based management interface to upload a file to location on an affected device that they should not have access to. A successful exploit could allow the attacker to overwrite files on the file system of the affected device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jjm-6whx-p8w4

около 4 лет назад

filp whoops Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2jjm-3c42-6xhh

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2jjm-2c27-7368

почти 3 года назад

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Courier Management System 1.0. This issue affects some unknown processing of the component Manage Account Page. The manipulation of the argument First Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240941 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2jjj-q6r5-r2xp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.

EPSS: Низкий
github логотип

GHSA-2jjj-25f5-6pvh

почти 2 года назад

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2jjh-v97q-pjgc

около 4 лет назад

Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

EPSS: Низкий
github логотип

GHSA-2jjh-g3f8-fcmf

около 4 лет назад

ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2jjh-699r-xmc8

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2jjg-vj96-f833

около 1 года назад

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2jjf-m6gp-mr6f

больше 4 лет назад

Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.

EPSS: Низкий
github логотип

GHSA-2jj9-p9wg-x9q9

больше 1 года назад

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jj8-7w4h-hf3p

больше 2 лет назад

Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jjq-x889-r334

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2jjq-x548-rhpv

isolated-vm has vulnerable CachedDataOptions in API

CVSS3: 9.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-2jjq-jgq8-2h5h

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jjq-jfw3-m48c

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-2jjp-v4x9-55gm

Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jjp-c35x-v2v9

Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-2jjp-9wg8-3jxx

Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2jjp-7rw3-8xf9

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be restricted on an affected system. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by using the web-based management interface to upload a file to location on an affected device that they should not have access to. A successful exploit could allow the attacker to overwrite files on the file system of the affected device.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-2jjm-6whx-p8w4

filp whoops Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jjm-3c42-6xhh

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-2jjm-2c27-7368

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Courier Management System 1.0. This issue affects some unknown processing of the component Manage Account Page. The manipulation of the argument First Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240941 was assigned to this vulnerability.

CVSS3: 3.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-2jjj-q6r5-r2xp

Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2jjj-25f5-6pvh

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jjh-v97q-pjgc

Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2jjh-g3f8-fcmf

ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.

CVSS3: 6.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2jjh-699r-xmc8

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-2jjg-vj96-f833

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2jjf-m6gp-mr6f

Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2jj9-p9wg-x9q9

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jj8-7w4h-hf3p

Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу