Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3pqv-6pm3-g46j

больше 4 лет назад

SQL Injection in RosarioSIS

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3pqv-622q-29qq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3pqv-3gf8-jfg6

больше 4 лет назад

Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3pqr-r447-f4mh

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3pqq-fhm8-qxg5

почти 4 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pqq-c927-m2hq

больше 2 лет назад

Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3pqq-c2p3-r2g4

больше 4 лет назад

The USF BCM (aka com.appmakr.app193115) application 252847 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3pqp-rh6f-w44r

больше 4 лет назад

jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.

CVSS3: 4.8
EPSS: Высокий
github логотип

GHSA-3pqp-qx7r-vppf

почти 3 года назад

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3pqp-px69-7mm4

больше 4 лет назад

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2773.

EPSS: Средний
github логотип

GHSA-3pqp-55x3-46fh

больше 4 лет назад

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

EPSS: Средний
github логотип

GHSA-3pqj-xjg3-p5x7

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.

EPSS: Низкий
github логотип

GHSA-3pqj-q5j3-4r5q

больше 1 года назад

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pqj-chvj-wmcp

больше 4 лет назад

The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

EPSS: Низкий
github логотип

GHSA-3pqj-4h6v-gq86

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pqh-p72c-fj85

почти 5 лет назад

Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pqh-mpvw-5fr2

больше 4 лет назад

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

EPSS: Низкий
github логотип

GHSA-3pqh-j93j-qr4h

больше 4 лет назад

FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pqg-mc4c-xrv2

больше 4 лет назад

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

EPSS: Низкий
github логотип

GHSA-3pqg-7243-253q

больше 4 лет назад

SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pqv-6pm3-g46j

SQL Injection in RosarioSIS

CVSS3: 9.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqv-622q-29qq

Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqv-3gf8-jfg6

Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqr-r447-f4mh

Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqq-fhm8-qxg5

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3pqq-c927-m2hq

Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3pqq-c2p3-r2g4

The USF BCM (aka com.appmakr.app193115) application 252847 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqp-rh6f-w44r

jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.

CVSS3: 4.8
71%
Высокий
больше 4 лет назад
github логотип
GHSA-3pqp-qx7r-vppf

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVSS3: 9.8
38%
Средний
почти 3 года назад
github логотип
GHSA-3pqp-px69-7mm4

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2773.

20%
Средний
больше 4 лет назад
github логотип
GHSA-3pqp-55x3-46fh

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

62%
Средний
больше 4 лет назад
github логотип
GHSA-3pqj-xjg3-p5x7

Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqj-q5j3-4r5q

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pqj-chvj-wmcp

The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqj-4h6v-gq86

Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3pqh-p72c-fj85

Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-3pqh-mpvw-5fr2

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqh-j93j-qr4h

FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqg-mc4c-xrv2

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3pqg-7243-253q

SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу