Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2j3f-2fhx-9r3x

около 4 лет назад

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

EPSS: Низкий
github логотип

GHSA-2j3c-m8j3-c8j2

около 4 лет назад

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

EPSS: Низкий
github логотип

GHSA-2j3c-jv49-w6c7

около 4 лет назад

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j39-qcjm-428w

больше 2 лет назад

Apache Struts vulnerable to path traversal

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2j39-6c38-r3mx

около 4 лет назад

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-2j39-64q5-rjfv

больше 4 лет назад

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j38-xhmg-c3g9

около 4 лет назад

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-2j38-pmwm-2h3f

около 4 лет назад

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

EPSS: Низкий
github логотип

GHSA-2j38-64p3-w8wc

11 месяцев назад

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2j38-53q9-crr9

около 4 лет назад

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j37-h336-4w29

около 4 лет назад

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

EPSS: Низкий
github логотип

GHSA-2j35-5wj8-vcv8

около 4 лет назад

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j33-qvm8-55q5

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress allows Stored XSS. This issue affects VoucherPress: from n/a through 1.5.7.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j32-c79r-58r7

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j2x-m8gc-xcrm

около 4 лет назад

EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.

EPSS: Низкий
github логотип

GHSA-2j2x-hx4g-2gf4

почти 8 лет назад

In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2j2x-hqr9-3h42

около 2 месяцев назад

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

EPSS: Низкий
github логотип

GHSA-2j2x-2gpw-g8fm

больше 3 лет назад

flat vulnerable to Prototype Pollution

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j2w-j5j7-7cgr

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetIsp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j2w-gm6q-cv65

около 2 лет назад

: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j3f-2fhx-9r3x

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2j3c-m8j3-c8j2

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2j3c-jv49-w6c7

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j39-qcjm-428w

Apache Struts vulnerable to path traversal

CVSS3: 9.8
81%
Высокий
больше 2 лет назад
github логотип
GHSA-2j39-6c38-r3mx

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS3: 7.2
79%
Высокий
около 4 лет назад
github логотип
GHSA-2j39-64q5-rjfv

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2j38-xhmg-c3g9

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2j38-pmwm-2h3f

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2j38-64p3-w8wc

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2j38-53q9-crr9

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j37-h336-4w29

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

5%
Низкий
около 4 лет назад
github логотип
GHSA-2j35-5wj8-vcv8

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-2j33-qvm8-55q5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress allows Stored XSS. This issue affects VoucherPress: from n/a through 1.5.7.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-2j32-c79r-58r7

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-2j2x-m8gc-xcrm

EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2j2x-hx4g-2gf4

In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode

CVSS3: 7.4
2%
Низкий
почти 8 лет назад
github логотип
GHSA-2j2x-hqr9-3h42

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2j2x-2gpw-g8fm

flat vulnerable to Prototype Pollution

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j2w-j5j7-7cgr

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetIsp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2j2w-gm6q-cv65

: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

CVSS3: 5.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу