Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-3pc3-3mfc-x5vj

больше 4 лет назад

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.

EPSS: Низкий
github логотип

GHSA-3pc2-v6g3-vwg9

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3pc2-fm7p-q2vg

около 6 лет назад

Cross-site Scripting in October

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3pc2-c878-63rj

около 3 лет назад

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3p9x-xxx6-2w4p

больше 3 лет назад

Broken Access Control in 3rd party TYPO3 extension "femanager"

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3p9x-xxjc-hw5p

больше 4 лет назад

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

EPSS: Низкий
github логотип

GHSA-3p9x-fj5f-w25c

больше 4 лет назад

A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3p9x-34w6-f58v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p9w-wq67-w93f

больше 4 лет назад

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

EPSS: Низкий
github логотип

GHSA-3p9w-w3x4-vc62

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p9w-w3g3-89rg

больше 4 лет назад

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

EPSS: Низкий
github логотип

GHSA-3p9w-pv5h-crrp

почти 5 лет назад

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p9w-cf27-62fv

около 3 лет назад

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p9w-7x8w-2m9v

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

EPSS: Низкий
github логотип

GHSA-3p9v-xp6w-wcmc

больше 4 лет назад

QuickAppsCMS Cross-Site Request Forgery (CSRF)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p9v-cwqh-2mxm

около 2 месяцев назад

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9v-8h44-8rrr

больше 3 лет назад

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3p9v-2c3q-cf4v

почти 2 года назад

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p9r-x2jj-qm7x

почти 4 года назад

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9r-g8j3-8wq4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pc3-3mfc-x5vj

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pc2-v6g3-vwg9

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3pc2-fm7p-q2vg

Cross-site Scripting in October

CVSS3: 3.7
1%
Низкий
около 6 лет назад
github логотип
GHSA-3pc2-c878-63rj

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p9x-xxx6-2w4p

Broken Access Control in 3rd party TYPO3 extension "femanager"

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9x-xxjc-hw5p

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9x-fj5f-w25c

A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9x-34w6-f58v

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-wq67-w93f

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-w3x4-vc62

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-w3g3-89rg

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-pv5h-crrp

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-3p9w-cf27-62fv

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-3p9w-7x8w-2m9v

PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9v-xp6w-wcmc

QuickAppsCMS Cross-Site Request Forgery (CSRF)

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9v-cwqh-2mxm

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3p9v-8h44-8rrr

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9v-2c3q-cf4v

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p9r-x2jj-qm7x

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3p9r-g8j3-8wq4

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу