Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-3mjc-cvm2-cpqw

больше 4 лет назад

Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.

EPSS: Низкий
github логотип

GHSA-3mjc-9976-q699

больше 4 лет назад

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

EPSS: Низкий
github логотип

GHSA-3mjc-8px4-f596

больше 4 лет назад

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

EPSS: Низкий
github логотип

GHSA-3mjc-3jvj-6m9f

больше 2 лет назад

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3mj9-vrrp-55v4

9 месяцев назад

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mj9-r4cx-8mx5

больше 4 лет назад

Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mj9-p2pr-gqr4

больше 4 лет назад

A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mj9-c62w-jw5w

больше 4 лет назад

HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3mj9-8h4m-j8f7

почти 3 года назад

Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3mj8-x4jc-gf23

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

EPSS: Низкий
github логотип

GHSA-3mj8-wjf2-5v9c

больше 4 лет назад

HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.

EPSS: Низкий
github логотип

GHSA-3mj8-v2cx-7x5g

больше 4 лет назад

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

EPSS: Средний
github логотип

GHSA-3mj8-5fpc-8c72

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

EPSS: Низкий
github логотип

GHSA-3mj8-3cm6-5whc

больше 4 лет назад

openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mj6-p6q9-4j76

почти 4 года назад

Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mj6-hq84-85g9

больше 2 лет назад

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mj6-3crj-6pcw

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3mj5-5ph7-ggjq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.

EPSS: Низкий
github логотип

GHSA-3mj4-w4vq-39pp

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3mj4-2258-cj4p

больше 4 лет назад

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mjc-cvm2-cpqw

Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjc-9976-q699

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjc-8px4-f596

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjc-3jvj-6m9f

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3mj9-vrrp-55v4

A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3mj9-r4cx-8mx5

Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj9-p2pr-gqr4

A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj9-c62w-jw5w

HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS3: 9.8
100%
Критический
больше 4 лет назад
github логотип
GHSA-3mj9-8h4m-j8f7

Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

CVSS3: 7.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-3mj8-x4jc-gf23

Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj8-wjf2-5v9c

HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj8-v2cx-7x5g

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3mj8-5fpc-8c72

Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj8-3cm6-5whc

openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj6-p6q9-4j76

Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3mj6-hq84-85g9

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mj6-3crj-6pcw

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mj5-5ph7-ggjq

Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj4-w4vq-39pp

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS3: 3.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj4-2258-cj4p

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу