Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-29gx-388f-w262

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.

EPSS: Низкий
github логотип

GHSA-29gw-r2hj-fm58

больше 2 лет назад

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-29gw-9793-fvw7

больше 3 лет назад

IPython vulnerable to command injection via set_term_title

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-29gv-cv9c-r93w

7 месяцев назад

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-29gr-w86r-vj34

17 дней назад

A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-29gr-w57f-rpfw

почти 9 лет назад

actionpack vulnerable to Path Traversal

EPSS: Низкий
github логотип

GHSA-29gq-wq8x-vfcr

больше 3 лет назад

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29gq-rw72-mrqg

около 2 лет назад

In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-29gq-h27w-54qf

около 4 лет назад

Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29gp-96hf-p856

больше 3 лет назад

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gp-92wp-94q8

больше 7 лет назад

react-dev-utils on Windows vulnerable to Remote Code Execution

EPSS: Низкий
github логотип

GHSA-29gp-2c3m-3j6m

больше 4 лет назад

Sandbox Escape by math function in smarty

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29gm-gchh-5j4j

больше 1 года назад

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gj-xrph-g435

около 4 лет назад

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-29gj-vxgx-8qph

18 дней назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29gj-jj49-x9g7

почти 3 года назад

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29gh-89p4-ffqv

около 3 лет назад

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29gh-3cpv-qpjp

около 4 лет назад

Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-29gg-qvj7-46c7

около 1 года назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gg-8679-22q3

около 4 лет назад

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29gx-388f-w262

Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-29gw-r2hj-fm58

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.

CVSS3: 9.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-29gw-9793-fvw7

IPython vulnerable to command injection via set_term_title

CVSS3: 4.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-29gv-cv9c-r93w

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

CVSS3: 8.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-29gr-w86r-vj34

A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 7.3
0%
Низкий
17 дней назад
github логотип
GHSA-29gr-w57f-rpfw

actionpack vulnerable to Path Traversal

3%
Низкий
почти 9 лет назад
github логотип
GHSA-29gq-wq8x-vfcr

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29gq-rw72-mrqg

In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.

CVSS3: 7.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-29gq-h27w-54qf

Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-29gp-96hf-p856

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29gp-92wp-94q8

react-dev-utils on Windows vulnerable to Remote Code Execution

3%
Низкий
больше 7 лет назад
github логотип
GHSA-29gp-2c3m-3j6m

Sandbox Escape by math function in smarty

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-29gm-gchh-5j4j

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-29gj-xrph-g435

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.

CVSS3: 4.4
3%
Низкий
около 4 лет назад
github логотип
GHSA-29gj-vxgx-8qph

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.

CVSS3: 7.1
0%
Низкий
18 дней назад
github логотип
GHSA-29gj-jj49-x9g7

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
2%
Низкий
почти 3 года назад
github логотип
GHSA-29gh-89p4-ffqv

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-29gh-3cpv-qpjp

Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection.

CVSS3: 2.3
4%
Низкий
около 4 лет назад
github логотип
GHSA-29gg-qvj7-46c7

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
2%
Низкий
около 1 года назад
github логотип
GHSA-29gg-8679-22q3

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
2%
Низкий
около 4 лет назад

Уязвимостей на страницу