Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2943-9672-r45w

25 дней назад

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2943-53pm-phm4

около 4 лет назад

Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

EPSS: Низкий
github логотип

GHSA-2943-4gp2-qhj2

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2942-p8v5-q78c

больше 4 лет назад

Windows Kerberos Elevation of Privilege Vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2942-jp7w-55rc

больше 2 лет назад

An issue in GLPI v.10.0.12 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the title field.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-293x-x4gc-p56j

около 4 лет назад

Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.

EPSS: Низкий
github логотип

GHSA-293x-mf2v-87jf

около 4 лет назад

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

EPSS: Низкий
github логотип

GHSA-293x-f7pv-38xc

10 дней назад

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-293x-92j8-gvrh

около 2 лет назад

Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-293w-8h49-x8x8

около 3 лет назад

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-293v-5329-36wp

около 3 лет назад

MCMS vulnerable to arbitrary code execution via crafted thumbnail

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-293v-32vx-9g86

больше 2 лет назад

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293r-hxw5-cfmj

3 месяца назад

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-293r-f52g-2w34

больше 4 лет назад

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

EPSS: Низкий
github логотип

GHSA-293r-4r95-pff2

около 4 лет назад

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-293q-vg2m-m48p

около 4 лет назад

SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-293q-m4h6-56g9

8 месяцев назад

OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-293q-jm6v-g4pw

больше 2 лет назад

The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-293q-5pc2-p657

10 дней назад

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293q-567p-wmwq

около 2 месяцев назад

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2943-9672-r45w

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist.

CVSS3: 9.8
1%
Низкий
25 дней назад
github логотип
GHSA-2943-53pm-phm4

Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2943-4gp2-qhj2

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2942-p8v5-q78c

Windows Kerberos Elevation of Privilege Vulnerability.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2942-jp7w-55rc

An issue in GLPI v.10.0.12 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the title field.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-293x-x4gc-p56j

Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.

8%
Низкий
около 4 лет назад
github логотип
GHSA-293x-mf2v-87jf

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

0%
Низкий
около 4 лет назад
github логотип
GHSA-293x-f7pv-38xc

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
0%
Низкий
10 дней назад
github логотип
GHSA-293x-92j8-gvrh

Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-293w-8h49-x8x8

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-293v-5329-36wp

MCMS vulnerable to arbitrary code execution via crafted thumbnail

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-293v-32vx-9g86

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-293r-hxw5-cfmj

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
3 месяца назад
github логотип
GHSA-293r-f52g-2w34

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-293r-4r95-pff2

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

0%
Низкий
около 4 лет назад
github логотип
GHSA-293q-vg2m-m48p

SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-293q-m4h6-56g9

OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVSS3: 8.8
2%
Низкий
8 месяцев назад
github логотип
GHSA-293q-jm6v-g4pw

The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-293q-5pc2-p657

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
10 дней назад
github логотип
GHSA-293q-567p-wmwq

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу