Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-25rc-xhj7-mqxj

около 4 лет назад

A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 V5.X (All versions < V5.5 SP4 HF11), SIMATIC WinCC (TIA Portal) Basic, Comfort, Advanced (All versions < V14), SIMATIC WinCC (TIA Portal) Professional V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) Professional V14 (All versions < V14 SP1), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1), SIMATIC WinCC V7.0 SP2 and earlier versions (All versions < V7.0 SP2 Upd 12), SIMATIC WinCC V7.0 SP3 (All versions < V7.0 SP3 Upd 8), SIMATIC WinCC V7.2 (All versions < V7.2 Upd 14), SIMATIC Win...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-25rc-v26v-6w83

около 1 года назад

The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25rc-9mcg-m884

около 4 лет назад

** DISPUTED ** The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25rc-3m9x-wr5g

около 2 лет назад

Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25r9-gpg2-xcwf

около 4 лет назад

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-25r8-4ph4-p8ww

около 4 лет назад

Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347.

EPSS: Низкий
github логотип

GHSA-25r6-p769-mwpx

около 4 лет назад

Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.

EPSS: Низкий
github логотип

GHSA-25r6-gqj3-prpr

3 месяца назад

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation of the argument troiaCode results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-25r6-8rph-4cc3

около 4 лет назад

In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25r6-8q2p-7878

около 4 лет назад

Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.

EPSS: Низкий
github логотип

GHSA-25r5-rrxc-5jjh

около 4 лет назад

Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as demonstrated by creating a new .php file that permits remote file inclusion, and then requesting this file.

EPSS: Низкий
github логотип

GHSA-25r5-g9mw-wmpc

около 4 лет назад

, aka 'Dynamics CRM Webclient Cross-site Scripting Vulnerability'.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-25r5-fcrf-9795

около 4 лет назад

NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25r5-69f6-hgcg

больше 4 лет назад

Skype for Business Information Disclosure Vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25r4-xgpc-p9hq

около 4 лет назад

SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID parameter to the default URI.

EPSS: Низкий
github логотип

GHSA-25r4-89vx-h95c

около 3 лет назад

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25r4-295r-fvqm

около 4 лет назад

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25r3-fx4p-7qc5

около 4 лет назад

Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

EPSS: Низкий
github логотип

GHSA-25r3-9hc8-wv3w

около 4 лет назад

An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-25r3-37cq-xj9m

около 4 лет назад

A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to exhaust available resources and cause a DoS condition on an affected AP, as well as a DoS condition for client traffic traversing the AP.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25rc-xhj7-mqxj

A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 V5.X (All versions < V5.5 SP4 HF11), SIMATIC WinCC (TIA Portal) Basic, Comfort, Advanced (All versions < V14), SIMATIC WinCC (TIA Portal) Professional V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) Professional V14 (All versions < V14 SP1), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1), SIMATIC WinCC V7.0 SP2 and earlier versions (All versions < V7.0 SP2 Upd 12), SIMATIC WinCC V7.0 SP3 (All versions < V7.0 SP3 Upd 8), SIMATIC WinCC V7.2 (All versions < V7.2 Upd 14), SIMATIC Win...

CVSS3: 6.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-25rc-v26v-6w83

The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary users.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-25rc-9mcg-m884

** DISPUTED ** The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot.

CVSS3: 6.1
5%
Низкий
около 4 лет назад
github логотип
GHSA-25rc-3m9x-wr5g

Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-25r9-gpg2-xcwf

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework.

CVSS3: 5.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-25r8-4ph4-p8ww

Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347.

0%
Низкий
около 4 лет назад
github логотип
GHSA-25r6-p769-mwpx

Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.

3%
Низкий
около 4 лет назад
github логотип
GHSA-25r6-gqj3-prpr

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation of the argument troiaCode results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
3 месяца назад
github логотип
GHSA-25r6-8rph-4cc3

In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-25r6-8q2p-7878

Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.

9%
Низкий
около 4 лет назад
github логотип
GHSA-25r5-rrxc-5jjh

Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as demonstrated by creating a new .php file that permits remote file inclusion, and then requesting this file.

3%
Низкий
около 4 лет назад
github логотип
GHSA-25r5-g9mw-wmpc

, aka 'Dynamics CRM Webclient Cross-site Scripting Vulnerability'.

CVSS3: 8.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-25r5-fcrf-9795

NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.

CVSS3: 9.8
8%
Низкий
около 4 лет назад
github логотип
GHSA-25r5-69f6-hgcg

Skype for Business Information Disclosure Vulnerability.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-25r4-xgpc-p9hq

SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID parameter to the default URI.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25r4-89vx-h95c

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVSS3: 9.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-25r4-295r-fvqm

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-25r3-fx4p-7qc5

Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25r3-9hc8-wv3w

An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

CVSS3: 5.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-25r3-37cq-xj9m

A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to exhaust available resources and cause a DoS condition on an affected AP, as well as a DoS condition for client traffic traversing the AP.

CVSS3: 8.6
1%
Низкий
около 4 лет назад

Уязвимостей на страницу