Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-25q7-hhvp-2gr6

больше 4 лет назад

RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials that were used.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25q7-6x5v-rx9h

больше 4 лет назад

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-25q6-m425-9fqr

около 4 лет назад

Feehi CMS Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-25q5-cv5r-qpp9

около 4 лет назад

Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.

EPSS: Низкий
github логотип

GHSA-25q4-mg92-89j6

больше 4 лет назад

Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-25q4-66ch-jm5r

около 2 лет назад

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that causes the vulnerable script to execute.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-25q4-2c75-g7c9

около 4 лет назад

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2804.

EPSS: Средний
github логотип

GHSA-25q3-x68m-7xf6

около 4 лет назад

Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header.

EPSS: Низкий
github логотип

GHSA-25q3-mc3p-85jx

почти 2 года назад

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-25q2-mm9v-fcj8

6 месяцев назад

A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25px-qwqc-5cg6

около 1 года назад

InCopy versions 20.2, 19.5.3 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25px-mjfm-j7v4

около 4 лет назад

Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) currencies.php, (3) exchange_rates.php, (4) gl_account_types.php, and (5) gl_accounts.php in gl/manage/; and (6) audit_trail_db.inc, (7) comments_db.inc, (8) inventory_db.inc, (9) manufacturing_db.inc, and (10) references_db.inc in includes/db/.

EPSS: Низкий
github логотип

GHSA-25px-gj7m-w9m3

4 месяца назад

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-25px-79m5-c52x

около 4 лет назад

Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-25pw-q952-x37g

почти 2 года назад

Duplicate Advisory: pyload-ng vulnerable to RCE with js2py sandbox escape

EPSS: Низкий
github логотип

GHSA-25pw-4h6w-qwvm

5 месяцев назад

OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25pv-rw22-6jxg

около 1 года назад

A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=calculate_payroll. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-25pv-m7gv-3gwr

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.

EPSS: Низкий
github логотип

GHSA-25pv-7q9q-qqjc

больше 3 лет назад

Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack of JavaScript request string sanitization. Using this vulnerability, an authenticated attacker can execute arbitrary HTML and script code in the target browser against another Metasploit Pro user using a specially crafted request. Note that in most deployments, all Metasploit Pro users tend to enjoy privileges equivalent to local administrator.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-25pv-5r6h-55j6

больше 4 лет назад

The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25q7-hhvp-2gr6

RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials that were used.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25q7-6x5v-rx9h

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

CVSS3: 8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25q6-m425-9fqr

Feehi CMS Cross-site Scripting

CVSS3: 5.4
5%
Низкий
около 4 лет назад
github логотип
GHSA-25q5-cv5r-qpp9

Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25q4-mg92-89j6

Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-25q4-66ch-jm5r

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that causes the vulnerable script to execute.

CVSS3: 5.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-25q4-2c75-g7c9

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2804.

16%
Средний
около 4 лет назад
github логотип
GHSA-25q3-x68m-7xf6

Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header.

5%
Низкий
около 4 лет назад
github логотип
GHSA-25q3-mc3p-85jx

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-25q2-mm9v-fcj8

A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-25px-qwqc-5cg6

InCopy versions 20.2, 19.5.3 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-25px-mjfm-j7v4

Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) currencies.php, (3) exchange_rates.php, (4) gl_account_types.php, and (5) gl_accounts.php in gl/manage/; and (6) audit_trail_db.inc, (7) comments_db.inc, (8) inventory_db.inc, (9) manufacturing_db.inc, and (10) references_db.inc in includes/db/.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25px-gj7m-w9m3

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

CVSS3: 4.8
0%
Низкий
4 месяца назад
github логотип
GHSA-25px-79m5-c52x

Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25pw-q952-x37g

Duplicate Advisory: pyload-ng vulnerable to RCE with js2py sandbox escape

почти 2 года назад
github логотип
GHSA-25pw-4h6w-qwvm

OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-25pv-rw22-6jxg

A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=calculate_payroll. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-25pv-m7gv-3gwr

Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25pv-7q9q-qqjc

Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack of JavaScript request string sanitization. Using this vulnerability, an authenticated attacker can execute arbitrary HTML and script code in the target browser against another Metasploit Pro user using a specially crafted request. Note that in most deployments, all Metasploit Pro users tend to enjoy privileges equivalent to local administrator.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25pv-5r6h-55j6

The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу