Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-394f-8grw-xrm8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.

EPSS: Низкий
github логотип

GHSA-394c-5j6w-4xmx

больше 4 лет назад

ua-parser-js Regular Expression Denial of Service vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3949-wvqv-jcq4

больше 4 лет назад

A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.

EPSS: Низкий
github логотип

GHSA-3949-f494-cm99

больше 4 лет назад

Cross-site Scripting in Prism

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3949-74rr-85j5

около 2 лет назад

The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an application with a malicious name.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3948-x4f5-75xx

больше 4 лет назад

The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-3948-p33j-2mqm

почти 4 года назад

Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3947-v5cg-rpwj

больше 1 года назад

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3946-qxr3-66h7

больше 4 лет назад

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

EPSS: Средний
github логотип

GHSA-3945-6x88-h7vv

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

EPSS: Низкий
github логотип

GHSA-3944-787c-f852

больше 6 лет назад

Persistent Cross-Site scripting in Nexus Repository Manager

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3944-77rg-ppg5

больше 4 лет назад

Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.

EPSS: Низкий
github логотип

GHSA-3943-mgp9-h6fv

около 2 месяцев назад

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3943-gw8x-8ppm

больше 4 лет назад

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34125463. References: QC-CR#1115406.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3943-4f4j-gcgj

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg When len >= INT_MAX - transhdrlen, ulen = len + transhdrlen will be overflow. To fix, we can follow what udpv6 does and subtract the transhdrlen from the max.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3942-ccxx-8xqv

больше 4 лет назад

Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-3942-82qw-f9qh

почти 3 года назад

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3942-5prh-7v6g

больше 4 лет назад

PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116.

EPSS: Средний
github логотип

GHSA-393x-fr59-r8fg

больше 4 лет назад

statics-server Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-393x-72qj-vrh3

больше 4 лет назад

S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to CVE-2019-9040.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-394f-8grw-xrm8

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-394c-5j6w-4xmx

ua-parser-js Regular Expression Denial of Service vulnerability

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3949-wvqv-jcq4

A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3949-f494-cm99

Cross-site Scripting in Prism

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3949-74rr-85j5

The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an application with a malicious name.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3948-x4f5-75xx

The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3948-p33j-2mqm

Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-3947-v5cg-rpwj

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3946-qxr3-66h7

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

45%
Средний
больше 4 лет назад
github логотип
GHSA-3945-6x88-h7vv

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3944-787c-f852

Persistent Cross-Site scripting in Nexus Repository Manager

CVSS3: 4.8
1%
Низкий
больше 6 лет назад
github логотип
GHSA-3944-77rg-ppg5

Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3943-mgp9-h6fv

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3943-gw8x-8ppm

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34125463. References: QC-CR#1115406.

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3943-4f4j-gcgj

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix signed integer overflow in l2tp_ip6_sendmsg When len >= INT_MAX - transhdrlen, ulen = len + transhdrlen will be overflow. To fix, we can follow what udpv6 does and subtract the transhdrlen from the max.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3942-ccxx-8xqv

Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.

37%
Средний
больше 4 лет назад
github логотип
GHSA-3942-82qw-f9qh

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

CVSS3: 4.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-3942-5prh-7v6g

PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116.

17%
Средний
больше 4 лет назад
github логотип
GHSA-393x-fr59-r8fg

statics-server Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-393x-72qj-vrh3

S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to CVE-2019-9040.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу