Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3878-g84c-f27c

почти 2 года назад

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3878-8q4v-56w7

4 месяца назад

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3878-7xhc-2g3f

больше 4 лет назад

Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06.

EPSS: Низкий
github логотип

GHSA-3877-qfcm-54mw

больше 4 лет назад

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3877-6pj5-6gwv

12 дней назад

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3876-gmcv-479m

больше 4 лет назад

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3876-f57v-xhhx

больше 4 лет назад

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) "Add video to chat" or (2) "Add video to mood" dialog, a different vector than CVE-2008-0454.

EPSS: Низкий
github логотип

GHSA-3876-9wf2-9986

больше 2 лет назад

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3876-89hf-c4pw

больше 4 лет назад

Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.

EPSS: Низкий
github логотип

GHSA-3875-qp8f-c4m6

больше 4 лет назад

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: Низкий
github логотип

GHSA-3875-qc7c-w94f

больше 2 лет назад

NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3875-gc8x-5cmm

больше 4 лет назад

The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3875-8gcx-7v46

4 месяца назад

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3874-v58r-hmr4

больше 3 лет назад

A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-226102 is the identifier assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3874-c4vv-qxvf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.

EPSS: Низкий
github логотип

GHSA-3873-x9wv-xhwq

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure side), if length of rights string is very large, a buffer over read occurs, exposing TZ App memory to non-secure side.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3873-898q-6f32

больше 4 лет назад

OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.

EPSS: Средний
github логотип

GHSA-3873-529g-4g7g

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP-Lister Lite for eBay allows Reflected XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.6.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3873-3x3p-6gpc

больше 4 лет назад

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3872-f48p-pxqj

больше 4 лет назад

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3878-g84c-f27c

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3878-8q4v-56w7

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.

CVSS3: 3.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3878-7xhc-2g3f

Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3877-qfcm-54mw

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3877-6pj5-6gwv

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

CVSS3: 5.4
0%
Низкий
12 дней назад
github логотип
GHSA-3876-gmcv-479m

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)

CVSS3: 8.8
11%
Средний
больше 4 лет назад
github логотип
GHSA-3876-f57v-xhhx

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) "Add video to chat" or (2) "Add video to mood" dialog, a different vector than CVE-2008-0454.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3876-9wf2-9986

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVSS3: 7.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3876-89hf-c4pw

Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3875-qp8f-c4m6

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3875-qc7c-w94f

NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3875-gc8x-5cmm

The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3875-8gcx-7v46

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

CVSS3: 9.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3874-v58r-hmr4

A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-226102 is the identifier assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3874-c4vv-qxvf

Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3873-x9wv-xhwq

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure side), if length of rights string is very large, a buffer over read occurs, exposing TZ App memory to non-secure side.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3873-898q-6f32

OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3873-529g-4g7g

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP-Lister Lite for eBay allows Reflected XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.6.0.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3873-3x3p-6gpc

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3872-f48p-pxqj

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate

CVSS3: 8.8
4%
Низкий
больше 4 лет назад

Уязвимостей на страницу