Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35q5-4f7h-p787

2 месяца назад

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged Application Server executes to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35q4-rjfj-7r6x

около 2 месяцев назад

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35q3-4p7p-rfwc

больше 4 лет назад

Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.

EPSS: Низкий
github логотип

GHSA-35q3-3jc2-w9w3

больше 3 лет назад

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35q2-47q7-3pc3

больше 5 лет назад

Node-Redis potential exponential regex in monitor mode

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35px-6m82-p8rw

почти 4 года назад

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35pw-jwxr-q4v2

больше 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35pv-r327-8m4j

около 2 лет назад

Missing Authorization vulnerability in Tobias Conrad Get Better Reviews for WooCommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through 4.0.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35pv-8c58-rxqx

больше 4 лет назад

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-35pr-gqm6-r366

больше 4 лет назад

Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information

EPSS: Низкий
github логотип

GHSA-35pq-x9mv-j9hq

9 месяцев назад

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-35pq-fvh7-h49r

больше 4 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

EPSS: Низкий
github логотип

GHSA-35pq-7pv2-2rfw

больше 1 года назад

ps_contactinfo has a potential XSS due to usage of the nofilter tag in template

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-35pp-gpq2-4898

3 месяца назад

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-35pp-4j8v-5825

больше 4 лет назад

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-35pm-xrv5-x4qv

больше 4 лет назад

IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35pm-rxh5-93qj

больше 4 лет назад

Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.

EPSS: Низкий
github логотип

GHSA-35pm-7mgg-xfm6

больше 4 лет назад

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

EPSS: Низкий
github логотип

GHSA-35pj-p27v-5rpc

9 месяцев назад

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35pj-cxpm-pvh5

больше 4 лет назад

Prototype pollution vulnerability in 'cache-base' versions 0.7.0 through 4.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35q5-4f7h-p787

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged Application Server executes to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-35q4-rjfj-7r6x

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-35q3-4p7p-rfwc

Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35q3-3jc2-w9w3

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35q2-47q7-3pc3

Node-Redis potential exponential regex in monitor mode

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
github логотип
GHSA-35px-6m82-p8rw

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-35pw-jwxr-q4v2

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-35pv-r327-8m4j

Missing Authorization vulnerability in Tobias Conrad Get Better Reviews for WooCommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through 4.0.6.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-35pv-8c58-rxqx

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35pr-gqm6-r366

Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35pq-x9mv-j9hq

The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee widget in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-35pq-fvh7-h49r

In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35pq-7pv2-2rfw

ps_contactinfo has a potential XSS due to usage of the nofilter tag in template

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-35pp-gpq2-4898

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-35pp-4j8v-5825

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35pm-xrv5-x4qv

IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35pm-rxh5-93qj

Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35pm-7mgg-xfm6

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35pj-p27v-5rpc

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

CVSS3: 7.1
10%
Низкий
9 месяцев назад
github логотип
GHSA-35pj-cxpm-pvh5

Prototype pollution vulnerability in 'cache-base' versions 0.7.0 through 4.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

больше 4 лет назад

Уязвимостей на страницу