Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-34x7-h5wm-79jf

около 2 лет назад

A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34x7-7wfj-jp4r

1 день назад

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing path validation to read any file accessible to the service, with disclosure limited to files matching expected JSON structures that are then written to datasets.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34x7-2qqc-3mxq

больше 4 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34x6-gmv7-8394

больше 4 лет назад

SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.

EPSS: Низкий
github логотип

GHSA-34x5-w6rv-c97v

около 2 лет назад

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34x5-h37x-3w3p

больше 4 лет назад

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-34x5-g49j-7c65

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

EPSS: Низкий
github логотип

GHSA-34x5-95ff-w3cg

больше 4 лет назад

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges to gain administrator privileges.

EPSS: Низкий
github логотип

GHSA-34x3-j83x-4r5v

около 3 лет назад

A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235250 is the identifier assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-34x3-76m3-g8f7

больше 3 лет назад

Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34x3-6phf-9f2j

больше 4 лет назад

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34x2-m38g-824f

6 месяцев назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34wx-x2w9-vqm3

больше 4 лет назад

DoS vulnerability in bundled XStream library in Jenkins Core

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34wx-v4h8-8xh4

больше 4 лет назад

Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information disclosure via network access.

EPSS: Низкий
github логотип

GHSA-34wx-3jmq-rv2m

больше 1 года назад

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-34wx-3364-j343

больше 4 лет назад

PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.

EPSS: Средний
github логотип

GHSA-34wv-v24v-vm88

больше 4 лет назад

An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.

EPSS: Низкий
github логотип

GHSA-34wv-gh47-86r8

больше 2 лет назад

BitLocker Security Feature Bypass Vulnerability

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-34wv-c7h9-3524

7 месяцев назад

SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34wv-75jw-6v6p

4 месяца назад

A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to argument injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34x7-h5wm-79jf

A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-34x7-7wfj-jp4r

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing path validation to read any file accessible to the service, with disclosure limited to files matching expected JSON structures that are then written to datasets.

CVSS3: 4.3
1 день назад
github логотип
GHSA-34x7-2qqc-3mxq

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-34x6-gmv7-8394

SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34x5-w6rv-c97v

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-34x5-h37x-3w3p

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34x5-g49j-7c65

Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34x5-95ff-w3cg

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges to gain administrator privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34x3-j83x-4r5v

A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235250 is the identifier assigned to this vulnerability.

CVSS3: 3.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-34x3-76m3-g8f7

Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34x3-6phf-9f2j

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34x2-m38g-824f

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-34wx-x2w9-vqm3

DoS vulnerability in bundled XStream library in Jenkins Core

CVSS3: 6.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-34wx-v4h8-8xh4

Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information disclosure via network access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34wx-3jmq-rv2m

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-34wx-3364-j343

PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.

64%
Средний
больше 4 лет назад
github логотип
GHSA-34wv-v24v-vm88

An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wv-gh47-86r8

BitLocker Security Feature Bypass Vulnerability

CVSS3: 6.6
3%
Низкий
больше 2 лет назад
github логотип
GHSA-34wv-c7h9-3524

SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-34wv-75jw-6v6p

A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to argument injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
4 месяца назад

Уязвимостей на страницу