Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-23p3-rx33-wm34

около 4 лет назад

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

EPSS: Низкий
github логотип

GHSA-23p3-9m3p-qpwp

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23p2-2jrp-5wcp

почти 2 года назад

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23mx-m43g-r4fh

около 1 года назад

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-23mx-4w8p-jgwp

около 2 месяцев назад

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23mw-hwq9-w4q8

почти 3 года назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mr-m7vf-wgmp

около 4 лет назад

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-23mr-c4wx-m5rr

около 4 лет назад

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23mm-fp65-w636

больше 3 лет назад

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23mm-62vv-wv83

почти 4 года назад

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-23mj-f5f2-4h46

больше 1 года назад

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mh-p5gr-48gh

больше 4 лет назад

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-23mh-jxf4-vm3h

около 4 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-23mg-qphc-9fg5

больше 4 лет назад

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

EPSS: Низкий
github логотип

GHSA-23mg-57wx-h29h

около 4 лет назад

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

EPSS: Низкий
github логотип

GHSA-23mf-2ffr-xmv9

больше 4 лет назад

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-23mc-xgfq-qhjf

около 4 лет назад

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

EPSS: Низкий
github логотип

GHSA-23mc-xgfj-48f2

больше 3 лет назад

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23m9-rr4p-xpwh

3 месяца назад

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23m7-v83h-jpr5

около 3 лет назад

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23p3-rx33-wm34

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23p3-9m3p-qpwp

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-23p2-2jrp-5wcp

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-23mx-m43g-r4fh

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-23mx-4w8p-jgwp

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-23mw-hwq9-w4q8

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-23mr-m7vf-wgmp

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

3%
Низкий
около 4 лет назад
github логотип
GHSA-23mr-c4wx-m5rr

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-23mm-fp65-w636

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23mm-62vv-wv83

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
68%
Средний
почти 4 года назад
github логотип
GHSA-23mj-f5f2-4h46

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-23mh-p5gr-48gh

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mh-jxf4-vm3h

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

6%
Низкий
около 4 лет назад
github логотип
GHSA-23mg-qphc-9fg5

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mg-57wx-h29h

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

3%
Низкий
около 4 лет назад
github логотип
GHSA-23mf-2ffr-xmv9

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVSS3: 9.8
17%
Средний
больше 4 лет назад
github логотип
GHSA-23mc-xgfq-qhjf

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23mc-xgfj-48f2

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23m9-rr4p-xpwh

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-23m7-v83h-jpr5

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.

CVSS3: 6.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу