Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-22cr-447g-57w6

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Tahir Ali Jan Bulk YouTube Post Creator allows Reflected XSS. This issue affects Bulk YouTube Post Creator: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22cq-xxr9-jrrv

около 4 лет назад

Zenario CMS vulnerable to CSRF

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22cq-qqmm-44qr

больше 1 года назад

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-22cq-h96p-qcc2

больше 3 лет назад

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22cq-cq7f-8jm3

около 4 лет назад

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22cp-w34c-5qxr

почти 4 года назад

The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) through 2022-06-27 performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-22cp-hq23-fv85

9 месяцев назад

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages.  The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22cp-6jm2-7pjh

больше 4 лет назад

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

EPSS: Средний
github логотип

GHSA-22cm-3qf2-2wc7

больше 5 лет назад

LDAP Injection in is-user-valid

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22cj-m4wf-fv2c

около 2 месяцев назад

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22cj-gf6g-gpgc

12 месяцев назад

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22ch-h6m8-g2vp

около 2 месяцев назад

Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-22cf-8wqp-mvp7

больше 4 лет назад

Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

EPSS: Низкий
github логотип

GHSA-22cf-67wm-xj29

больше 1 года назад

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22cc-w7xm-rfhx

больше 2 лет назад

Mezzanine allows attackers to bypass access controls via manipulating the Host header

EPSS: Низкий
github логотип

GHSA-22cc-qxwq-jx65

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-22cc-p3c6-wpvm

5 месяцев назад

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22cc-j8pf-c532

около 4 лет назад

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to AX/HI Web UI.

EPSS: Низкий
github логотип

GHSA-22cc-5v95-5pqq

больше 4 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22c9-qjc2-9748

около 4 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22cr-447g-57w6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Tahir Ali Jan Bulk YouTube Post Creator allows Reflected XSS. This issue affects Bulk YouTube Post Creator: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-22cq-xxr9-jrrv

Zenario CMS vulnerable to CSRF

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-22cq-qqmm-44qr

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-22cq-h96p-qcc2

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22cq-cq7f-8jm3

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS3: 9.8
8%
Низкий
около 4 лет назад
github логотип
GHSA-22cp-w34c-5qxr

The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) through 2022-06-27 performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
github логотип
GHSA-22cp-hq23-fv85

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages.  The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-22cp-6jm2-7pjh

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

19%
Средний
больше 4 лет назад
github логотип
GHSA-22cm-3qf2-2wc7

LDAP Injection in is-user-valid

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
github логотип
GHSA-22cj-m4wf-fv2c

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

CVSS3: 7.5
около 2 месяцев назад
github логотип
GHSA-22cj-gf6g-gpgc

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-22ch-h6m8-g2vp

Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22cf-8wqp-mvp7

Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-22cf-67wm-xj29

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-22cc-w7xm-rfhx

Mezzanine allows attackers to bypass access controls via manipulating the Host header

1%
Низкий
больше 2 лет назад
github логотип
GHSA-22cc-qxwq-jx65

Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-22cc-p3c6-wpvm

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

CVSS3: 7.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-22cc-j8pf-c532

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to AX/HI Web UI.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22cc-5v95-5pqq

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-22c9-qjc2-9748

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу