Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-23p4-qm9x-842q

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23p4-5ppc-536p

больше 4 лет назад

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

EPSS: Низкий
github логотип

GHSA-23p3-vg9x-qw6p

больше 4 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

EPSS: Низкий
github логотип

GHSA-23p3-vcf6-94xq

почти 3 года назад

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23p3-rx33-wm34

около 4 лет назад

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

EPSS: Низкий
github логотип

GHSA-23p3-9m3p-qpwp

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23p2-2jrp-5wcp

почти 2 года назад

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23mx-m43g-r4fh

около 1 года назад

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-23mx-4w8p-jgwp

2 месяца назад

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23mw-hwq9-w4q8

почти 3 года назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mr-m7vf-wgmp

больше 4 лет назад

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-23mr-c4wx-m5rr

больше 4 лет назад

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23mm-fp65-w636

больше 3 лет назад

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23mm-62vv-wv83

почти 4 года назад

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-23mj-f5f2-4h46

больше 1 года назад

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mh-p5gr-48gh

больше 4 лет назад

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-23mh-jxf4-vm3h

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-23mg-qphc-9fg5

больше 4 лет назад

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

EPSS: Низкий
github логотип

GHSA-23mg-c4fv-vfxj

1 день назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23mg-57wx-h29h

около 4 лет назад

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23p4-qm9x-842q

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23p4-5ppc-536p

Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23p3-vg9x-qw6p

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23p3-vcf6-94xq

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-23p3-rx33-wm34

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23p3-9m3p-qpwp

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-23p2-2jrp-5wcp

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-23mx-m43g-r4fh

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-23mx-4w8p-jgwp

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-23mw-hwq9-w4q8

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-23mr-m7vf-wgmp

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mr-c4wx-m5rr

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23mm-fp65-w636

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23mm-62vv-wv83

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
68%
Средний
почти 4 года назад
github логотип
GHSA-23mj-f5f2-4h46

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-23mh-p5gr-48gh

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mh-jxf4-vm3h

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-23mg-qphc-9fg5

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mg-c4fv-vfxj

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 5.4
0%
Низкий
1 день назад
github логотип
GHSA-23mg-57wx-h29h

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

3%
Низкий
около 4 лет назад

Уязвимостей на страницу