Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-xqcx-wqc2-rjfv

почти 4 года назад

SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xqcx-6mm2-fv2j

больше 2 лет назад

In Abbott ID NOW before 7.1, settings can be modified via physical access to an internal serial port.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xqcw-gm88-2753

почти 4 года назад

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqcv-p45j-c72q

больше 2 лет назад

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqcv-fgfh-v26g

почти 4 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-xqcr-vmvx-c673

почти 4 года назад

SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

EPSS: Средний
github логотип

GHSA-xqcr-r97c-wq7p

4 месяца назад

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xqcq-xphx-4p87

почти 4 года назад

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqcq-j8w9-3pxv

больше 2 лет назад

Jettison parser crash by stackoverflow

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqcp-x2j9-xj7c

почти 4 года назад

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

EPSS: Низкий
github логотип

GHSA-xqcp-jqmf-35jv

почти 4 года назад

A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqcp-9p67-2j64

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when using fscache If we hit the 'index == next_cached' case, we leak a refcount on the struct page. Fix this by using readahead_folio() which takes care of the refcount for you.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqcp-4jqv-37rh

больше 2 лет назад

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqcm-xjf8-jp3p

почти 4 года назад

Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

EPSS: Средний
github логотип

GHSA-xqcm-jrw9-wq72

около 2 месяцев назад

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqcm-7p74-m69m

9 месяцев назад

The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php), via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xqcj-wpcf-8vvg

почти 4 года назад

CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.

EPSS: Низкий
github логотип

GHSA-xqch-rc2w-pgwf

почти 4 года назад

An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqcg-xx67-m64q

около 4 лет назад

In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqcg-wphj-2xhm

почти 4 года назад

Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqcx-wqc2-rjfv

SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqcx-6mm2-fv2j

In Abbott ID NOW before 7.1, settings can be modified via physical access to an internal serial port.

CVSS3: 5.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqcw-gm88-2753

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqcv-p45j-c72q

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqcv-fgfh-v26g

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqcr-vmvx-c673

SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

21%
Средний
почти 4 года назад
github логотип
GHSA-xqcr-r97c-wq7p

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

CVSS3: 4.6
0%
Низкий
4 месяца назад
github логотип
GHSA-xqcq-xphx-4p87

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqcq-j8w9-3pxv

Jettison parser crash by stackoverflow

CVSS3: 6.5
больше 2 лет назад
github логотип
GHSA-xqcp-x2j9-xj7c

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqcp-jqmf-35jv

A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqcp-9p67-2j64

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when using fscache If we hit the 'index == next_cached' case, we leak a refcount on the struct page. Fix this by using readahead_folio() which takes care of the refcount for you.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xqcp-4jqv-37rh

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqcm-xjf8-jp3p

Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

27%
Средний
почти 4 года назад
github логотип
GHSA-xqcm-jrw9-wq72

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xqcm-7p74-m69m

The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php), via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xqcj-wpcf-8vvg

CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xqch-rc2w-pgwf

An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqcg-xx67-m64q

In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xqcg-wphj-2xhm

Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу