Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-24g3-3pph-m744

больше 4 лет назад

Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.

EPSS: Низкий
github логотип

GHSA-24g2-j7cx-hj42

больше 4 лет назад

Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.

EPSS: Средний
github логотип

GHSA-24g2-fgx6-x4g7

5 месяцев назад

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-24g2-f5xv-hrqq

больше 4 лет назад

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to remote code execution as root.

EPSS: Низкий
github логотип

GHSA-24g2-6vx6-3vf6

больше 1 года назад

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-24fx-v9pv-mr36

больше 4 лет назад

Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a POST request. NOTE: unlike in CVE-2018-17317, the attacker does not need a valid session.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24fx-4wrx-3r7g

больше 4 лет назад

The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zero arguments.

EPSS: Низкий
github логотип

GHSA-24fw-p524-4547

больше 4 лет назад

Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.

EPSS: Низкий
github логотип

GHSA-24fv-mmr6-7gc5

больше 4 лет назад

Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24fr-xcq3-rqjr

больше 4 лет назад

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24fq-qhc2-ccp5

больше 2 лет назад

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlist.php, in the deleted parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24fp-5v3p-rvpw

3 месяца назад

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

EPSS: Низкий
github логотип

GHSA-24fp-3vjc-ghg3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

EPSS: Низкий
github логотип

GHSA-24fm-hvfw-c28f

4 месяца назад

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24fm-5qww-3rxw

больше 4 лет назад

Freeway 1.5 Alpha allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/Freeway/boxes/last_product.php and certain other files.

EPSS: Низкий
github логотип

GHSA-24fj-mqgp-74gr

больше 1 года назад

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. There is a typo in the affected file name.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-24fj-8r25-f374

больше 4 лет назад

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding to HTTP requests that are sent to the web interface of the software. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web interface of the software on an affected system. A successful exploit could allow the attacker to access sensitive information about the software. The attacker could use this information to conduct additional reconnaissance attacks. Cisco Bug IDs: CSCvc52856.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-24fj-8422-2v9w

больше 4 лет назад

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24fj-279j-cvw2

больше 4 лет назад

Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.

EPSS: Низкий
github логотип

GHSA-24fh-vxfp-5g6v

больше 4 лет назад

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24g3-3pph-m744

Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-24g2-j7cx-hj42

Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.

24%
Средний
больше 4 лет назад
github логотип
GHSA-24g2-fgx6-x4g7

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-24g2-f5xv-hrqq

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to remote code execution as root.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-24g2-6vx6-3vf6

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-24fx-v9pv-mr36

Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a POST request. NOTE: unlike in CVE-2018-17317, the attacker does not need a valid session.

CVSS3: 9.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-24fx-4wrx-3r7g

The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zero arguments.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-24fw-p524-4547

Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-24fv-mmr6-7gc5

Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-24fr-xcq3-rqjr

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-24fq-qhc2-ccp5

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlist.php, in the deleted parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24fp-5v3p-rvpw

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

0%
Низкий
3 месяца назад
github логотип
GHSA-24fp-3vjc-ghg3

Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-24fm-hvfw-c28f

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-24fm-5qww-3rxw

Freeway 1.5 Alpha allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/Freeway/boxes/last_product.php and certain other files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-24fj-mqgp-74gr

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. There is a typo in the affected file name.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24fj-8r25-f374

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding to HTTP requests that are sent to the web interface of the software. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web interface of the software on an affected system. A successful exploit could allow the attacker to access sensitive information about the software. The attacker could use this information to conduct additional reconnaissance attacks. Cisco Bug IDs: CSCvc52856.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-24fj-8422-2v9w

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24fj-279j-cvw2

Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-24fh-vxfp-5g6v

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу