Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-23p3-vg9x-qw6p

больше 4 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

EPSS: Низкий
github логотип

GHSA-23p3-vcf6-94xq

почти 3 года назад

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23p3-rx33-wm34

больше 4 лет назад

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

EPSS: Низкий
github логотип

GHSA-23p3-9m3p-qpwp

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23p2-2jrp-5wcp

почти 2 года назад

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23mx-m43g-r4fh

около 1 года назад

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-23mx-4w8p-jgwp

2 месяца назад

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23mw-hwq9-w4q8

почти 3 года назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mr-m7vf-wgmp

больше 4 лет назад

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-23mr-c4wx-m5rr

больше 4 лет назад

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23mm-fp65-w636

больше 3 лет назад

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23mm-62vv-wv83

почти 4 года назад

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-23mj-f5f2-4h46

больше 1 года назад

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mh-p5gr-48gh

больше 4 лет назад

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-23mh-jxf4-vm3h

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-23mg-qphc-9fg5

больше 4 лет назад

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

EPSS: Низкий
github логотип

GHSA-23mg-c4fv-vfxj

11 дней назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23mg-57wx-h29h

больше 4 лет назад

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

EPSS: Низкий
github логотип

GHSA-23mf-2ffr-xmv9

больше 4 лет назад

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-23mc-xgfq-qhjf

больше 4 лет назад

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23p3-vg9x-qw6p

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23p3-vcf6-94xq

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-23p3-rx33-wm34

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23p3-9m3p-qpwp

Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-23p2-2jrp-5wcp

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-23mx-m43g-r4fh

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-23mx-4w8p-jgwp

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-23mw-hwq9-w4q8

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-23mr-m7vf-wgmp

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mr-c4wx-m5rr

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23mm-fp65-w636

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23mm-62vv-wv83

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
69%
Средний
почти 4 года назад
github логотип
GHSA-23mj-f5f2-4h46

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-23mh-p5gr-48gh

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mh-jxf4-vm3h

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-23mg-qphc-9fg5

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mg-c4fv-vfxj

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 5.4
0%
Низкий
11 дней назад
github логотип
GHSA-23mg-57wx-h29h

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23mf-2ffr-xmv9

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVSS3: 9.8
17%
Средний
больше 4 лет назад
github логотип
GHSA-23mc-xgfq-qhjf

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу