Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-2542-9qv5-j3j9

около 1 года назад

phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testing.php file, due to insufficient validation of user input for the " govtissuedid" parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-253w-x2w8-p697

около 1 года назад

A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-253w-rh2x-47g3

5 месяцев назад

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-253w-3f25-wwwm

больше 4 лет назад

An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to connect to a WePresent presentation system.

EPSS: Низкий
github логотип

GHSA-253v-865x-49j8

больше 4 лет назад

The wEPISDParentPortal (aka com.dreamstep.wEPISDParentPortal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-253r-m962-f83q

больше 4 лет назад

Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to cause a denial of service attack remotely via a specially crafted GET request with a leading "/" in the URL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-253r-3vgg-gj92

больше 4 лет назад

In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE).

EPSS: Низкий
github логотип

GHSA-253q-prr2-4prx

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-253q-9q78-63x4

8 месяцев назад

Clatter has a PSK Validity Rule Violation issue

EPSS: Низкий
github логотип

GHSA-253q-85fr-vjfv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-253p-g49j-p89x

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.

EPSS: Низкий
github логотип

GHSA-253p-9p9w-rg6r

7 месяцев назад

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-253p-896q-pwmq

около 4 лет назад

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203440.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-253m-678w-hcj3

больше 4 лет назад

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-253m-4wjm-2prr

больше 4 лет назад

Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-253j-mgc4-hp35

больше 4 лет назад

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-253h-f8wh-gcxr

6 месяцев назад

TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction pointer with malicious addresses.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-253h-63vc-5w2v

больше 4 лет назад

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.

EPSS: Низкий
github логотип

GHSA-253g-w96v-v3cj

больше 4 лет назад

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.

EPSS: Низкий
github логотип

GHSA-253g-rphr-6h5j

почти 2 года назад

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2542-9qv5-j3j9

phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testing.php file, due to insufficient validation of user input for the " govtissuedid" parameter.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-253w-x2w8-p697

A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-253w-rh2x-47g3

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-253w-3f25-wwwm

An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to connect to a WePresent presentation system.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-253v-865x-49j8

The wEPISDParentPortal (aka com.dreamstep.wEPISDParentPortal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-253r-m962-f83q

Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to cause a denial of service attack remotely via a specially crafted GET request with a leading "/" in the URL.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-253r-3vgg-gj92

In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-253q-prr2-4prx

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-253q-9q78-63x4

Clatter has a PSK Validity Rule Violation issue

0%
Низкий
8 месяцев назад
github логотип
GHSA-253q-85fr-vjfv

Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-253p-g49j-p89x

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-253p-9p9w-rg6r

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload

CVSS3: 9.8
2%
Низкий
7 месяцев назад
github логотип
GHSA-253p-896q-pwmq

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203440.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-253m-678w-hcj3

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-253m-4wjm-2prr

Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-253j-mgc4-hp35

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-253h-f8wh-gcxr

TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction pointer with malicious addresses.

CVSS3: 8.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-253h-63vc-5w2v

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-253g-w96v-v3cj

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-253g-rphr-6h5j

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу