Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-22r9-wcv9-vx8v

больше 4 лет назад

Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0549.

EPSS: Низкий
github логотип

GHSA-22r9-5j98-76h8

больше 1 года назад

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.2.6.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22r8-wqq9-4mpg

больше 4 лет назад

An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22r8-gvpx-mqwv

28 дней назад

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22r8-f3mc-v2m4

больше 4 лет назад

The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.

EPSS: Низкий
github логотип

GHSA-22r7-8crj-hpfh

больше 4 лет назад

Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.

EPSS: Низкий
github логотип

GHSA-22r7-4wq2-qrrj

больше 4 лет назад

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22r7-2v6v-5qmw

больше 4 лет назад

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

EPSS: Низкий
github логотип

GHSA-22r5-h494-2vm4

больше 4 лет назад

Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.

EPSS: Низкий
github логотип

GHSA-22r5-83g8-x228

больше 4 лет назад

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.

EPSS: Средний
github логотип

GHSA-22r5-47c6-39f8

23 дня назад

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22r4-f9q2-4m9g

больше 4 лет назад

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22r3-hxrp-33gc

около 3 лет назад

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22r3-9w55-cj54

больше 2 лет назад

Pkg Local Privilege Escalation

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-22r2-m2r8-4chj

около 1 года назад

A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22r2-gj47-5f7c

3 месяца назад

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-22r2-8jr8-3hmr

больше 4 лет назад

Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22r2-3hp3-ff6j

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Poll Maker allows DOM-Based XSS. This issue affects Poll Maker: from n/a through 6.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22qx-x99p-8745

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-22qx-rv28-v9m8

около 2 лет назад

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22r9-wcv9-vx8v

Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0549.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22r9-5j98-76h8

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.2.6.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-22r8-wqq9-4mpg

An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22r8-gvpx-mqwv

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

CVSS3: 5.3
0%
Низкий
28 дней назад
github логотип
GHSA-22r8-f3mc-v2m4

The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22r7-8crj-hpfh

Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22r7-4wq2-qrrj

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22r7-2v6v-5qmw

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22r5-h494-2vm4

Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22r5-83g8-x228

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.

34%
Средний
больше 4 лет назад
github логотип
GHSA-22r5-47c6-39f8

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

CVSS3: 9.8
0%
Низкий
23 дня назад
github логотип
GHSA-22r4-f9q2-4m9g

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-22r3-hxrp-33gc

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-22r3-9w55-cj54

Pkg Local Privilege Escalation

CVSS3: 6.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22r2-m2r8-4chj

A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-22r2-gj47-5f7c

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-22r2-8jr8-3hmr

Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-22r2-3hp3-ff6j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Poll Maker allows DOM-Based XSS. This issue affects Poll Maker: from n/a through 6.0.1.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-22qx-x99p-8745

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22qx-rv28-v9m8

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
1%
Низкий
около 2 лет назад

Уязвимостей на страницу