Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-22ph-2jjc-cggf

больше 4 лет назад

c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

EPSS: Низкий
github логотип

GHSA-22pg-w2f6-xfjw

12 месяцев назад

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-22pg-r6fg-6256

больше 4 лет назад

Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCth03022.

EPSS: Низкий
github логотип

GHSA-22pf-6rh7-89gj

почти 2 года назад

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22pc-rqp3-3hrg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message.

EPSS: Низкий
github логотип

GHSA-22pc-q2px-qx4f

10 месяцев назад

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An attacker can craft a malicious URL that, when visited by a victim, causes arbitrary JavaScript code to be executed in the victim's browser within the security context of the vulnerable application. This issue could allow attackers to steal session cookies, disclose sensitive information, perform unauthorized actions on behalf of the user, or conduct phishing attacks.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-22p9-wv53-3rq4

3 месяца назад

LinkifyIt#match scan loop has quadratic algorithmic complexity

EPSS: Низкий
github логотип

GHSA-22p9-vg4g-45mc

больше 4 лет назад

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

EPSS: Низкий
github логотип

GHSA-22p9-v5cc-5f4w

больше 4 лет назад

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22p9-r2f5-22mf

около 1 месяца назад

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-22p8-j48p-jr45

больше 4 лет назад

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

EPSS: Низкий
github логотип

GHSA-22p7-jgf7-772h

5 месяцев назад

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers to update the plugin's settings, including injecting malicious scripts that will be stored and executed in the admin area, via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22p7-7xrf-xxhr

больше 4 лет назад

The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

EPSS: Низкий
github логотип

GHSA-22p7-26xx-rjp2

11 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.

EPSS: Низкий
github логотип

GHSA-22p7-2347-c784

больше 3 лет назад

A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22p6-w2px-4gj3

около 1 года назад

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22p6-rw8w-cm9m

больше 4 лет назад

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22p6-c9vr-pq5x

больше 2 лет назад

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22p6-5mp7-g3v6

почти 4 года назад

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22p5-hr7r-x3qv

больше 4 лет назад

The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22ph-2jjc-cggf

c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-22pg-w2f6-xfjw

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.

CVSS3: 9.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-22pg-r6fg-6256

Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCth03022.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22pf-6rh7-89gj

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-22pc-rqp3-3hrg

Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22pc-q2px-qx4f

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An attacker can craft a malicious URL that, when visited by a victim, causes arbitrary JavaScript code to be executed in the victim's browser within the security context of the vulnerable application. This issue could allow attackers to steal session cookies, disclose sensitive information, perform unauthorized actions on behalf of the user, or conduct phishing attacks.

CVSS3: 4.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-22p9-wv53-3rq4

LinkifyIt#match scan loop has quadratic algorithmic complexity

0%
Низкий
3 месяца назад
github логотип
GHSA-22p9-vg4g-45mc

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22p9-v5cc-5f4w

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22p9-r2f5-22mf

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

CVSS3: 4.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-22p8-j48p-jr45

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-22p7-jgf7-772h

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers to update the plugin's settings, including injecting malicious scripts that will be stored and executed in the admin area, via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-22p7-7xrf-xxhr

The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-22p7-26xx-rjp2

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.

0%
Низкий
11 месяцев назад
github логотип
GHSA-22p7-2347-c784

A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22p6-w2px-4gj3

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-22p6-rw8w-cm9m

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22p6-c9vr-pq5x

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22p6-5mp7-g3v6

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-22p5-hr7r-x3qv

The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

CVSS3: 7.8
8%
Низкий
больше 4 лет назад

Уязвимостей на страницу