Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 508

Количество 376 508

github логотип

GHSA-xqqr-p362-6rmc

почти 8 лет назад

Directory Traversal in hostr

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqqr-mq8x-22qx

больше 4 лет назад

Jenkins JX Resources Plugin missing permission check

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqqr-m249-5wxh

больше 3 лет назад

A vulnerability has been found in CESNET theme-cesnet up to 1.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the file cesnet/core/lostpassword/templates/resetpassword.php. The manipulation leads to insufficiently protected credentials. Attacking locally is a requirement. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 2b857f2233ce5083b4d5bc9bfc4152f933c3e4a6. It is recommended to upgrade the affected component. The identifier VDB-217633 was assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqqr-6rp7-gjf6

больше 4 лет назад

Multiple SQL injection vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) gastname, (2) gastwohnort, or (3) gasteintrag parameters.

EPSS: Низкий
github логотип

GHSA-xqqr-5rg9-gj2h

больше 4 лет назад

Vulnerability in Compaq Tru64 UNIX edauth command.

EPSS: Низкий
github логотип

GHSA-xqqq-qrvp-j2jg

больше 4 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

EPSS: Низкий
github логотип

GHSA-xqqq-h53w-5pj3

около 4 лет назад

Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqqp-wpjp-4w5q

больше 4 лет назад

Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xqqm-w483-3fhq

больше 4 лет назад

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

EPSS: Низкий
github логотип

GHSA-xqqm-hh5r-8934

больше 4 лет назад

Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqqm-4xjp-r9cv

больше 3 лет назад

A vulnerability was found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226103.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqqj-h3wv-qfx7

9 месяцев назад

The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xqqj-2hmg-wc6r

больше 4 лет назад

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xqqh-q9w9-6726

больше 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xqqh-jw9f-jfcc

больше 4 лет назад

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqqh-8g96-r9wj

почти 4 года назад

A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to impersonate another user's name.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqqh-6x8q-wqhc

почти 5 лет назад

The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

EPSS: Низкий
github логотип

GHSA-xqqh-3w52-q8p7

около 1 месяца назад

Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqqg-x653-vrx5

больше 2 лет назад

A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xqqf-j87h-83gq

почти 4 года назад

Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqqr-p362-6rmc

Directory Traversal in hostr

CVSS3: 7.5
2%
Низкий
почти 8 лет назад
github логотип
GHSA-xqqr-mq8x-22qx

Jenkins JX Resources Plugin missing permission check

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqr-m249-5wxh

A vulnerability has been found in CESNET theme-cesnet up to 1.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the file cesnet/core/lostpassword/templates/resetpassword.php. The manipulation leads to insufficiently protected credentials. Attacking locally is a requirement. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 2b857f2233ce5083b4d5bc9bfc4152f933c3e4a6. It is recommended to upgrade the affected component. The identifier VDB-217633 was assigned to this vulnerability.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqqr-6rp7-gjf6

Multiple SQL injection vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) gastname, (2) gastwohnort, or (3) gasteintrag parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqr-5rg9-gj2h

Vulnerability in Compaq Tru64 UNIX edauth command.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqq-qrvp-j2jg

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqq-h53w-5pj3

Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vectors.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqqp-wpjp-4w5q

Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqm-w483-3fhq

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqm-hh5r-8934

Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqm-4xjp-r9cv

A vulnerability was found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226103.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xqqj-h3wv-qfx7

The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-xqqj-2hmg-wc6r

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.

CVSS3: 7.5
29%
Средний
больше 4 лет назад
github логотип
GHSA-xqqh-q9w9-6726

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqh-jw9f-jfcc

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqqh-8g96-r9wj

A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to impersonate another user's name.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqqh-6x8q-wqhc

The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

1%
Низкий
почти 5 лет назад
github логотип
GHSA-xqqh-3w52-q8p7

Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute

CVSS3: 5.3
около 1 месяца назад
github логотип
GHSA-xqqg-x653-vrx5

A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xqqf-j87h-83gq

Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.

CVSS3: 8.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу