Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xmxw-j4c5-629g

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xmxv-mcf7-rf26

около 4 лет назад

The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xmxr-5hxx-256r

22 дня назад

Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Price Protection executes to compromise Oracle Price Protection. While the vulnerability is in Oracle Price Protection, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xmxp-x783-v5rx

почти 4 года назад

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xmxp-gx58-3r75

около 4 лет назад

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2019-0536, CVE-2019-0549, CVE-2019-0554.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmxj-v2q8-8qx6

почти 2 года назад

Concrete CMS Stored XSS in the "Next&Previous Nav" block

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-xmxj-pp68-34rr

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xmxj-3326-2879

10 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xmxh-qgmj-jcc4

около 4 лет назад

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xmxh-pm35-h64j

8 месяцев назад

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xmxh-g7wj-8m4m

больше 5 лет назад

OS Command Injection in curling

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmxg-28xr-rp8x

около 4 лет назад

drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xmxf-wjr9-rpwr

около 3 лет назад

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmxf-f859-45ch

6 месяцев назад

Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xmxf-9v5q-5mfw

больше 4 лет назад

A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xmxc-mvx2-q963

около 4 лет назад

On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xmxc-8qjw-52gx

около 4 лет назад

Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

EPSS: Низкий
github логотип

GHSA-xmxc-2jc7-w66m

больше 3 лет назад

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmx9-rjwq-m2x6

около 4 лет назад

Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmx9-mmqw-jcw6

около 4 лет назад

The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmxw-j4c5-629g

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xmxv-mcf7-rf26

The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmxr-5hxx-256r

Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Price Protection executes to compromise Oracle Price Protection. While the vulnerability is in Oracle Price Protection, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.4
0%
Низкий
22 дня назад
github логотип
GHSA-xmxp-x783-v5rx

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-xmxp-gx58-3r75

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2019-0536, CVE-2019-0549, CVE-2019-0554.

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xmxj-v2q8-8qx6

Concrete CMS Stored XSS in the "Next&Previous Nav" block

CVSS3: 2.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xmxj-pp68-34rr

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-xmxj-3326-2879

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.

CVSS3: 8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xmxh-qgmj-jcc4

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CVSS3: 5.9
5%
Низкий
около 4 лет назад
github логотип
GHSA-xmxh-pm35-h64j

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

CVSS3: 6.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-xmxh-g7wj-8m4m

OS Command Injection in curling

CVSS3: 9.8
5%
Низкий
больше 5 лет назад
github логотип
GHSA-xmxg-28xr-rp8x

drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor.

CVSS3: 6.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-xmxf-wjr9-rpwr

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xmxf-f859-45ch

Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xmxf-9v5q-5mfw

A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xmxc-mvx2-q963

On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmxc-8qjw-52gx

Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xmxc-2jc7-w66m

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xmx9-rjwq-m2x6

Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmx9-mmqw-jcw6

The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.

CVSS3: 5.5
4%
Низкий
около 4 лет назад

Уязвимостей на страницу