Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xmwc-2xfr-rrcr

около 4 лет назад

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.

EPSS: Низкий
github логотип

GHSA-xmw9-q7x9-j5qc

больше 5 лет назад

Unbounded connection acceptance leads to file handle exhaustion

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmw9-gg4q-2f2x

больше 4 лет назад

Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.

EPSS: Средний
github логотип

GHSA-xmw9-879h-j6mq

больше 4 лет назад

Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.

EPSS: Низкий
github логотип

GHSA-xmw9-6v8p-w6jg

около 4 лет назад

Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."

EPSS: Низкий
github логотип

GHSA-xmw9-6r43-x9ww

5 месяцев назад

SiYuan has directory traversal within its publishing service

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmw8-pxhc-cq64

около 2 месяцев назад

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise the credentials of connected cameras.

EPSS: Низкий
github логотип

GHSA-xmw7-wmp8-hj98

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.

EPSS: Низкий
github логотип

GHSA-xmw7-pfh7-ccxp

около 4 лет назад

The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmw7-848p-p95w

около 4 лет назад

Airbnb Knowledge Repo XSS In Comments

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmw5-w4c2-cp2g

26 дней назад

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xmw5-45v9-pxqx

около 4 лет назад

XSS vulnerability in Jenkins TICS Plugin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmw4-wxv9-hm5g

почти 2 года назад

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xmw3-64p4-g77h

6 месяцев назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmw2-mw3c-793w

больше 4 лет назад

Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.

EPSS: Низкий
github логотип

GHSA-xmw2-h4mh-h75v

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xmw2-9pgq-w58j

около 4 лет назад

The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.

EPSS: Низкий
github логотип

GHSA-xmw2-9fv2-vx29

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmw2-8pp9-3q4c

больше 4 лет назад

SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xmw2-2pgj-jq4h

около 4 лет назад

Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmwc-2xfr-rrcr

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmw9-q7x9-j5qc

Unbounded connection acceptance leads to file handle exhaustion

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
github логотип
GHSA-xmw9-gg4q-2f2x

Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.

17%
Средний
больше 4 лет назад
github логотип
GHSA-xmw9-879h-j6mq

Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xmw9-6v8p-w6jg

Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmw9-6r43-x9ww

SiYuan has directory traversal within its publishing service

CVSS3: 9.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-xmw8-pxhc-cq64

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise the credentials of connected cameras.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xmw7-wmp8-hj98

Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmw7-pfh7-ccxp

The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmw7-848p-p95w

Airbnb Knowledge Repo XSS In Comments

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmw5-w4c2-cp2g

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.

CVSS3: 8.1
0%
Низкий
26 дней назад
github логотип
GHSA-xmw5-45v9-pxqx

XSS vulnerability in Jenkins TICS Plugin

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmw4-wxv9-hm5g

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xmw3-64p4-g77h

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVSS3: 9.8
2%
Низкий
6 месяцев назад
github логотип
GHSA-xmw2-mw3c-793w

Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmw2-h4mh-h75v

Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmw2-9pgq-w58j

The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmw2-9fv2-vx29

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmw2-8pp9-3q4c

SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmw2-2pgj-jq4h

Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу