Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-xx97-cmjp-pm7g

больше 1 года назад

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xx96-p4qh-f9mr

около 4 лет назад

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xx95-hcg5-8859

9 месяцев назад

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx95-62h6-h7v3

больше 1 года назад

lgsl Stored Cross-Site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-xx94-r2jp-2426

около 4 лет назад

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xx94-f2ch-qhxm

около 4 лет назад

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in acknowledge.c.

EPSS: Низкий
github логотип

GHSA-xx93-36xf-3332

больше 3 лет назад

A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215107.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx92-xfrf-9xp3

3 месяца назад

Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as unauthorized read access to a subset of Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx8x-qm77-m9x3

около 4 лет назад

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

EPSS: Средний
github логотип

GHSA-xx8x-hq3h-f37h

около 1 месяца назад

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-xx8x-95r2-vhg6

около 4 лет назад

Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Space.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xx8w-mq23-29g4

больше 2 лет назад

Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xx8w-4q6h-66xg

больше 1 года назад

DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xx8v-jwch-cjrx

больше 4 лет назад

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.

EPSS: Низкий
github логотип

GHSA-xx8v-9cvf-fc7h

около 4 лет назад

Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

EPSS: Низкий
github логотип

GHSA-xx8r-qhq8-fw6r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter) plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

EPSS: Низкий
github логотип

GHSA-xx8r-qcqq-3fgj

около 4 лет назад

In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx8r-jj29-vw5j

7 месяцев назад

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx8r-j779-rrrw

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx8r-cffm-j9h6

около 4 лет назад

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx97-cmjp-pm7g

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx96-p4qh-f9mr

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.

CVSS3: 5.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-xx95-hcg5-8859

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xx95-62h6-h7v3

lgsl Stored Cross-Site Scripting vulnerability

0%
Низкий
больше 1 года назад
github логотип
GHSA-xx94-r2jp-2426

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVSS3: 9.8
12%
Средний
около 4 лет назад
github логотип
GHSA-xx94-f2ch-qhxm

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of &nbsp; expansion in acknowledge.c.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xx93-36xf-3332

A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215107.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx92-xfrf-9xp3

Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as unauthorized read access to a subset of Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xx8x-qm77-m9x3

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

11%
Средний
около 4 лет назад
github логотип
GHSA-xx8x-hq3h-f37h

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.

CVSS3: 7.9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xx8x-95r2-vhg6

Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Space.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx8w-mq23-29g4

Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation

CVSS3: 8.8
34%
Средний
больше 2 лет назад
github логотип
GHSA-xx8w-4q6h-66xg

DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

CVSS3: 9.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-xx8v-jwch-cjrx

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xx8v-9cvf-fc7h

Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xx8r-qhq8-fw6r

Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter) plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xx8r-qcqq-3fgj

In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx8r-jj29-vw5j

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xx8r-j779-rrrw

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx8r-cffm-j9h6

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

CVSS3: 9.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу