Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xm99-6pv5-q363

больше 4 лет назад

Disputed: OS Command injection in github.com/kardianos/service

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xm98-p8mq-5j7x

около 4 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xm98-9qfh-q6g4

около 2 месяцев назад

Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xm98-722w-4373

около 4 лет назад

IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.

EPSS: Низкий
github логотип

GHSA-xm97-jwxx-3wfh

9 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app with root privileges may be able to access private information.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xm97-9w7x-8vx8

больше 4 лет назад

In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm97-7rvr-ppc2

больше 4 лет назад

Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.

EPSS: Низкий
github логотип

GHSA-xm97-4p58-pfr9

около 4 лет назад

Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.

EPSS: Низкий
github логотип

GHSA-xm96-gfjx-jcrc

3 месяца назад

ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xm95-m7m8-r568

почти 4 года назад

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xm94-xrhg-42m4

6 месяцев назад

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' parameter in '/components/cart/cartApplyDiscount.php'.

EPSS: Низкий
github логотип

GHSA-xm94-m277-f852

4 месяца назад

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm94-gcw3-hgpv

больше 4 лет назад

The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.

EPSS: Низкий
github логотип

GHSA-xm94-9jw8-p6hw

около 4 лет назад

Insertion of Sensitive Information into Externally-Accessible File or Directory in Jenkins Credentials Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xm94-78r5-v85h

больше 4 лет назад

Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xm93-cr5j-3294

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.

EPSS: Низкий
github логотип

GHSA-xm93-639c-r743

около 4 лет назад

Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.

EPSS: Низкий
github логотип

GHSA-xm92-v2mq-842q

около 4 лет назад

Apache Struts improper action name cleanup

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm92-rf24-h74w

около 4 лет назад

Apache Geronimo Application Server multiple directory traversal vulnerabilities

EPSS: Средний
github логотип

GHSA-xm92-qf3w-36f3

около 4 лет назад

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm99-6pv5-q363

Disputed: OS Command injection in github.com/kardianos/service

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xm98-p8mq-5j7x

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts.

CVSS3: 5.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xm98-9qfh-q6g4

Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xm98-722w-4373

IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm97-jwxx-3wfh

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app with root privileges may be able to access private information.

CVSS3: 4.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-xm97-9w7x-8vx8

In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-xm97-7rvr-ppc2

Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xm97-4p58-pfr9

Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm96-gfjx-jcrc

ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation

CVSS3: 8.1
3 месяца назад
github логотип
GHSA-xm95-m7m8-r568

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-xm94-xrhg-42m4

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' parameter in '/components/cart/cartApplyDiscount.php'.

0%
Низкий
6 месяцев назад
github логотип
GHSA-xm94-m277-f852

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xm94-gcw3-hgpv

The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xm94-9jw8-p6hw

Insertion of Sensitive Information into Externally-Accessible File or Directory in Jenkins Credentials Plugin

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xm94-78r5-v85h

Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xm93-cr5j-3294

PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xm93-639c-r743

Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm92-v2mq-842q

Apache Struts improper action name cleanup

CVSS3: 9.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-xm92-rf24-h74w

Apache Geronimo Application Server multiple directory traversal vulnerabilities

36%
Средний
около 4 лет назад
github логотип
GHSA-xm92-qf3w-36f3

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу