Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgr6-pqjv-3pf8

19 дней назад

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

EPSS: Низкий
github логотип

GHSA-xgr6-3chx-rcqp

больше 4 лет назад

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgr5-qc6w-vcg9

7 месяцев назад

RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting

EPSS: Низкий
github логотип

GHSA-xgr5-8gm5-gj39

больше 4 лет назад

Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xgr5-38f7-xqvv

около 4 лет назад

libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgr3-26hm-39gg

больше 1 года назад

Missing Authorization vulnerability in bPlugins LLC Button Block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through 1.1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgr2-w47g-6j54

около 4 лет назад

A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this vulnerability by using the static key to craft a valid session token. A successful exploit could allow the attacker to perform arbitrary actions through the REST API with administrative privileges.

EPSS: Низкий
github логотип

GHSA-xgr2-v94m-rc9g

почти 9 лет назад

activesupport in Rails vulnerable to incorrect data conversion

EPSS: Критический
github логотип

GHSA-xgr2-6f6r-9xqp

больше 1 года назад

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xgr2-5837-hf48

11 месяцев назад

NovoSGA: Manipulation of User Creation Page can lead to weak password requirements

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xgr2-4f4q-m3p9

почти 3 года назад

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgqx-4642-r33v

около 4 лет назад

An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.

EPSS: Низкий
github логотип

GHSA-xgqw-65w4-7gf7

больше 4 лет назад

The mintToken function of a smart contract implementation for BpsToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgqw-2pfm-43g4

больше 4 лет назад

SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xgqw-2h6m-8x8q

27 дней назад

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgqv-jcxf-qp28

около 1 месяца назад

A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgqv-fw8c-8qm6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

EPSS: Низкий
github логотип

GHSA-xgqr-wgh8-w4hw

больше 4 лет назад

Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

EPSS: Средний
github логотип

GHSA-xgqr-693c-m9jh

почти 3 года назад

A vulnerability has been found in SourceCodester Take-Note App 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239350 is the identifier assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgqr-5wqw-9fpv

почти 4 года назад

Apache UIMA Path Traversal vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgr6-pqjv-3pf8

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

0%
Низкий
19 дней назад
github логотип
GHSA-xgr6-3chx-rcqp

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgr5-qc6w-vcg9

RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting

0%
Низкий
7 месяцев назад
github логотип
GHSA-xgr5-8gm5-gj39

Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.

CVSS3: 7.5
35%
Средний
больше 4 лет назад
github логотип
GHSA-xgr5-38f7-xqvv

libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xgr3-26hm-39gg

Missing Authorization vulnerability in bPlugins LLC Button Block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through 1.1.5.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgr2-w47g-6j54

A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this vulnerability by using the static key to craft a valid session token. A successful exploit could allow the attacker to perform arbitrary actions through the REST API with administrative privileges.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xgr2-v94m-rc9g

activesupport in Rails vulnerable to incorrect data conversion

95%
Критический
почти 9 лет назад
github логотип
GHSA-xgr2-6f6r-9xqp

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgr2-5837-hf48

NovoSGA: Manipulation of User Creation Page can lead to weak password requirements

CVSS3: 3.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-xgr2-4f4q-m3p9

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xgqx-4642-r33v

An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xgqw-65w4-7gf7

The mintToken function of a smart contract implementation for BpsToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgqw-2pfm-43g4

SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgqw-2h6m-8x8q

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
27 дней назад
github логотип
GHSA-xgqv-jcxf-qp28

A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xgqv-fw8c-8qm6

Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgqr-wgh8-w4hw

Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

13%
Средний
больше 4 лет назад
github логотип
GHSA-xgqr-693c-m9jh

A vulnerability has been found in SourceCodester Take-Note App 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239350 is the identifier assigned to this vulnerability.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xgqr-5wqw-9fpv

Apache UIMA Path Traversal vulnerability

CVSS3: 7.5
2%
Низкий
почти 4 года назад

Уязвимостей на страницу