Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg75-68x3-7p3q

больше 4 лет назад

Apache Struts vulnerable to possible DoS attack when using URLValidator

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-xg75-35c7-jmgx

больше 3 лет назад

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xg75-3277-gvvj

больше 7 лет назад

Directory Traversal in serve

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg73-94fp-g449

больше 3 лет назад

mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xg73-5hqj-7hwg

около 1 года назад

A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg72-j993-8h8h

10 месяцев назад

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg72-j456-mcj9

больше 1 года назад

Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xg72-6c83-ghh4

около 4 лет назад

Microweber Stored Cross-site Scripting before v1.2.20

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xg6x-xg63-gmxc

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry even when the lookup resolves to an error route. If dst->error is set, xfrm6_rcv_encap() drops the skb without attaching the dst to the skb and without releasing the reference returned by the lookup. Repeated packets hitting this path therefore leak dst entries. Release the dst before jumping to the drop path.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg6x-r7hq-2gx8

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.

EPSS: Низкий
github логотип

GHSA-xg6x-h9c9-2m83

5 месяцев назад

Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)

EPSS: Низкий
github логотип

GHSA-xg6w-w34w-wcwm

больше 4 лет назад

IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xg6w-qq7g-f5fh

больше 3 лет назад

Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg6w-h55h-j5qh

больше 4 лет назад

IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

EPSS: Низкий
github логотип

GHSA-xg6w-8fxx-mqf6

больше 3 лет назад

A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ecommerce/admin/category/controller.php of the component Category Name Handler. The manipulation of the argument CATEGORY leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223411.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xg6v-xh9g-65cv

около 4 лет назад

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg6v-vr2f-h5xx

больше 4 лет назад

Improper memory initialization in Platform Sample/Silicon Reference firmware Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow privileged user to potentially enable an escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xg6r-jcjj-j993

около 4 лет назад

cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).

EPSS: Низкий
github логотип

GHSA-xg6r-cjq3-qmj5

3 месяца назад

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xg6r-c3f5-m35h

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg75-68x3-7p3q

Apache Struts vulnerable to possible DoS attack when using URLValidator

CVSS3: 5.3
10%
Средний
больше 4 лет назад
github логотип
GHSA-xg75-35c7-jmgx

Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xg75-3277-gvvj

Directory Traversal in serve

CVSS3: 7.5
2%
Низкий
больше 7 лет назад
github логотип
GHSA-xg73-94fp-g449

mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs

CVSS3: 9.8
70%
Средний
больше 3 лет назад
github логотип
GHSA-xg73-5hqj-7hwg

A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xg72-j993-8h8h

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xg72-j456-mcj9

Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-xg72-6c83-ghh4

Microweber Stored Cross-site Scripting before v1.2.20

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xg6x-xg63-gmxc

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry even when the lookup resolves to an error route. If dst->error is set, xfrm6_rcv_encap() drops the skb without attaching the dst to the skb and without releasing the reference returned by the lookup. Repeated packets hitting this path therefore leak dst entries. Release the dst before jumping to the drop path.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xg6x-r7hq-2gx8

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6x-h9c9-2m83

Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)

5 месяцев назад
github логотип
GHSA-xg6w-w34w-wcwm

IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6w-qq7g-f5fh

Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xg6w-h55h-j5qh

IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6w-8fxx-mqf6

A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ecommerce/admin/category/controller.php of the component Category Name Handler. The manipulation of the argument CATEGORY leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223411.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xg6v-xh9g-65cv

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xg6v-vr2f-h5xx

Improper memory initialization in Platform Sample/Silicon Reference firmware Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow privileged user to potentially enable an escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6r-jcjj-j993

cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).

2%
Низкий
около 4 лет назад
github логотип
GHSA-xg6r-cjq3-qmj5

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xg6r-c3f5-m35h

Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.

8%
Низкий
больше 4 лет назад

Уязвимостей на страницу