Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 351 897

Количество 351 897

github логотип

GHSA-xxxw-3j6h-q7h6

почти 2 года назад

Grafana plugin SDK Information Leakage

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxxv-phx4-9pvx

4 месяца назад

The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter corresponds to an existing WordPress user, while the callback function (update_user_wechatshop_info) uses a separate, attacker-controlled 'userid' parameter to determine which user's metadata gets modified, with no verification that the 'openid' and 'userid' belong to the same user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary users' store-related metadata (storeinfo, storeappid, storename) via the 'userid' REST API parameter.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxxv-ffhq-jc78

почти 3 года назад

** DISPUTED ** Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxv-9j5g-vqfc

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so calling it before triggers a double free.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxxv-8qg4-6qv9

около 4 лет назад

Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-xxxv-6j6h-6fqv

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.

EPSS: Низкий
github логотип

GHSA-xxxq-m57r-j966

около 4 лет назад

P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause malicious code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxxq-chmp-67g4

около 6 лет назад

RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxxp-8x92-f69v

около 3 лет назад

An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxm-q6xf-58pf

около 4 лет назад

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xxxm-cq2q-5v69

почти 3 года назад

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxj-w44j-q5cf

около 2 месяцев назад

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxj-4ccj-cfw9

около 4 лет назад

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

EPSS: Низкий
github логотип

GHSA-xxxh-xcx8-7g7r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xxxh-8gvj-6w39

около 4 лет назад

Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a PDF document with a crafted TrueType font.

EPSS: Низкий
github логотип

GHSA-xxxg-x793-7fq3

4 месяца назад

Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.php

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xxxg-8p58-2qqv

9 месяцев назад

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxxf-qw8j-6rfv

больше 4 лет назад

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxxf-8fjp-59qv

около 4 лет назад

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

EPSS: Низкий
github логотип

GHSA-xxxc-p928-96mq

9 месяцев назад

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 2.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxxw-3j6h-q7h6

Grafana plugin SDK Information Leakage

CVSS3: 5.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-xxxv-phx4-9pvx

The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter corresponds to an existing WordPress user, while the callback function (update_user_wechatshop_info) uses a separate, attacker-controlled 'userid' parameter to determine which user's metadata gets modified, with no verification that the 'openid' and 'userid' belong to the same user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary users' store-related metadata (storeinfo, storeappid, storename) via the 'userid' REST API parameter.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xxxv-ffhq-jc78

** DISPUTED ** Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxxv-9j5g-vqfc

In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so calling it before triggers a double free.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xxxv-8qg4-6qv9

Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xxxv-6j6h-6fqv

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xxxq-m57r-j966

P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause malicious code execution.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxxq-chmp-67g4

RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign

CVSS3: 9.8
3%
Низкий
около 6 лет назад
github логотип
GHSA-xxxp-8x92-f69v

An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxxm-q6xf-58pf

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

CVSS3: 8.8
21%
Средний
около 4 лет назад
github логотип
GHSA-xxxm-cq2q-5v69

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xxxj-w44j-q5cf

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xxxj-4ccj-cfw9

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xxxh-xcx8-7g7r

Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxxh-8gvj-6w39

Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a PDF document with a crafted TrueType font.

7%
Низкий
около 4 лет назад
github логотип
GHSA-xxxg-x793-7fq3

Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.php

CVSS3: 8.2
0%
Низкий
4 месяца назад
github логотип
GHSA-xxxg-8p58-2qqv

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-xxxf-qw8j-6rfv

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxxf-8fjp-59qv

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxxc-p928-96mq

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 2.2
0%
Низкий
9 месяцев назад

Уязвимостей на страницу