Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-xwrg-6m45-8r48

8 месяцев назад

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xwrf-mmfx-x4vx

около 4 лет назад

On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-xwrf-hhx9-vmhv

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Ensure rdma_addr_cancel() happens before issuing more requests The FSM can run in a circle allowing rdma_resolve_ip() to be called twice on the same id_priv. While this cannot happen without going through the work, it violates the invariant that the same address resolution background request cannot be active twice. CPU 1 CPU 2 rdma_resolve_addr(): RDMA_CM_IDLE -> RDMA_CM_ADDR_QUERY rdma_resolve_ip(addr_handler) #1 process_one_req(): for #1 addr_handler(): RDMA_CM_ADDR_QUERY -> RDMA_CM_ADDR_BOUND mutex_unlock(&id_priv->handler_mutex); [.. handler still running ..] rdma_resolve_addr(): RDMA_CM_ADDR_BOUND -> RDMA_CM_ADDR_QUERY rdma_resolve_ip(addr_handler) !! two requests are now on the req_list rdma_destroy_id(): destroy_id_handler_unlo...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwr9-qph4-cpwg

12 месяцев назад

A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that correlates to the last two consecutive sign in session interval, making it predictable.

EPSS: Низкий
github логотип

GHSA-xwr9-qp3g-c7vh

больше 1 года назад

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwr9-j862-6mj9

больше 2 лет назад

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xwr8-52r2-77wh

4 дня назад

Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwr7-j9pf-gg7p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter.

EPSS: Низкий
github логотип

GHSA-xwr6-26hr-pc5h

3 дня назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-xwr5-mcxm-cm87

около 4 лет назад

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwr5-m59h-vwqr

4 месяца назад

Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xwr5-cx3m-rj3v

9 месяцев назад

kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwr4-7vg8-hx5g

5 дней назад

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xwr3-fmgj-mmfr

почти 9 лет назад

Exposure of Sensitive Information in bio-basespace-sdk

EPSS: Низкий
github логотип

GHSA-xwr3-f5gh-9v6w

больше 1 года назад

Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwr3-6hhp-5cch

почти 3 года назад

QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwr3-5rff-6h5p

больше 4 лет назад

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160830.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xwr2-9ffc-64f7

больше 2 лет назад

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xwqx-x38c-cw95

около 4 лет назад

Snipe-IT 6.0.2 vulnerable to Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xwqx-rpjh-4w5r

около 4 лет назад

delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwrg-6m45-8r48

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.

CVSS3: 5.4
6%
Низкий
8 месяцев назад
github логотип
GHSA-xwrf-mmfx-x4vx

On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xwrf-hhx9-vmhv

In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Ensure rdma_addr_cancel() happens before issuing more requests The FSM can run in a circle allowing rdma_resolve_ip() to be called twice on the same id_priv. While this cannot happen without going through the work, it violates the invariant that the same address resolution background request cannot be active twice. CPU 1 CPU 2 rdma_resolve_addr(): RDMA_CM_IDLE -> RDMA_CM_ADDR_QUERY rdma_resolve_ip(addr_handler) #1 process_one_req(): for #1 addr_handler(): RDMA_CM_ADDR_QUERY -> RDMA_CM_ADDR_BOUND mutex_unlock(&id_priv->handler_mutex); [.. handler still running ..] rdma_resolve_addr(): RDMA_CM_ADDR_BOUND -> RDMA_CM_ADDR_QUERY rdma_resolve_ip(addr_handler) !! two requests are now on the req_list rdma_destroy_id(): destroy_id_handler_unlo...

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwr9-qph4-cpwg

A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that correlates to the last two consecutive sign in session interval, making it predictable.

0%
Низкий
12 месяцев назад
github логотип
GHSA-xwr9-qp3g-c7vh

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwr9-j862-6mj9

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xwr8-52r2-77wh

Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
4 дня назад
github логотип
GHSA-xwr7-j9pf-gg7p

Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwr6-26hr-pc5h

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

3 дня назад
github логотип
GHSA-xwr5-mcxm-cm87

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS3: 6.1
10%
Низкий
около 4 лет назад
github логотип
GHSA-xwr5-m59h-vwqr

Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

CVSS3: 6.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xwr5-cx3m-rj3v

kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xwr4-7vg8-hx5g

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 8.1
1%
Низкий
5 дней назад
github логотип
GHSA-xwr3-fmgj-mmfr

Exposure of Sensitive Information in bio-basespace-sdk

2%
Низкий
почти 9 лет назад
github логотип
GHSA-xwr3-f5gh-9v6w

Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-xwr3-6hhp-5cch

QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xwr3-5rff-6h5p

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160830.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xwr2-9ffc-64f7

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xwqx-x38c-cw95

Snipe-IT 6.0.2 vulnerable to Cross-site Scripting

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xwqx-rpjh-4w5r

delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу