Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-xxrm-mm6r-v5x3

около 4 лет назад

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.

EPSS: Низкий
github логотип

GHSA-xxrm-5v3v-6c86

больше 3 лет назад

The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxrm-3f86-v97j

18 дней назад

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxrj-j9r7-g9q6

больше 4 лет назад

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.

EPSS: Низкий
github логотип

GHSA-xxrj-3q2m-w65m

около 4 лет назад

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xxrh-w3xc-mv6f

больше 3 лет назад

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxrh-2f9r-39q6

4 месяца назад

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of the component pandasai-lancedb Extension. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xxrg-mg63-qfpj

больше 1 года назад

Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xxrg-cc44-fcvc

около 4 лет назад

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0645, CVE-2019-0650.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxrg-2j8c-797x

около 3 лет назад

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxrf-fc9m-h444

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xxrc-mppm-r6mw

больше 4 лет назад

SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxrc-69rc-659v

около 4 лет назад

CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.

EPSS: Низкий
github логотип

GHSA-xxr9-8j75-c68c

около 4 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

EPSS: Низкий
github логотип

GHSA-xxr9-6j7m-9mvq

около 4 лет назад

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxr9-37w5-wgwc

около 4 лет назад

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

EPSS: Низкий
github логотип

GHSA-xxr9-34qv-3673

около 4 лет назад

Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxr8-rx47-q5rr

около 4 лет назад

Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.

EPSS: Низкий
github логотип

GHSA-xxr8-r558-393h

больше 4 лет назад

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).

EPSS: Низкий
github логотип

GHSA-xxr8-hvgp-fvhc

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One] allows Reflected XSS.This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.20.13.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxrm-mm6r-v5x3

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxrm-5v3v-6c86

The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxrm-3f86-v97j

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.

CVSS3: 9.8
1%
Низкий
18 дней назад
github логотип
GHSA-xxrj-j9r7-g9q6

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxrj-3q2m-w65m

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.

CVSS3: 6.7
4%
Низкий
около 4 лет назад
github логотип
GHSA-xxrh-w3xc-mv6f

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxrh-2f9r-39q6

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of the component pandasai-lancedb Extension. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xxrg-mg63-qfpj

Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability

CVSS3: 8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxrg-cc44-fcvc

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0645, CVE-2019-0650.

CVSS3: 7.5
10%
Низкий
около 4 лет назад
github логотип
GHSA-xxrg-2j8c-797x

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.

CVSS3: 5.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxrf-fc9m-h444

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0.

CVSS3: 9.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxrc-mppm-r6mw

SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxrc-69rc-659v

CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxr9-8j75-c68c

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xxr9-6j7m-9mvq

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxr9-37w5-wgwc

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxr9-34qv-3673

Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxr8-rx47-q5rr

Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxr8-r558-393h

Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxr8-hvgp-fvhc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One] allows Reflected XSS.This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.20.13.

CVSS3: 7.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу