Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-xw22-wv29-3299

больше 5 лет назад

ApiKey secret could be revelated on network issue

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvxx-vrh7-xh3v

около 4 лет назад

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvxx-4fr3-55xv

7 месяцев назад

Panda3D versions up to and including 1.10.16 deploy-stub contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a large number of command-line arguments can exhaust stack space and propagate uninitialized stack memory into Python interpreter initialization, resulting in a reliable crash and undefined behavior.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvxw-65r3-5rcf

около 2 месяцев назад

Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvxv-v375-9q9p

около 4 лет назад

The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xvxv-2qp5-99vx

6 месяцев назад

Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvxr-rrxw-rfp9

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe() When devres_open_group() fails, it returns -ENOMEM without freeing memory allocated by edac_mc_alloc(). Call edac_mc_free() on the error handling path to avoid a memory leak. [ bp: Massage commit message. ]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvxr-fcpp-g423

около 4 лет назад

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.

EPSS: Низкий
github логотип

GHSA-xvxr-4f6g-g73v

около 4 лет назад

SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL commands via the User field.

EPSS: Низкий
github логотип

GHSA-xvxq-r6r9-xm62

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack the authentication of arbitrary users for requests that delete tests, aka Bug ID CSCzu81067.

EPSS: Низкий
github логотип

GHSA-xvxq-p298-r7fw

около 4 лет назад

The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvxq-hq48-xphm

около 4 лет назад

Sandbox bypass in Script Security Plugin

CVSS3: 9.9
EPSS: Высокий
github логотип

GHSA-xvxq-g8hw-fx4g

больше 1 года назад

OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvxq-7q9x-g29m

около 2 лет назад

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvxp-rj85-x563

около 4 лет назад

The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvxp-pj7j-gmjj

3 месяца назад

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

EPSS: Низкий
github логотип

GHSA-xvxm-x86g-723r

9 месяцев назад

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xvxm-rm97-hmmp

около 4 лет назад

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30141, CVE-2022-30143, CVE-2022-30146, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvxj-48v4-h2xv

около 4 лет назад

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

EPSS: Низкий
github логотип

GHSA-xvxh-jmmc-4vxm

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qedi: Fix crash while reading debugfs attribute The qedi_dbg_do_not_recover_cmd_read() function invokes sprintf() directly on a __user pointer, which results into the crash. To fix this issue, use a small local stack buffer for sprintf() and then call simple_read_from_buffer(), which in turns make the copy_to_user() call. BUG: unable to handle page fault for address: 00007f4801111000 PGD 8000000864df6067 P4D 8000000864df6067 PUD 864df7067 PMD 846028067 PTE 0 Oops: 0002 [#1] PREEMPT SMP PTI Hardware name: HPE ProLiant DL380 Gen10/ProLiant DL380 Gen10, BIOS U30 06/15/2023 RIP: 0010:memcpy_orig+0xcd/0x130 RSP: 0018:ffffb7a18c3ffc40 EFLAGS: 00010202 RAX: 00007f4801111000 RBX: 00007f4801111000 RCX: 000000000000000f RDX: 000000000000000f RSI: ffffffffc0bfd7a0 RDI: 00007f4801111000 RBP: ffffffffc0bfd7a0 R08: 725f746f6e5f6f64 R09: 3d7265766f636572 R10: ffffb7a18c3ffd08 R11: 0000000000000000 R12: 00007f4881110fff R...

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw22-wv29-3299

ApiKey secret could be revelated on network issue

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-xvxx-vrh7-xh3v

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvxx-4fr3-55xv

Panda3D versions up to and including 1.10.16 deploy-stub contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a large number of command-line arguments can exhaust stack space and propagate uninitialized stack memory into Python interpreter initialization, resulting in a reliable crash and undefined behavior.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xvxw-65r3-5rcf

Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xvxv-v375-9q9p

The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."

CVSS3: 3.3
4%
Низкий
около 4 лет назад
github логотип
GHSA-xvxv-2qp5-99vx

Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvxr-rrxw-rfp9

In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe() When devres_open_group() fails, it returns -ENOMEM without freeing memory allocated by edac_mc_alloc(). Call edac_mc_free() on the error handling path to avoid a memory leak. [ bp: Massage commit message. ]

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvxr-fcpp-g423

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xvxr-4f6g-g73v

SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL commands via the User field.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xvxq-r6r9-xm62

Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack the authentication of arbitrary users for requests that delete tests, aka Bug ID CSCzu81067.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvxq-p298-r7fw

The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvxq-hq48-xphm

Sandbox bypass in Script Security Plugin

CVSS3: 9.9
74%
Высокий
около 4 лет назад
github логотип
GHSA-xvxq-g8hw-fx4g

OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvxq-7q9x-g29m

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xvxp-rj85-x563

The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvxp-pj7j-gmjj

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

0%
Низкий
3 месяца назад
github логотип
GHSA-xvxm-x86g-723r

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-xvxm-rm97-hmmp

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30141, CVE-2022-30143, CVE-2022-30146, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xvxj-48v4-h2xv

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xvxh-jmmc-4vxm

In the Linux kernel, the following vulnerability has been resolved: scsi: qedi: Fix crash while reading debugfs attribute The qedi_dbg_do_not_recover_cmd_read() function invokes sprintf() directly on a __user pointer, which results into the crash. To fix this issue, use a small local stack buffer for sprintf() and then call simple_read_from_buffer(), which in turns make the copy_to_user() call. BUG: unable to handle page fault for address: 00007f4801111000 PGD 8000000864df6067 P4D 8000000864df6067 PUD 864df7067 PMD 846028067 PTE 0 Oops: 0002 [#1] PREEMPT SMP PTI Hardware name: HPE ProLiant DL380 Gen10/ProLiant DL380 Gen10, BIOS U30 06/15/2023 RIP: 0010:memcpy_orig+0xcd/0x130 RSP: 0018:ffffb7a18c3ffc40 EFLAGS: 00010202 RAX: 00007f4801111000 RBX: 00007f4801111000 RCX: 000000000000000f RDX: 000000000000000f RSI: ffffffffc0bfd7a0 RDI: 00007f4801111000 RBP: ffffffffc0bfd7a0 R08: 725f746f6e5f6f64 R09: 3d7265766f636572 R10: ffffb7a18c3ffd08 R11: 0000000000000000 R12: 00007f4881110fff R...

CVSS3: 7.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу