Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-xvvg-qwqf-w23x

больше 4 лет назад

The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.

EPSS: Низкий
github логотип

GHSA-xvvf-vgph-gpgv

больше 4 лет назад

Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."

EPSS: Низкий
github логотип

GHSA-xvvf-v9gv-r484

около 4 лет назад

The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-xvvf-rwfm-7qrx

около 2 лет назад

Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xvvf-5vw8-ww5f

около 4 лет назад

bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xvvc-9r93-427f

8 дней назад

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvv9-wwh9-rq4w

больше 4 лет назад

The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvv9-f9hm-rghr

около 4 лет назад

Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvv9-5j67-3rpq

почти 3 года назад

zola Path Traversal vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvv9-3xj2-h727

около 4 лет назад

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvv8-rrjg-xrq4

больше 1 года назад

Missing Authorization vulnerability in Eniture Technology Pallet Packaging for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pallet Packaging for WooCommerce: from n/a through 1.1.15.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvv8-8wh9-9fh2

около 4 лет назад

Keycloak Authentication Error

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvv8-2hxw-mghp

7 месяцев назад

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xvv7-wqpf-2qrv

больше 2 лет назад

The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvv7-9gx9-6xh5

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xvv7-73jx-5wcg

6 месяцев назад

A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. Upgrading to version 8.21 is able to mitigate this issue. The name of the patch is 0f5a9c38778ca550cbab6c5093470e1e90cb837f. Upgrading the affected component is advised.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvv6-p4wf-mvx7

3 месяца назад

TYPO3 CMS Stores Cleartext Password in User Settings Module

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvv5-rwhg-mg45

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: dm integrity: Fix UAF in dm_integrity_dtr() Dm_integrity also has the same UAF problem when dm_resume() and dm_destroy() are concurrent. Therefore, cancelling timer again in dm_integrity_dtr().

EPSS: Низкий
github логотип

GHSA-xvv5-hxv6-mmcg

6 месяцев назад

A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xvv5-hhxw-j52w

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt This leak will cause a hang when tearing down the SCSI host. For example, iscsid hangs with the following call trace: [130120.652718] scsi_alloc_sdev: Allocation failure during SCSI scanning, some SCSI devices might not be configured PID: 2528 TASK: ffff9d0408974e00 CPU: 3 COMMAND: "iscsid" #0 [ffffb5b9c134b9e0] __schedule at ffffffff860657d4 #1 [ffffb5b9c134ba28] schedule at ffffffff86065c6f #2 [ffffb5b9c134ba40] schedule_timeout at ffffffff86069fb0 #3 [ffffb5b9c134bab0] __wait_for_common at ffffffff8606674f #4 [ffffb5b9c134bb10] scsi_remove_host at ffffffff85bfe84b #5 [ffffb5b9c134bb30] iscsi_sw_tcp_session_destroy at ffffffffc03031c4 [iscsi_tcp] #6 [ffffb5b9c134bb48] iscsi_if_recv_msg at ffffffffc0292692 [scsi_transport_iscsi] #7 [ffffb5b9c134bb98] iscsi_if_rx at ffffffffc02929c2 [scsi_transport_iscsi] #8 [ffffb5b9c134bbf0] netlink_unicast at ff...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvvg-qwqf-w23x

The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvvf-vgph-gpgv

Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvvf-v9gv-r484

The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which has unknown impact and attack vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvvf-rwfm-7qrx

Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

CVSS3: 4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvvf-5vw8-ww5f

bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).

CVSS3: 5.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvvc-9r93-427f

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.

CVSS3: 9.8
0%
Низкий
8 дней назад
github логотип
GHSA-xvv9-wwh9-rq4w

The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvv9-f9hm-rghr

Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvv9-5j67-3rpq

zola Path Traversal vulnerability

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xvv9-3xj2-h727

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xvv8-rrjg-xrq4

Missing Authorization vulnerability in Eniture Technology Pallet Packaging for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pallet Packaging for WooCommerce: from n/a through 1.1.15.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvv8-8wh9-9fh2

Keycloak Authentication Error

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xvv8-2hxw-mghp

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xvv7-wqpf-2qrv

The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvv7-9gx9-6xh5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvv7-73jx-5wcg

A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. Upgrading to version 8.21 is able to mitigate this issue. The name of the patch is 0f5a9c38778ca550cbab6c5093470e1e90cb837f. Upgrading the affected component is advised.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvv6-p4wf-mvx7

TYPO3 CMS Stores Cleartext Password in User Settings Module

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xvv5-rwhg-mg45

In the Linux kernel, the following vulnerability has been resolved: dm integrity: Fix UAF in dm_integrity_dtr() Dm_integrity also has the same UAF problem when dm_resume() and dm_destroy() are concurrent. Therefore, cancelling timer again in dm_integrity_dtr().

0%
Низкий
7 месяцев назад
github логотип
GHSA-xvv5-hxv6-mmcg

A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvv5-hhxw-j52w

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt This leak will cause a hang when tearing down the SCSI host. For example, iscsid hangs with the following call trace: [130120.652718] scsi_alloc_sdev: Allocation failure during SCSI scanning, some SCSI devices might not be configured PID: 2528 TASK: ffff9d0408974e00 CPU: 3 COMMAND: "iscsid" #0 [ffffb5b9c134b9e0] __schedule at ffffffff860657d4 #1 [ffffb5b9c134ba28] schedule at ffffffff86065c6f #2 [ffffb5b9c134ba40] schedule_timeout at ffffffff86069fb0 #3 [ffffb5b9c134bab0] __wait_for_common at ffffffff8606674f #4 [ffffb5b9c134bb10] scsi_remove_host at ffffffff85bfe84b #5 [ffffb5b9c134bb30] iscsi_sw_tcp_session_destroy at ffffffffc03031c4 [iscsi_tcp] #6 [ffffb5b9c134bb48] iscsi_if_recv_msg at ffffffffc0292692 [scsi_transport_iscsi] #7 [ffffb5b9c134bb98] iscsi_if_rx at ffffffffc02929c2 [scsi_transport_iscsi] #8 [ffffb5b9c134bbf0] netlink_unicast at ff...

CVSS3: 5.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу