Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2021-24032

больше 1 года назад

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2021-23980

11 месяцев назад

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

EPSS: Низкий
msrc логотип

CVE-2021-23841

11 месяцев назад

Null pointer deref in X509_issuer_and_serial_hash()

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2021-23840

11 месяцев назад

Integer overflow in CipherUpdate

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2021-2357

около 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-2356

около 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2021-2354

около 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-2352

около 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-23445

7 месяцев назад

Cross-site Scripting (XSS)

EPSS: Низкий
msrc логотип

CVE-2021-2340

около 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
EPSS: Низкий
msrc логотип

CVE-2021-2339

около 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-23358

11 месяцев назад

Arbitrary Code Injection

EPSS: Низкий
msrc логотип

CVE-2021-23336

почти 2 года назад

CVSS3: 5.9
EPSS: Средний
msrc логотип

CVE-2021-23240

больше 5 лет назад

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-23239

больше 5 лет назад

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

CVSS3: 2.5
EPSS: Низкий
msrc логотип

CVE-2021-23222

больше 4 лет назад

A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2021-23214

больше 4 лет назад

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of SSL certificate verification and encryption.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2021-23192

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-23134

около 5 лет назад

Linux kernel llcp_sock_bind/connect use-after-free

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-23133

больше 5 лет назад

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 4.7
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2021-23980

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2021-23841

Null pointer deref in X509_issuer_and_serial_hash()

CVSS3: 5.9
7%
Низкий
11 месяцев назад
msrc логотип
CVE-2021-23840

Integer overflow in CipherUpdate

CVSS3: 7.5
51%
Средний
11 месяцев назад
msrc логотип
CVE-2021-2357

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
3%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-2356

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.9
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-2354

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
3%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-2352

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
3%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-23445

Cross-site Scripting (XSS)

2%
Низкий
7 месяцев назад
msrc логотип
CVE-2021-2340

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-2339

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-23358

Arbitrary Code Injection

4%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 5.9
36%
Средний
почти 2 года назад
msrc логотип
CVE-2021-23240

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.

CVSS3: 7.8
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-23239

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

CVSS3: 2.5
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-23222

A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-23214

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of SSL certificate verification and encryption.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
почти 2 года назад
msrc логотип
CVE-2021-23134

Linux kernel llcp_sock_bind/connect use-after-free

CVSS3: 7.8
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 7
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу