Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 322

Количество 56 322

redhat логотип

CVE-2024-21534

почти 2 года назад

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-21529

почти 2 года назад

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2024-21528

почти 2 года назад

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2024-21520

около 2 лет назад

Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-21512

больше 2 лет назад

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2024-21511

больше 2 лет назад

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-21510

почти 2 года назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2024-21509

больше 2 лет назад

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-21508

больше 2 лет назад

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-21507

больше 2 лет назад

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-21506

больше 2 лет назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2024-21503

больше 2 лет назад

Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service. Exploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-21501

больше 2 лет назад

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-21490

больше 2 лет назад

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-21489

почти 2 года назад

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2024-21484

больше 2 лет назад

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-21409

больше 2 лет назад

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2024-21404

больше 2 лет назад

.NET Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-21392

больше 2 лет назад

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-21386

больше 2 лет назад

.NET Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-21534

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVSS3: 9.8
9%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-21529

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program.

CVSS3: 8.2
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-21528

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

CVSS3: 5.9
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-21520

Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-21512

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

CVSS3: 8.2
3%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21511

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-21509

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21508

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21507

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21506

No description is available for this CVE.

больше 2 лет назад
redhat логотип
CVE-2024-21503

Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service. Exploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21501

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21490

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21489

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

CVSS3: 8.2
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-21484

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21409

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

CVSS3: 7.3
3%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21404

.NET Denial of Service Vulnerability

CVSS3: 7.5
3%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21392

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
3%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-21386

.NET Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу