Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-35r4-97wh-88x3

больше 3 лет назад

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

EPSS: Низкий
github логотип

GHSA-35r4-377q-pc5v

около 1 года назад

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35r3-xfww-vf6j

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35qx-qjjj-9pfh

6 месяцев назад

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35qx-pprw-fwph

больше 2 лет назад

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-35qx-m8hh-rrjv

больше 3 лет назад

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

EPSS: Средний
github логотип

GHSA-35qx-9vmg-3r4c

больше 3 лет назад

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

EPSS: Низкий
github логотип

GHSA-35qx-2fq7-2xm7

почти 4 года назад

Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.

EPSS: Низкий
github логотип

GHSA-35qw-m5x8-mjp9

больше 1 года назад

SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35qw-h594-mg3j

почти 2 года назад

Information disclosure while parsing dts header atom in Video.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-35qw-c8w7-fcg8

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850 GCC_GCC_PCIE_HOT_RST is wrongly defined for WCN7850, causing kernel crash on some specific platforms. Since this register is divergent for WCN7850 and QCN9274, move it to register table to allow different definitions. Then correct the register address for WCN7850 to fix this issue. Note IPQ5332 is not affected as it is not PCIe based device. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35qw-9rhr-g626

9 месяцев назад

A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component POST Request Handler. The manipulation of the argument sortid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-35qw-3m24-r2j5

около 2 лет назад

Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-35qw-39fh-853x

больше 3 лет назад

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

EPSS: Низкий
github логотип

GHSA-35qr-m9p5-57hv

почти 4 года назад

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-35qr-4q99-cqm9

10 месяцев назад

Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bring Fraktguiden for WooCommerce: from n/a through 1.11.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35qq-wvhr-hv5f

почти 4 года назад

Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.

EPSS: Низкий
github логотип

GHSA-35qq-95r4-7cg5

больше 3 лет назад

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35qp-xq9f-2rjx

больше 4 лет назад

Improper Privilege Management in HashiCorp Nomad

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35qp-vx95-wwwf

22 дня назад

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35r4-97wh-88x3

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-35r4-377q-pc5v

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVSS3: 4.3
2%
Низкий
около 1 года назад
github логотип
GHSA-35r3-xfww-vf6j

In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-35qx-qjjj-9pfh

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-35qx-pprw-fwph

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164.

CVSS3: 2.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35qx-m8hh-rrjv

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

12%
Средний
больше 3 лет назад
github логотип
GHSA-35qx-9vmg-3r4c

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35qx-2fq7-2xm7

Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.

0%
Низкий
почти 4 года назад
github логотип
GHSA-35qw-m5x8-mjp9

SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-35qw-h594-mg3j

Information disclosure while parsing dts header atom in Video.

CVSS3: 6.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-35qw-c8w7-fcg8

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850 GCC_GCC_PCIE_HOT_RST is wrongly defined for WCN7850, causing kernel crash on some specific platforms. Since this register is divergent for WCN7850 and QCN9274, move it to register table to allow different definitions. Then correct the register address for WCN7850 to fix this issue. Note IPQ5332 is not affected as it is not PCIe based device. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-35qw-9rhr-g626

A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component POST Request Handler. The manipulation of the argument sortid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-35qw-3m24-r2j5

Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 6.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-35qw-39fh-853x

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35qr-m9p5-57hv

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

1%
Низкий
почти 4 года назад
github логотип
GHSA-35qr-4q99-cqm9

Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bring Fraktguiden for WooCommerce: from n/a through 1.11.4.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-35qq-wvhr-hv5f

Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-35qq-95r4-7cg5

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35qp-xq9f-2rjx

Improper Privilege Management in HashiCorp Nomad

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35qp-vx95-wwwf

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

CVSS3: 9.9
0%
Низкий
22 дня назад

Уязвимостей на страницу