Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-35gq-67f6-phh5

почти 2 года назад

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35gp-jxw8-xw6h

больше 3 лет назад

Codiad CSRF Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35gp-6hvq-gx74

больше 3 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.

EPSS: Низкий
github логотип

GHSA-35gp-5q9f-g9pq

больше 1 года назад

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-35gm-xggq-mjxq

больше 3 лет назад

show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.

EPSS: Низкий
github логотип

GHSA-35gm-cw3v-mj5j

больше 2 лет назад

The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-35gj-2h6h-27p5

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak in rx_desc and tx_desc Currently when ath12k_dp_cc_desc_init() is called we allocate memory to rx_descs and tx_descs. In ath12k_dp_cc_cleanup(), during descriptor cleanup rx_descs and tx_descs memory is not freed. This is cause of memory leak. These allocated memory should be freed in ath12k_dp_cc_cleanup. In ath12k_dp_cc_desc_init(), we can save base address of rx_descs and tx_descs. In ath12k_dp_cc_cleanup(), we can free rx_descs and tx_descs memory using their base address. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1

EPSS: Низкий
github логотип

GHSA-35gh-vgcm-m7v3

10 месяцев назад

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassword/txtfullname/txtemail leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-35gh-gpw3-mx2q

больше 1 года назад

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35gh-9rr7-fw4g

больше 2 лет назад

In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35gg-hfjv-3g6c

больше 3 лет назад

An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35gg-5cvh-w445

больше 3 лет назад

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-35gg-3hw5-mf59

почти 2 года назад

Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35gf-xjgf-96c5

больше 2 лет назад

Jenkins OpenShift Login Plugin vulnerable to Open Redirect

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35gc-287r-3fpq

больше 2 лет назад

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-35g9-pq5m-qcf5

больше 3 лет назад

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35g9-mghc-h66h

почти 4 года назад

Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.

EPSS: Низкий
github логотип

GHSA-35g9-c897-73x7

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-35g9-4fjq-g938

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.

EPSS: Низкий
github логотип

GHSA-35g8-4m6m-fr64

больше 3 лет назад

In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-172655291

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35gq-67f6-phh5

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-35gp-jxw8-xw6h

Codiad CSRF Vulnerability

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35gp-6hvq-gx74

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-35gp-5q9f-g9pq

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-35gm-xggq-mjxq

show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35gm-cw3v-mj5j

The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35gj-2h6h-27p5

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak in rx_desc and tx_desc Currently when ath12k_dp_cc_desc_init() is called we allocate memory to rx_descs and tx_descs. In ath12k_dp_cc_cleanup(), during descriptor cleanup rx_descs and tx_descs memory is not freed. This is cause of memory leak. These allocated memory should be freed in ath12k_dp_cc_cleanup. In ath12k_dp_cc_desc_init(), we can save base address of rx_descs and tx_descs. In ath12k_dp_cc_cleanup(), we can free rx_descs and tx_descs memory using their base address. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-35gh-vgcm-m7v3

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassword/txtfullname/txtemail leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-35gh-gpw3-mx2q

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35gh-9rr7-fw4g

In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-35gg-hfjv-3g6c

An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35gg-5cvh-w445

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

CVSS3: 7.5
16%
Средний
больше 3 лет назад
github логотип
GHSA-35gg-3hw5-mf59

Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability

CVSS3: 7.5
7%
Низкий
почти 2 года назад
github логотип
GHSA-35gf-xjgf-96c5

Jenkins OpenShift Login Plugin vulnerable to Open Redirect

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35gc-287r-3fpq

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35g9-pq5m-qcf5

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35g9-mghc-h66h

Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.

1%
Низкий
почти 4 года назад
github логотип
GHSA-35g9-c897-73x7

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35g9-4fjq-g938

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35g8-4m6m-fr64

In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-172655291

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу