Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33h3-4p7j-r54j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: RDMA: Fix use-after-free in rxe_queue_cleanup On error handling path in rxe_qp_from_init() qp->sq.queue is freed and then rxe_create_qp() will drop last reference to this object. qp clean up function will try to free this queue one time and it causes UAF bug. Fix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33h2-rxgw-84jc

больше 2 лет назад

In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ALPS07937105.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-33h2-rv7w-ppfj

больше 3 лет назад

An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() would have done. Without this fix, adnshost may read and process one byte beyond the buffer, perhaps crashing or perhaps somehow leaking the value of that byte.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33h2-c39r-888q

почти 3 года назад

A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edoc/doctor/patient.php. The manipulation of the argument search12 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221821 was assigned to this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33h2-69j3-r336

больше 4 лет назад

Out-of-bounds Read in OpenCV

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33gx-m93p-j6wc

больше 2 лет назад

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gx-2jcq-hq54

больше 3 лет назад

phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php, which allows remote attackers to execute arbitrary PHP code.

EPSS: Низкий
github логотип

GHSA-33gw-pvgj-248f

около 2 лет назад

A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248689 was assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gw-fhjf-8v75

больше 3 лет назад

cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33gv-rvgq-gpxp

около 3 лет назад

Withdrawn Advisory: HTML injections in BTCPayServer

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33gr-vm8m-gj5m

больше 3 лет назад

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a denial of service (NULL pointer dereference, and device hang or reboot) via a crafted media file, aka internal bug 29770686.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33gr-gjg6-c627

3 месяца назад

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33gq-q699-4w29

около 1 года назад

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-33gq-cgfx-f6m6

почти 4 года назад

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

EPSS: Низкий
github логотип

GHSA-33gp-gmg3-hfpq

больше 1 года назад

XWiki Platform vulnerable to document deletion and overwrite from edit

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gm-x234-gjx5

почти 3 года назад

File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33gm-hf2j-r258

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

EPSS: Средний
github логотип

GHSA-33gj-cgfq-5j2j

около 2 лет назад

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gh-f3xq-j9hx

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33gg-5m74-52cv

больше 3 лет назад

A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33h3-4p7j-r54j

In the Linux kernel, the following vulnerability has been resolved: RDMA: Fix use-after-free in rxe_queue_cleanup On error handling path in rxe_qp_from_init() qp->sq.queue is freed and then rxe_create_qp() will drop last reference to this object. qp clean up function will try to free this queue one time and it causes UAF bug. Fix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-33h2-rxgw-84jc

In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ALPS07937105.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33h2-rv7w-ppfj

An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() would have done. Without this fix, adnshost may read and process one byte beyond the buffer, perhaps crashing or perhaps somehow leaking the value of that byte.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33h2-c39r-888q

A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edoc/doctor/patient.php. The manipulation of the argument search12 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221821 was assigned to this vulnerability.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-33h2-69j3-r336

Out-of-bounds Read in OpenCV

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-33gx-m93p-j6wc

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33gx-2jcq-hq54

phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php, which allows remote attackers to execute arbitrary PHP code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-33gw-pvgj-248f

A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248689 was assigned to this vulnerability.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-33gw-fhjf-8v75

cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33gv-rvgq-gpxp

Withdrawn Advisory: HTML injections in BTCPayServer

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-33gr-vm8m-gj5m

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a denial of service (NULL pointer dereference, and device hang or reboot) via a crafted media file, aka internal bug 29770686.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33gr-gjg6-c627

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-33gq-q699-4w29

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

CVSS3: 7.6
0%
Низкий
около 1 года назад
github логотип
GHSA-33gq-cgfx-f6m6

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

8%
Низкий
почти 4 года назад
github логотип
GHSA-33gp-gmg3-hfpq

XWiki Platform vulnerable to document deletion and overwrite from edit

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-33gm-x234-gjx5

File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-33gm-hf2j-r258

Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

19%
Средний
почти 4 года назад
github логотип
GHSA-33gj-cgfq-5j2j

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-33gh-f3xq-j9hx

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33gg-5m74-52cv

A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу