Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 311 347

Количество 311 347

github логотип

GHSA-2hhg-c3w2-vgr6

почти 4 года назад

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

EPSS: Низкий
github логотип

GHSA-2hhg-24wg-6mmv

около 1 года назад

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hhf-q463-9hv4

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

EPSS: Низкий
github логотип

GHSA-2hhf-gxff-r59q

больше 2 лет назад

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hhf-9f74-3jqg

2 месяца назад

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hhc-f86x-x74f

больше 3 лет назад

Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hhc-539m-8qw5

больше 3 лет назад

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hh9-vfrm-8f6w

больше 3 лет назад

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hh8-gpv5-pc93

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hh7-f3x9-8mgq

больше 3 лет назад

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

EPSS: Низкий
github логотип

GHSA-2hh7-5899-hfpg

5 месяцев назад

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hh6-6xcj-rrfv

больше 3 лет назад

IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hh5-jxwx-3pwr

больше 3 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hh5-254v-jpf4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free of encap entry in neigh update handler Function mlx5e_rep_neigh_update() wasn't updated to accommodate rtnl lock removal from TC filter update path and properly handle concurrent encap entry insertion/deletion which can lead to following use-after-free: [23827.464923] ================================================================== [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take+0x72/0x140 [mlx5_core] [23827.470971] Read of size 4 at addr ffff8881d132228c by task kworker/u20:6/21635 [23827.472251] [23827.472615] CPU: 9 PID: 21635 Comm: kworker/u20:6 Not tainted 5.13.0-rc3+ #5 [23827.473788] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 [23827.475639] Workqueue: mlx5e mlx5e_rep_neigh_update [mlx5_core] [23827.476731] Call Trace: [23827.477260] dump_stack+0xbb/0x107 [23827.477906] print_addre...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hh4-qfh8-22w2

почти 2 года назад

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hh4-c6pj-8p6j

7 месяцев назад

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hh4-7m9c-h6f2

больше 3 лет назад

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

EPSS: Низкий
github логотип

GHSA-2hh3-q7m3-vf3h

почти 4 года назад

post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-2hh3-jmv8-5fmx

больше 3 лет назад

Moodle Does Not Escape Characters In Email Headers

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hh3-6mr4-7gqq

больше 3 лет назад

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hhg-c3w2-vgr6

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hhg-24wg-6mmv

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2hhf-q463-9hv4

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hhf-gxff-r59q

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVSS3: 6.1
8%
Низкий
больше 2 лет назад
github логотип
GHSA-2hhf-9f74-3jqg

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2hhc-f86x-x74f

Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hhc-539m-8qw5

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

CVSS3: 8.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh9-vfrm-8f6w

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh8-gpv5-pc93

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2hh7-f3x9-8mgq

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh7-5899-hfpg

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2hh6-6xcj-rrfv

IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh5-jxwx-3pwr

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh5-254v-jpf4

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free of encap entry in neigh update handler Function mlx5e_rep_neigh_update() wasn't updated to accommodate rtnl lock removal from TC filter update path and properly handle concurrent encap entry insertion/deletion which can lead to following use-after-free: [23827.464923] ================================================================== [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take+0x72/0x140 [mlx5_core] [23827.470971] Read of size 4 at addr ffff8881d132228c by task kworker/u20:6/21635 [23827.472251] [23827.472615] CPU: 9 PID: 21635 Comm: kworker/u20:6 Not tainted 5.13.0-rc3+ #5 [23827.473788] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 [23827.475639] Workqueue: mlx5e mlx5e_rep_neigh_update [mlx5_core] [23827.476731] Call Trace: [23827.477260] dump_stack+0xbb/0x107 [23827.477906] print_addre...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hh4-qfh8-22w2

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-2hh4-c6pj-8p6j

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2hh4-7m9c-h6f2

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh3-q7m3-vf3h

post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hh3-jmv8-5fmx

Moodle Does Not Escape Characters In Email Headers

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh3-6mr4-7gqq

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу