Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-293j-rh9p-w2r8

больше 3 лет назад

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

EPSS: Низкий
github логотип

GHSA-293j-h7h4-4rp5

почти 4 года назад

Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-293j-3754-3xrj

почти 4 года назад

PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

EPSS: Низкий
github логотип

GHSA-293h-rg6q-5hxj

почти 4 года назад

BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

EPSS: Низкий
github логотип

GHSA-293h-f2f3-6fqq

больше 1 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-293h-cqj2-8x83

больше 3 лет назад

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

EPSS: Низкий
github логотип

GHSA-293h-57f9-wc4c

больше 3 лет назад

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2939-pqmr-4866

больше 3 лет назад

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2939-hj2x-54vq

7 месяцев назад

A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/assigned-requests.php. The manipulation of the argument teamid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2938-5hf8-58m3

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on dentry, ->d_lock on its parent, ->i_rwsem exclusive on the parent's inode, rename_lock), but none of those are met at any of the sites. Take a stable snapshot of the name instead.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2937-wfx7-vxfg

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page when @from is cloned, i.e. to->pp_recycle --> false from->pp_recycle --> true skb_cloned(from) --> true However, it actually requires skb_cloned(@from) to hold true until coalescing finishes in this situation. If the other cloned SKB is released while the merging is in process, from_shinfo->nr_frags will be set to 0 toward the end of the function, causing the increment of frag page _refcount to be unexpectedly skipped resulting in inconsistent reference counts. Later when SKB(@to) is released, it frees the page directly even though the page pool page is still in use, leading to use-after-free or double-free errors. So it should be prohibited. The double-free error message below prompted us to investi...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2936-3xwv-v4fj

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Stored XSS. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2935-f8mx-xc5w

больше 3 лет назад

A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2935-2wfm-hhpv

11 месяцев назад

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2934-h34j-g33x

около 2 лет назад

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2934-gw32-fqg4

около 1 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2933-vwp4-xpm8

4 месяца назад

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2933-mrxr-9gj9

больше 3 лет назад

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2932-f892-c8hc

почти 4 года назад

nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.

EPSS: Низкий
github логотип

GHSA-2932-63p2-x63x

около 1 года назад

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-293j-rh9p-w2r8

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-293j-h7h4-4rp5

Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
почти 4 года назад
github логотип
GHSA-293j-3754-3xrj

PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-293h-rg6q-5hxj

BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293h-f2f3-6fqq

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-293h-cqj2-8x83

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293h-57f9-wc4c

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2939-pqmr-4866

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

CVSS3: 7.5
19%
Средний
больше 3 лет назад
github логотип
GHSA-2939-hj2x-54vq

A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/assigned-requests.php. The manipulation of the argument teamid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2938-5hf8-58m3

In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on dentry, ->d_lock on its parent, ->i_rwsem exclusive on the parent's inode, rename_lock), but none of those are met at any of the sites. Take a stable snapshot of the name instead.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2937-wfx7-vxfg

In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page when @from is cloned, i.e. to->pp_recycle --> false from->pp_recycle --> true skb_cloned(from) --> true However, it actually requires skb_cloned(@from) to hold true until coalescing finishes in this situation. If the other cloned SKB is released while the merging is in process, from_shinfo->nr_frags will be set to 0 toward the end of the function, causing the increment of frag page _refcount to be unexpectedly skipped resulting in inconsistent reference counts. Later when SKB(@to) is released, it frees the page directly even though the page pool page is still in use, leading to use-after-free or double-free errors. So it should be prohibited. The double-free error message below prompted us to investi...

CVSS3: 4.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-2936-3xwv-v4fj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Stored XSS. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2935-f8mx-xc5w

A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2935-2wfm-hhpv

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

CVSS3: 4.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-2934-h34j-g33x

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2934-gw32-fqg4

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2933-vwp4-xpm8

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2933-mrxr-9gj9

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2932-f892-c8hc

nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2932-63p2-x63x

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.

CVSS3: 5.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу