Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-2939-pqmr-4866

почти 4 года назад

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2939-hj2x-54vq

9 месяцев назад

A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/assigned-requests.php. The manipulation of the argument teamid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2938-5hf8-58m3

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on dentry, ->d_lock on its parent, ->i_rwsem exclusive on the parent's inode, rename_lock), but none of those are met at any of the sites. Take a stable snapshot of the name instead.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2937-wfx7-vxfg

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page when @from is cloned, i.e. to->pp_recycle --> false from->pp_recycle --> true skb_cloned(from) --> true However, it actually requires skb_cloned(@from) to hold true until coalescing finishes in this situation. If the other cloned SKB is released while the merging is in process, from_shinfo->nr_frags will be set to 0 toward the end of the function, causing the increment of frag page _refcount to be unexpectedly skipped resulting in inconsistent reference counts. Later when SKB(@to) is released, it frees the page directly even though the page pool page is still in use, leading to use-after-free or double-free errors. So it should be prohibited. The double-free error message below prompted us to investi...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2936-3xwv-v4fj

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Stored XSS. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2935-f8mx-xc5w

почти 4 года назад

A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2935-2wfm-hhpv

около 1 года назад

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2934-h34j-g33x

около 2 лет назад

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2934-gw32-fqg4

3 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2933-vwp4-xpm8

6 месяцев назад

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2933-mrxr-9gj9

почти 4 года назад

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2932-f892-c8hc

почти 4 года назад

nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.

EPSS: Низкий
github логотип

GHSA-2932-63p2-x63x

около 1 года назад

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-292x-hjr8-226f

почти 4 года назад

Cloud Foundry UAA Privilege Escalation

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-292x-9cr3-pgc3

почти 4 года назад

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data as well as unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-292x-89v7-pcq6

почти 4 года назад

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

EPSS: Средний
github логотип

GHSA-292w-467q-qfj8

почти 4 года назад

xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

EPSS: Низкий
github логотип

GHSA-292w-2m2h-rw25

около 1 года назад

Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-292v-wgjp-vm43

11 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-292v-q449-fgpm

около 2 лет назад

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2939-pqmr-4866

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

CVSS3: 7.5
22%
Средний
почти 4 года назад
github логотип
GHSA-2939-hj2x-54vq

A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/assigned-requests.php. The manipulation of the argument teamid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2938-5hf8-58m3

In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on dentry, ->d_lock on its parent, ->i_rwsem exclusive on the parent's inode, rename_lock), but none of those are met at any of the sites. Take a stable snapshot of the name instead.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2937-wfx7-vxfg

In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page when @from is cloned, i.e. to->pp_recycle --> false from->pp_recycle --> true skb_cloned(from) --> true However, it actually requires skb_cloned(@from) to hold true until coalescing finishes in this situation. If the other cloned SKB is released while the merging is in process, from_shinfo->nr_frags will be set to 0 toward the end of the function, causing the increment of frag page _refcount to be unexpectedly skipped resulting in inconsistent reference counts. Later when SKB(@to) is released, it frees the page directly even though the page pool page is still in use, leading to use-after-free or double-free errors. So it should be prohibited. The double-free error message below prompted us to investi...

CVSS3: 4.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-2936-3xwv-v4fj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Stored XSS. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2935-f8mx-xc5w

A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2935-2wfm-hhpv

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-2934-h34j-g33x

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2934-gw32-fqg4

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2933-vwp4-xpm8

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2933-mrxr-9gj9

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2932-f892-c8hc

nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2932-63p2-x63x

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-292x-hjr8-226f

Cloud Foundry UAA Privilege Escalation

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-292x-9cr3-pgc3

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data as well as unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

2%
Низкий
почти 4 года назад
github логотип
GHSA-292x-89v7-pcq6

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

37%
Средний
почти 4 года назад
github логотип
GHSA-292w-467q-qfj8

xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-292w-2m2h-rw25

Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-292v-wgjp-vm43

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVSS3: 9.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-292v-q449-fgpm

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in EXR format.

CVSS3: 7.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу