Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 321 178

Количество 321 178

github логотип

GHSA-23xm-cf42-h7f9

больше 3 лет назад

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function mptcp_limit_get_set of the file ip/ipmptcp.c of the component iproute2. The manipulation leads to memory leak. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-211362 is the identifier assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23xm-3rwj-r45h

почти 4 года назад

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

EPSS: Низкий
github логотип

GHSA-23xj-w5qm-57j6

почти 4 года назад

Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23xh-x244-cxmg

почти 4 года назад

Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Server Infrastructure.

EPSS: Низкий
github логотип

GHSA-23xh-3w4x-5qh2

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23xg-w5j8-3ff2

почти 4 года назад

An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs.

EPSS: Низкий
github логотип

GHSA-23xg-g252-mcgr

почти 4 года назад

SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.

EPSS: Низкий
github логотип

GHSA-23xf-wg9r-49fr

больше 3 лет назад

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-23xf-jw4c-q879

около 2 месяцев назад

IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23xf-gc3r-v6rr

больше 2 лет назад

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23xf-5535-62v5

около 3 лет назад

jeecg-boot vulnerable to SQL injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23xc-wwgh-93wr

6 месяцев назад

A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the component Comment/Guestbook. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 4.1.4 can resolve this issue. It is suggested to upgrade the affected component. According to the researcher the vendor has confirmed the flaw and fix in a private issue response.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-23x9-mmjc-x474

почти 4 года назад

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

EPSS: Средний
github логотип

GHSA-23x9-8hxr-978c

почти 4 года назад

OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23x9-2qmf-qr95

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23x8-q6vj-xc33

почти 4 года назад

An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23x8-m9wv-h49m

почти 4 года назад

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7800 before 1.0.1.58, R7800 before 1.0.2.74, R8900 before 1.0.5.18, R9000 before 1.0.5.18, and XR700 before 1.0.1.34.

EPSS: Низкий
github логотип

GHSA-23x8-j7hm-5xwf

почти 4 года назад

Improper Neutralization of Input During Web Page Generation in Apache Axis2

EPSS: Средний
github логотип

GHSA-23x8-g5mh-phmc

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up The flag I2C_HID_READ_PENDING is used to serialize I2C operations. However, this is not necessary, because I2C core already has its own locking for that. More importantly, this flag can cause a lock-up: if the flag is set in i2c_hid_xfer() and an interrupt happens, the interrupt handler (i2c_hid_irq) will check this flag and return immediately without doing anything, then the interrupt handler will be invoked again in an infinite loop. Since interrupt handler is an RT task, it takes over the CPU and the flag-clearing task never gets scheduled, thus we have a lock-up. Delete this unnecessary flag.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23x7-wjwv-f9j6

почти 4 года назад

Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23xm-cf42-h7f9

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function mptcp_limit_get_set of the file ip/ipmptcp.c of the component iproute2. The manipulation leads to memory leak. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-211362 is the identifier assigned to this vulnerability.

CVSS3: 5.5
больше 3 лет назад
github логотип
GHSA-23xm-3rwj-r45h

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23xj-w5qm-57j6

Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-23xh-x244-cxmg

Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Server Infrastructure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23xh-3w4x-5qh2

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23xg-w5j8-3ff2

An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23xg-g252-mcgr

SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23xf-wg9r-49fr

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVSS3: 9.8
94%
Критический
больше 3 лет назад
github логотип
GHSA-23xf-jw4c-q879

IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-23xf-gc3r-v6rr

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23xf-5535-62v5

jeecg-boot vulnerable to SQL injection

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-23xc-wwgh-93wr

A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the component Comment/Guestbook. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 4.1.4 can resolve this issue. It is suggested to upgrade the affected component. According to the researcher the vendor has confirmed the flaw and fix in a private issue response.

CVSS3: 3.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-23x9-mmjc-x474

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

21%
Средний
почти 4 года назад
github логотип
GHSA-23x9-8hxr-978c

OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-23x9-2qmf-qr95

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23x8-q6vj-xc33

An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-23x8-m9wv-h49m

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7800 before 1.0.1.58, R7800 before 1.0.2.74, R8900 before 1.0.5.18, R9000 before 1.0.5.18, and XR700 before 1.0.1.34.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23x8-j7hm-5xwf

Improper Neutralization of Input During Web Page Generation in Apache Axis2

22%
Средний
почти 4 года назад
github логотип
GHSA-23x8-g5mh-phmc

In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up The flag I2C_HID_READ_PENDING is used to serialize I2C operations. However, this is not necessary, because I2C core already has its own locking for that. More importantly, this flag can cause a lock-up: if the flag is set in i2c_hid_xfer() and an interrupt happens, the interrupt handler (i2c_hid_irq) will check this flag and return immediately without doing anything, then the interrupt handler will be invoked again in an infinite loop. Since interrupt handler is an RT task, it takes over the CPU and the flag-clearing task never gets scheduled, thus we have a lock-up. Delete this unnecessary flag.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-23x7-wjwv-f9j6

Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.

6%
Низкий
почти 4 года назад

Уязвимостей на страницу