Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 321 958

Количество 321 958

github логотип

GHSA-23x6-43x8-rcvc

около 1 года назад

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23x5-qv54-6pcg

больше 2 лет назад

An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23x5-phcc-jfq4

10 месяцев назад

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/academic/grading-system of the component Grading System Page. The manipulation of the argument Remark leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-23x5-j68g-6jpw

около 4 лет назад

Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23x4-m842-fmwf

почти 5 лет назад

Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-23x4-8x8q-6443

9 месяцев назад

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration. This issue affects:  Junos OS:  * all versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S5-EVO,  * 24.2-EVO versions before 24.2R2-S1-EVO * 24.4-EVO versions before 24.4R2-EVO.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-23x3-vhwf-vxrj

около 3 лет назад

Windows Win32k Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23x3-fcgm-qf4c

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback commit 1f5664351410 ("ASoC: lower "no backend DAIs enabled for ... Port" log severity") ignores -EINVAL error message on common soc_pcm_ret(). It is used from many functions, ignoring -EINVAL is over-kill. The reason why -EINVAL was ignored was it really should only be used upon invalid parameters coming from userspace and in that case we don't want to log an error since we do not want to give userspace a way to do a denial-of-service attack on the syslog / diskspace. So don't use soc_pcm_ret() on .prepare callback is better idea.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23x3-68r3-3j2p

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers When CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_STACK are enabled, the object_is_on_stack() function may produce incorrect results due to the presence of tags in the obj pointer, while the stack pointer does not have tags. This discrepancy can lead to incorrect stack object detection and subsequently trigger warnings if CONFIG_DEBUG_OBJECTS is also enabled. Example of the warning: ODEBUG: object 3eff800082ea7bb0 is NOT on stack ffff800082ea0000, but annotated. ------------[ cut here ]------------ WARNING: CPU: 0 PID: 1 at lib/debugobjects.c:557 __debug_object_init+0x330/0x364 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc5 #4 Hardware name: linux,dummy-virt (DT) pstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __debug_object_init+0x330/0x364 lr : __debug_object_init+0x330/0x364 sp : ffff800082ea7b4...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23x3-5g9f-qhxq

почти 4 года назад

The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted COFF based file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23x2-xqxm-pxwj

почти 4 года назад

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23x2-rwgc-35fv

больше 3 лет назад

IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23x2-p68q-c69p

почти 4 года назад

A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-23x2-f488-jm35

почти 4 года назад

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23x2-c6m6-m9c7

почти 4 года назад

Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.

EPSS: Низкий
github логотип

GHSA-23wx-cgxq-vpwx

почти 4 года назад

Prototype Pollution in dset

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23wx-6wm2-v53g

почти 4 года назад

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23ww-hxf9-47fc

10 месяцев назад

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-23ww-2jh7-98f9

почти 4 года назад

search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.

EPSS: Низкий
github логотип

GHSA-23wv-w3v2-hcrj

больше 1 года назад

Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23x6-43x8-rcvc

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
4%
Низкий
около 1 года назад
github логотип
GHSA-23x5-qv54-6pcg

An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23x5-phcc-jfq4

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/academic/grading-system of the component Grading System Page. The manipulation of the argument Remark leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-23x5-j68g-6jpw

Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-23x4-m842-fmwf

Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator

CVSS3: 9.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-23x4-8x8q-6443

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration. This issue affects:  Junos OS:  * all versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S5-EVO,  * 24.2-EVO versions before 24.2R2-S1-EVO * 24.4-EVO versions before 24.4R2-EVO.

CVSS3: 5.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-23x3-vhwf-vxrj

Windows Win32k Elevation of Privilege Vulnerability.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-23x3-fcgm-qf4c

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback commit 1f5664351410 ("ASoC: lower "no backend DAIs enabled for ... Port" log severity") ignores -EINVAL error message on common soc_pcm_ret(). It is used from many functions, ignoring -EINVAL is over-kill. The reason why -EINVAL was ignored was it really should only be used upon invalid parameters coming from userspace and in that case we don't want to log an error since we do not want to give userspace a way to do a denial-of-service attack on the syslog / diskspace. So don't use soc_pcm_ret() on .prepare callback is better idea.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-23x3-68r3-3j2p

In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers When CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_STACK are enabled, the object_is_on_stack() function may produce incorrect results due to the presence of tags in the obj pointer, while the stack pointer does not have tags. This discrepancy can lead to incorrect stack object detection and subsequently trigger warnings if CONFIG_DEBUG_OBJECTS is also enabled. Example of the warning: ODEBUG: object 3eff800082ea7bb0 is NOT on stack ffff800082ea0000, but annotated. ------------[ cut here ]------------ WARNING: CPU: 0 PID: 1 at lib/debugobjects.c:557 __debug_object_init+0x330/0x364 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc5 #4 Hardware name: linux,dummy-virt (DT) pstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __debug_object_init+0x330/0x364 lr : __debug_object_init+0x330/0x364 sp : ffff800082ea7b4...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23x3-5g9f-qhxq

The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted COFF based file.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-23x2-xqxm-pxwj

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

CVSS3: 7.1
4%
Низкий
почти 4 года назад
github логотип
GHSA-23x2-rwgc-35fv

IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23x2-p68q-c69p

A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-23x2-f488-jm35

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-23x2-c6m6-m9c7

Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23wx-cgxq-vpwx

Prototype Pollution in dset

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-23wx-6wm2-v53g

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-23ww-hxf9-47fc

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-23ww-2jh7-98f9

search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.

4%
Низкий
почти 4 года назад
github логотип
GHSA-23wv-w3v2-hcrj

Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php

CVSS3: 5.9
0%
Низкий
больше 1 года назад

Уязвимостей на страницу