Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4x2c-gqrf-gvf9

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4x29-79gh-6v8q

3 месяца назад

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4x29-4984-2qcp

больше 4 лет назад

The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.

EPSS: Низкий
github логотип

GHSA-4x28-j85r-668q

больше 4 лет назад

ForkCMS Directory Traversal vulnerability

EPSS: Низкий
github логотип

GHSA-4x28-f32q-r2qv

11 месяцев назад

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-4x27-7f5c-rg8p

почти 3 года назад

A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4x26-g7hr-m7g8

почти 3 года назад

Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4x26-g6p5-4wpg

больше 4 лет назад

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x25-wq2v-85f9

больше 4 лет назад

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4x25-pvhw-5224

около 5 лет назад

Algorithms compute incorrect results in blake2

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x25-gh54-whv9

больше 4 лет назад

App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.

EPSS: Низкий
github логотип

GHSA-4x25-f45x-grv5

около 5 лет назад

Missing encryption in Apache Directory Studio

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4x25-f42w-9g46

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4x25-3w8p-m6r3

больше 4 лет назад

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21844, CVE-2022-21926.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4x24-p8p8-r7hm

больше 4 лет назад

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x24-3v7p-2g45

6 месяцев назад

A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4x22-rf55-6p54

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-4x22-m2xr-v7q7

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt wait_for_completion_interruptible_timeout() returns -ERESTARTSYS when interrupted. This needs to abort the URB and return an error. No data has been received from the device so any reads from the transfer buffer are invalid. The original code tests !ret, which only catches the timeout case (0). On signal delivery (-ERESTARTSYS), !ret is false so the function skips usb_kill_urb() and falls through to read from the unfilled transfer buffer. Fix by capturing the return value into a long (matching the function return type) and handling signal (negative) and timeout (zero) cases with separate checks that both call usb_kill_urb() before returning.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4x22-h5rw-64w4

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar allows Stored XSS. This issue affects Bg Orthodox Calendar: from n/a through 0.13.10.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4x22-3827-w69r

15 дней назад

Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4x2c-gqrf-gvf9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4x29-79gh-6v8q

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

CVSS3: 9.1
1%
Низкий
3 месяца назад
github логотип
GHSA-4x29-4984-2qcp

The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4x28-j85r-668q

ForkCMS Directory Traversal vulnerability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x28-f32q-r2qv

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

CVSS3: 5.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-4x27-7f5c-rg8p

A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-4x26-g7hr-m7g8

Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-4x26-g6p5-4wpg

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4x25-wq2v-85f9

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVSS3: 7.5
28%
Средний
больше 4 лет назад
github логотип
GHSA-4x25-pvhw-5224

Algorithms compute incorrect results in blake2

CVSS3: 9.8
1%
Низкий
около 5 лет назад
github логотип
GHSA-4x25-gh54-whv9

App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4x25-f45x-grv5

Missing encryption in Apache Directory Studio

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-4x25-f42w-9g46

Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x25-3w8p-m6r3

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21844, CVE-2022-21926.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x24-p8p8-r7hm

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4x24-3v7p-2g45

A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4x22-rf55-6p54

Rejected reason: Not used

7 месяцев назад
github логотип
GHSA-4x22-m2xr-v7q7

In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt wait_for_completion_interruptible_timeout() returns -ERESTARTSYS when interrupted. This needs to abort the URB and return an error. No data has been received from the device so any reads from the transfer buffer are invalid. The original code tests !ret, which only catches the timeout case (0). On signal delivery (-ERESTARTSYS), !ret is false so the function skips usb_kill_urb() and falls through to read from the unfilled transfer buffer. Fix by capturing the return value into a long (matching the function return type) and handling signal (negative) and timeout (zero) cases with separate checks that both call usb_kill_urb() before returning.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4x22-h5rw-64w4

Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar allows Stored XSS. This issue affects Bg Orthodox Calendar: from n/a through 0.13.10.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4x22-3827-w69r

Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
15 дней назад

Уязвимостей на страницу