Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4ww4-3fw2-49wh

больше 4 лет назад

cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4ww3-7pf6-6cmg

больше 4 лет назад

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4ww3-6ww5-444j

больше 4 лет назад

In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-207502397

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4ww3-585w-6p9r

больше 2 лет назад

There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4ww3-4m78-2f4v

больше 4 лет назад

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4ww3-3rxj-8v6q

почти 9 лет назад

actionpack allows remote attackers to bypass intended access restrictions

EPSS: Низкий
github логотип

GHSA-4ww2-rjh2-xpv9

около 2 месяцев назад

Duplicate Advisory: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

EPSS: Низкий
github логотип

GHSA-4wvx-qq9g-8hh9

больше 4 лет назад

An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wvw-75qh-fqjp

больше 2 лет назад

Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-4wvv-g662-rjm9

7 месяцев назад

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

EPSS: Низкий
github логотип

GHSA-4wvr-fq5p-2362

около 3 лет назад

The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, mod_jk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected. This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48. Users are recommended to upgrade to version 1.2.49, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wvq-x9ch-g78w

больше 4 лет назад

Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wvq-w7j8-wrfm

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE core_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT parameter list with transport_kmap_data_sg() and parses the destination TransportID with target_parse_pr_out_transport_id(). For an iSCSI TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns the ISID in iport_ptr as a raw pointer into that mapped buffer. The function then unmaps the buffer with transport_kunmap_data_sg() before dereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and core_scsi3_alloc_registration(). When the parameter list spans more than one page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses vmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual address backing iport_ptr is torn down and every subsequent dereference is a use-after-free read of the unmapped region. Keep the parameter ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wvq-85hg-6256

11 месяцев назад

Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4wvp-cwq3-wg7g

11 месяцев назад

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wvm-v4fc-prp5

около 3 лет назад

An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wvm-jj6w-gv33

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: arm64: set UXN on swapper page tables [ This issue was fixed upstream by accident in c3cee924bd85 ("arm64: head: cover entire kernel image in initial ID map") as part of a large refactoring of the arm64 boot flow. This simple fix is therefore preferred for -stable backporting ] On a system that implements FEAT_EPAN, read/write access to the idmap is denied because UXN is not set on the swapper PTEs. As a result, idmap_kpti_install_ng_mappings panics the kernel when accessing __idmap_kpti_flag. Fix it by setting UXN on these PTEs.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4wvm-h8w2-gjm9

почти 4 года назад

The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4wvm-346h-cg2w

больше 4 лет назад

SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. NOTE: The cat parameter vector is already covered by CVE-2008-4157.

EPSS: Низкий
github логотип

GHSA-4wvj-qq8r-j7f5

больше 2 лет назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable web pages. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4ww4-3fw2-49wh

cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ww3-7pf6-6cmg

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.

CVSS3: 8.8
24%
Средний
больше 4 лет назад
github логотип
GHSA-4ww3-6ww5-444j

In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-207502397

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ww3-585w-6p9r

There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4ww3-4m78-2f4v

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ww3-3rxj-8v6q

actionpack allows remote attackers to bypass intended access restrictions

2%
Низкий
почти 9 лет назад
github логотип
GHSA-4ww2-rjh2-xpv9

Duplicate Advisory: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

около 2 месяцев назад
github логотип
GHSA-4wvx-qq9g-8hh9

An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvw-75qh-fqjp

Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming

CVSS3: 2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4wvv-g662-rjm9

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

1%
Низкий
7 месяцев назад
github логотип
GHSA-4wvr-fq5p-2362

The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, mod_jk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected. This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48. Users are recommended to upgrade to version 1.2.49, which fixes the issue.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-4wvq-x9ch-g78w

Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvq-w7j8-wrfm

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE core_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT parameter list with transport_kmap_data_sg() and parses the destination TransportID with target_parse_pr_out_transport_id(). For an iSCSI TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns the ISID in iport_ptr as a raw pointer into that mapped buffer. The function then unmaps the buffer with transport_kunmap_data_sg() before dereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and core_scsi3_alloc_registration(). When the parameter list spans more than one page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses vmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual address backing iport_ptr is torn down and every subsequent dereference is a use-after-free read of the unmapped region. Keep the parameter ...

CVSS3: 9.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-4wvq-85hg-6256

Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.

CVSS3: 4.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-4wvp-cwq3-wg7g

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-4wvm-v4fc-prp5

An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4wvm-jj6w-gv33

In the Linux kernel, the following vulnerability has been resolved: arm64: set UXN on swapper page tables [ This issue was fixed upstream by accident in c3cee924bd85 ("arm64: head: cover entire kernel image in initial ID map") as part of a large refactoring of the arm64 boot flow. This simple fix is therefore preferred for -stable backporting ] On a system that implements FEAT_EPAN, read/write access to the idmap is denied because UXN is not set on the swapper PTEs. As a result, idmap_kpti_install_ng_mappings panics the kernel when accessing __idmap_kpti_flag. Fix it by setting UXN on these PTEs.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wvm-h8w2-gjm9

The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

CVSS3: 4.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4wvm-346h-cg2w

SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. NOTE: The cat parameter vector is already covered by CVE-2008-4157.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvj-qq8r-j7f5

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable web pages. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу