Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v86-x4wc-r83p

около 4 лет назад

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4v86-55fp-qc5m

больше 4 лет назад

IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.

EPSS: Низкий
github логотип

GHSA-4v84-gvmh-336p

больше 4 лет назад

KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4v83-595j-687r

больше 4 лет назад

The workgroup bridge (aka WGB) functionality in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (dropped connection) via a series of spoofed EAPoL-Logoff frames, related to an "EAPoL logoff attack," aka Bug ID CSCte43374.

EPSS: Низкий
github логотип

GHSA-4v82-mf94-m3qq

больше 4 лет назад

SQL injection vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to execute arbitrary SQL commands via the q parameter.

EPSS: Низкий
github логотип

GHSA-4v82-m79g-wgg4

больше 4 лет назад

Vulnerability in the Oracle Cloud Infrastructure Data Science Notebook Sessions. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Cloud Infrastructure Data Science Notebook Sessions executes to compromise Oracle Cloud Infrastructure Data Science Notebook Sessions. Successful attacks of this vulnerability can resultin unauthorized update, insert or delete access to some of Oracle Cloud Infrastructure Data Science Notebook Sessions accessible data as well as unauthorized read access to a subset of Oracle Cloud Infrastructure Data Science Notebook Sessions accessible data. All affected customers were notified of CVE-2021-2138 by Oracle. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

EPSS: Низкий
github логотип

GHSA-4v82-6mr7-c9f3

почти 4 года назад

An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4v82-25rx-c86g

больше 4 лет назад

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4v7x-pqxf-cx7m

больше 2 лет назад

net/http, x/net/http2: close connections when receiving too many headers

CVSS3: 5.3
EPSS: Критический
github логотип

GHSA-4v7w-jq2v-52pw

больше 4 лет назад

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v7v-9hh5-q3vp

около 1 года назад

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4v7v-7v7r-3r5h

8 месяцев назад

FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4v7v-2c44-w644

больше 4 лет назад

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

EPSS: Низкий
github логотип

GHSA-4v7r-f8hg-362g

почти 3 года назад

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v7r-f4w8-8972

4 месяца назад

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-4v7r-5cqf-6h4r

около 2 месяцев назад

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v7q-426w-6494

больше 4 лет назад

A heap-based buffer overflow exists in stbi__bmp_load_cont in stb_image.h in catimg 2.4.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4v7q-34w2-x874

больше 4 лет назад

The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4v7m-g3xm-g9cp

больше 4 лет назад

An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).

EPSS: Низкий
github логотип

GHSA-4v7m-9h3p-c5mq

больше 4 лет назад

Denial of service in MDaemon WorldClient and WebConfig services via a long URL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v86-x4wc-r83p

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

CVSS3: 7.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-4v86-55fp-qc5m

IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v84-gvmh-336p

KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

CVSS3: 9.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v83-595j-687r

The workgroup bridge (aka WGB) functionality in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (dropped connection) via a series of spoofed EAPoL-Logoff frames, related to an "EAPoL logoff attack," aka Bug ID CSCte43374.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v82-mf94-m3qq

SQL injection vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to execute arbitrary SQL commands via the q parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v82-m79g-wgg4

Vulnerability in the Oracle Cloud Infrastructure Data Science Notebook Sessions. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Cloud Infrastructure Data Science Notebook Sessions executes to compromise Oracle Cloud Infrastructure Data Science Notebook Sessions. Successful attacks of this vulnerability can resultin unauthorized update, insert or delete access to some of Oracle Cloud Infrastructure Data Science Notebook Sessions accessible data as well as unauthorized read access to a subset of Oracle Cloud Infrastructure Data Science Notebook Sessions accessible data. All affected customers were notified of CVE-2021-2138 by Oracle. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v82-6mr7-c9f3

An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-4v82-25rx-c86g

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7x-pqxf-cx7m

net/http, x/net/http2: close connections when receiving too many headers

CVSS3: 5.3
92%
Критический
больше 2 лет назад
github логотип
GHSA-4v7w-jq2v-52pw

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7v-9hh5-q3vp

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.

CVSS3: 7.2
1%
Низкий
около 1 года назад
github логотип
GHSA-4v7v-7v7r-3r5h

FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View

CVSS3: 8
0%
Низкий
8 месяцев назад
github логотип
GHSA-4v7v-2c44-w644

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7r-f8hg-362g

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4v7r-f4w8-8972

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

CVSS3: 8.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4v7r-5cqf-6h4r

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4v7q-426w-6494

A heap-based buffer overflow exists in stbi__bmp_load_cont in stb_image.h in catimg 2.4.0.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7q-34w2-x874

The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7m-g3xm-g9cp

An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7m-9h3p-c5mq

Denial of service in MDaemon WorldClient and WebConfig services via a long URL.

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу