Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v6x-wq6p-585m

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: clk: imx: clk-imx8mn: fix memory leak in imx8mn_clocks_probe Use devm_of_iomap() instead of of_iomap() to automatically handle the unused ioremap region. If any error occurs, regions allocated by kzalloc() will leak, but using devm_kzalloc() instead will automatically free the memory using devm_kfree().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v6x-c7xx-hw9f

7 месяцев назад

CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names

EPSS: Низкий
github логотип

GHSA-4v6x-453r-gmgq

2 месяца назад

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v6w-xpmh-gfgp

около 1 года назад

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

EPSS: Низкий
github логотип

GHSA-4v6w-vxg7-j28q

около 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-4v6w-6mf9-c2fr

больше 4 лет назад

Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4v6v-34r8-27m4

почти 2 года назад

IrfanView WBZ plugin WB1 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WB1 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22718.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v6r-qc3q-5hfm

больше 4 лет назад

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v6r-gxrx-pjw8

больше 4 лет назад

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-4v6r-g9pp-vmw9

около 3 лет назад

BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4v6q-v4j6-96rv

4 месяца назад

The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4v6q-gjm6-6vv4

больше 4 лет назад

ChakraCore RCE via Out-of-bounds write

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v6q-55j7-hcxg

около 2 лет назад

An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4v6q-2pvx-f85v

6 месяцев назад

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4v6p-qrqr-fp96

больше 2 лет назад

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the display function. This makes it possible for authenticated attackers, with contributor access and higher, to include and execute arbitrary php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4v6p-cxf9-98rf

больше 4 лет назад

Allocation of Resources Without Limits or Throttling in metadata-extractor

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v6p-4fvv-f67q

почти 4 года назад

Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v6j-72ww-qv59

9 месяцев назад

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v6j-536v-64fw

больше 1 года назад

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v6j-4h27-f953

больше 4 лет назад

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v6x-wq6p-585m

In the Linux kernel, the following vulnerability has been resolved: clk: imx: clk-imx8mn: fix memory leak in imx8mn_clocks_probe Use devm_of_iomap() instead of of_iomap() to automatically handle the unused ioremap region. If any error occurs, regions allocated by kzalloc() will leak, but using devm_kzalloc() instead will automatically free the memory using devm_kfree().

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4v6x-c7xx-hw9f

CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names

0%
Низкий
7 месяцев назад
github логотип
GHSA-4v6x-453r-gmgq

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4v6w-xpmh-gfgp

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

0%
Низкий
около 1 года назад
github логотип
GHSA-4v6w-vxg7-j28q

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

CVSS3: 8.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-4v6w-6mf9-c2fr

Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.

CVSS3: 9.8
15%
Средний
больше 4 лет назад
github логотип
GHSA-4v6v-34r8-27m4

IrfanView WBZ plugin WB1 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WB1 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22718.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-4v6r-qc3q-5hfm

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v6r-gxrx-pjw8

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

CVSS3: 5.5
12%
Средний
больше 4 лет назад
github логотип
GHSA-4v6r-g9pp-vmw9

BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

CVSS3: 9
1%
Низкий
около 3 лет назад
github логотип
GHSA-4v6q-v4j6-96rv

The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-4v6q-gjm6-6vv4

ChakraCore RCE via Out-of-bounds write

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v6q-55j7-hcxg

An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-4v6q-2pvx-f85v

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-4v6p-qrqr-fp96

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the display function. This makes it possible for authenticated attackers, with contributor access and higher, to include and execute arbitrary php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4v6p-cxf9-98rf

Allocation of Resources Without Limits or Throttling in metadata-extractor

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v6p-4fvv-f67q

Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-4v6j-72ww-qv59

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVSS3: 8.8
3%
Низкий
9 месяцев назад
github логотип
GHSA-4v6j-536v-64fw

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v6j-4h27-f953

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу