Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4jx6-7475-4qwh

больше 4 лет назад

SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.

EPSS: Низкий
github логотип

GHSA-4jx6-488q-wrq2

больше 4 лет назад

In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4jx5-7652-w3ch

около 1 месяца назад

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4jx4-q2fr-hj53

почти 5 лет назад

There is a Logic bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to obtain certain device information.

EPSS: Низкий
github логотип

GHSA-4jx4-gmpg-qw4c

больше 4 лет назад

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

EPSS: Низкий
github логотип

GHSA-4jx4-8xx2-8r3h

больше 4 лет назад

Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Server). Supported versions that are affected are 8.55, 8.56 and 8.57. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-4jx3-fh7f-pxhw

17 дней назад

In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate (fault_blocked = true) and releases it at the out:/error: labels. But when a writeback flush is also needed, a write_inode_now() failure returns directly and leaks the lock, so any later fault or truncate on the file stalls on the stale rwsem. For example, truncate(2) on a setuid file reaches fuse_do_setattr() with both ATTR_SIZE and ATTR_MODE set: truncate(2) └─ do_truncate() ├─ dentry_needs_remove_privs() # S_ISUID └─ notify_change() # KILL_SUID -> ATTR_MODE └─ fuse_setattr() # no killpriv: │ # ia_valid |= ATTR_MODE └─ fuse_do_setattr() ├─ filemap_invalidate_lock() # IS_DAX && is_truncate └─ write_inode_...

EPSS: Низкий
github логотип

GHSA-4jx3-7qrh-4fpw

около 1 года назад

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccountry' parameter in/country.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jx2-hvqw-93j9

больше 3 лет назад

dd-plist XML External Entitly vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jwx-pg4r-8w69

больше 1 года назад

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4jwx-78vx-gm6g

почти 5 лет назад

Cross-Site Request Forgery in kimai2

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4jwx-4mhh-7vcg

больше 4 лет назад

The server component in Marathon Aleph One before 0.17.1 and 2006-12-17 allows remote attackers to cause a denial of service (application crash) via unspecified vectors related to "gathering net games."

EPSS: Низкий
github логотип

GHSA-4jww-mhxc-7mmm

больше 4 лет назад

Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, which is not properly handled by includes/head.php; and (2) read arbitrary files via ".." sequences in the file parameter in an add_dl action to adm_index.php, as demonstrated by reading connect.php.

EPSS: Низкий
github логотип

GHSA-4jwv-x3w6-42jv

больше 4 лет назад

Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.

EPSS: Низкий
github логотип

GHSA-4jwv-8x37-cg8x

больше 4 лет назад

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

EPSS: Низкий
github логотип

GHSA-4jwr-q2v5-wg73

больше 4 лет назад

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.

EPSS: Низкий
github логотип

GHSA-4jwr-58v2-3w35

больше 4 лет назад

An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4jwq-xq2h-426q

больше 4 лет назад

The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

EPSS: Низкий
github логотип

GHSA-4jwq-qx73-v7q4

больше 4 лет назад

SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jwq-572w-4388

больше 2 лет назад

Memory over-allocation in evm crate

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jx6-7475-4qwh

SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jx6-488q-wrq2

In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jx5-7652-w3ch

An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4jx4-q2fr-hj53

There is a Logic bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to obtain certain device information.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-4jx4-gmpg-qw4c

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4jx4-8xx2-8r3h

Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Server). Supported versions that are affected are 8.55, 8.56 and 8.57. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jx3-fh7f-pxhw

In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate (fault_blocked = true) and releases it at the out:/error: labels. But when a writeback flush is also needed, a write_inode_now() failure returns directly and leaks the lock, so any later fault or truncate on the file stalls on the stale rwsem. For example, truncate(2) on a setuid file reaches fuse_do_setattr() with both ATTR_SIZE and ATTR_MODE set: truncate(2) └─ do_truncate() ├─ dentry_needs_remove_privs() # S_ISUID └─ notify_change() # KILL_SUID -> ATTR_MODE └─ fuse_setattr() # no killpriv: │ # ia_valid |= ATTR_MODE └─ fuse_do_setattr() ├─ filemap_invalidate_lock() # IS_DAX && is_truncate └─ write_inode_...

0%
Низкий
17 дней назад
github логотип
GHSA-4jx3-7qrh-4fpw

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccountry' parameter in/country.php.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-4jx2-hvqw-93j9

dd-plist XML External Entitly vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4jwx-pg4r-8w69

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4jwx-78vx-gm6g

Cross-Site Request Forgery in kimai2

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4jwx-4mhh-7vcg

The server component in Marathon Aleph One before 0.17.1 and 2006-12-17 allows remote attackers to cause a denial of service (application crash) via unspecified vectors related to "gathering net games."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jww-mhxc-7mmm

Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, which is not properly handled by includes/head.php; and (2) read arbitrary files via ".." sequences in the file parameter in an add_dl action to adm_index.php, as demonstrated by reading connect.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwv-x3w6-42jv

Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwv-8x37-cg8x

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwr-q2v5-wg73

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwr-58v2-3w35

An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwq-xq2h-426q

The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwq-qx73-v7q4

SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jwq-572w-4388

Memory over-allocation in evm crate

CVSS3: 6.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу