Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4rh7-jwg9-m28m

6 месяцев назад

openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage

EPSS: Низкий
github логотип

GHSA-4rh7-4h26-629j

больше 4 лет назад

The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1.

EPSS: Низкий
github логотип

GHSA-4rh7-2jj4-cgm5

больше 4 лет назад

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.

EPSS: Низкий
github логотип

GHSA-4rh6-rgjc-525r

больше 4 лет назад

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.

EPSS: Низкий
github логотип

GHSA-4rh6-83qm-cfmj

около 2 лет назад

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

EPSS: Низкий
github логотип

GHSA-4rh6-7h5w-cvjv

больше 4 лет назад

NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.

EPSS: Низкий
github логотип

GHSA-4rh5-mvp3-pqm7

около 2 лет назад

The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rh4-3933-r7hw

почти 2 года назад

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rh4-3695-hmxr

2 месяца назад

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4rh3-rmh3-hv6h

3 месяца назад

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4rgx-hjqw-p9f3

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: ensure the fw_info is not null before using it This resolves the dereference null return value warning reported by Coverity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rgw-hq9r-qp9v

больше 4 лет назад

The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.

EPSS: Низкий
github логотип

GHSA-4rgw-cq58-c8v4

больше 4 лет назад

admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rgv-cpg8-f3hr

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix race of truncate and swap entry split The helper for shmem swap freeing is not handling the order of swap entries correctly. It uses xa_cmpxchg_irq to erase the swap entry, but it gets the entry order before that using xa_get_order without lock protection, and it may get an outdated order value if the entry is split or changed in other ways after the xa_get_order and before the xa_cmpxchg_irq. And besides, the order could grow and be larger than expected, and cause truncation to erase data beyond the end border. For example, if the target entry and following entries are swapped in or freed, then a large folio was added in place and swapped out, using the same entry, the xa_cmpxchg_irq will still succeed, it's very unlikely to happen though. To fix that, open code the Xarray cmpxchg and put the order retrieval and value checking in the same critical section. Also, ensure the order won't exc...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4rgr-wmhw-58fg

4 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rgr-v5ff-6hgp

около 3 лет назад

In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rgr-65fh-c67c

больше 4 лет назад

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rgq-6973-6xxh

почти 2 года назад

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rgq-66fx-5hx2

больше 4 лет назад

The cookbible (aka net.bookjam.cookbible) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4rgq-38mh-9xqg

4 месяца назад

Admidio PKCS#12 private key export action lacks CSRF protection

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rh7-jwg9-m28m

openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage

6 месяцев назад
github логотип
GHSA-4rh7-4h26-629j

The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rh7-2jj4-cgm5

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rh6-rgjc-525r

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rh6-83qm-cfmj

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

0%
Низкий
около 2 лет назад
github логотип
GHSA-4rh6-7h5w-cvjv

NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4rh5-mvp3-pqm7

The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4rh4-3933-r7hw

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-4rh4-3695-hmxr

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад
github логотип
GHSA-4rh3-rmh3-hv6h

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVSS3: 9.8
20%
Средний
3 месяца назад
github логотип
GHSA-4rgx-hjqw-p9f3

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: ensure the fw_info is not null before using it This resolves the dereference null return value warning reported by Coverity.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4rgw-hq9r-qp9v

The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4rgw-cq58-c8v4

admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rgv-cpg8-f3hr

In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix race of truncate and swap entry split The helper for shmem swap freeing is not handling the order of swap entries correctly. It uses xa_cmpxchg_irq to erase the swap entry, but it gets the entry order before that using xa_get_order without lock protection, and it may get an outdated order value if the entry is split or changed in other ways after the xa_get_order and before the xa_cmpxchg_irq. And besides, the order could grow and be larger than expected, and cause truncation to erase data beyond the end border. For example, if the target entry and following entries are swapped in or freed, then a large folio was added in place and swapped out, using the same entry, the xa_cmpxchg_irq will still succeed, it's very unlikely to happen though. To fix that, open code the Xarray cmpxchg and put the order retrieval and value checking in the same critical section. Also, ensure the order won't exc...

CVSS3: 4.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-4rgr-wmhw-58fg

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4rgr-v5ff-6hgp

In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

CVSS3: 4.3
2%
Низкий
около 3 лет назад
github логотип
GHSA-4rgr-65fh-c67c

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4rgq-6973-6xxh

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4rgq-66fx-5hx2

The cookbible (aka net.bookjam.cookbible) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rgq-38mh-9xqg

Admidio PKCS#12 private key export action lacks CSRF protection

CVSS3: 4.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу