Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4qhh-6cpg-6632

больше 4 лет назад

The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4qhg-xgv5-f524

больше 1 года назад

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-4qhg-7v4f-qrrf

3 месяца назад

Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qhc-v8r6-8vwm

почти 3 года назад

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qhc-6r4v-5wmg

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Check frwr_wp_create() during connect frwr_wp_create() creates the singleton Memory Region used to encode padding for Write chunks whose payload length is not XDR-aligned. Its failure paths return a negative errno and leave ep->re_write_pad_mr set to NULL. rpcrdma_xprt_connect() currently ignores that return value. If frwr_wp_create() fails after the rest of the connection setup succeeds, xprt_rdma_connect_worker() treats the connection attempt as successful and sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned receive page length reaches rpcrdma_encode_write_list(), passes the NULL write-pad MR to encode_rdma_segment(), and dereferences it. This is locally triggerable on an NFS/RDMA client after a connect or reconnect hits a local MR allocation, DMA-map, MR-map, or post-send failure; a remote peer alone cannot force the local MR setup failure. Check the return value and fail the co...

EPSS: Низкий
github логотип

GHSA-4qh7-cr89-jx92

почти 3 года назад

An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4qh6-wmrm-mp28

около 4 лет назад

The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4qh6-qmh4-rp5h

около 2 месяцев назад

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qh6-m8h4-cff3

2 месяца назад

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4qh6-5ppq-rf93

около 4 лет назад

Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4qh5-p5x2-2wcj

больше 4 лет назад

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qh5-35r2-7932

больше 4 лет назад

Scripting Engine Memory Corruption Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4qh4-93x2-h5wr

8 месяцев назад

The Change WP URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'change-wp-url' page. This makes it possible for unauthenticated attackers to change the WP Login URL via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4qh3-vw22-fpq6

около 3 лет назад

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4qh3-jr4m-5c24

больше 4 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3806.

EPSS: Низкий
github логотип

GHSA-4qh3-gf24-f7qr

почти 4 года назад

Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4qh3-42m3-8rfh

больше 4 лет назад

KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.

EPSS: Низкий
github логотип

GHSA-4qh2-wppx-cq27

больше 4 лет назад

An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie.

EPSS: Высокий
github логотип

GHSA-4qh2-fhjf-7m6f

11 месяцев назад

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of the argument editBrandName results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4qgx-xw7p-6ggp

больше 4 лет назад

A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qhh-6cpg-6632

The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qhg-xgv5-f524

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-4qhg-7v4f-qrrf

Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4qhc-v8r6-8vwm

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4qhc-6r4v-5wmg

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Check frwr_wp_create() during connect frwr_wp_create() creates the singleton Memory Region used to encode padding for Write chunks whose payload length is not XDR-aligned. Its failure paths return a negative errno and leave ep->re_write_pad_mr set to NULL. rpcrdma_xprt_connect() currently ignores that return value. If frwr_wp_create() fails after the rest of the connection setup succeeds, xprt_rdma_connect_worker() treats the connection attempt as successful and sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned receive page length reaches rpcrdma_encode_write_list(), passes the NULL write-pad MR to encode_rdma_segment(), and dereferences it. This is locally triggerable on an NFS/RDMA client after a connect or reconnect hits a local MR allocation, DMA-map, MR-map, or post-send failure; a remote peer alone cannot force the local MR setup failure. Check the return value and fail the co...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-4qh7-cr89-jx92

An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server service account could escalate themselves to a super-user.

CVSS3: 5.9
1%
Низкий
почти 3 года назад
github логотип
GHSA-4qh6-wmrm-mp28

The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site scripting

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-4qh6-qmh4-rp5h

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4qh6-m8h4-cff3

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.

CVSS3: 7.2
1%
Низкий
2 месяца назад
github логотип
GHSA-4qh6-5ppq-rf93

Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-4qh5-p5x2-2wcj

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.

CVSS3: 6.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4qh5-35r2-7932

Scripting Engine Memory Corruption Vulnerability

CVSS3: 7.5
23%
Средний
больше 4 лет назад
github логотип
GHSA-4qh4-93x2-h5wr

The Change WP URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'change-wp-url' page. This makes it possible for unauthenticated attackers to change the WP Login URL via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-4qh3-vw22-fpq6

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4qh3-jr4m-5c24

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3806.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qh3-gf24-f7qr

Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4qh3-42m3-8rfh

KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4qh2-wppx-cq27

An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie.

82%
Высокий
больше 4 лет назад
github логотип
GHSA-4qh2-fhjf-7m6f

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of the argument editBrandName results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-4qgx-xw7p-6ggp

A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 6.6
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу