Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pqq-wq2g-6rcm

около 4 лет назад

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pqq-whjc-554c

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work. process_pending_rx() takes the same mutex, so teardown can deadlock against the worker it is flushing. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the l2cap_conn_ready() -> queue_work(..., &conn->pending_rx_work) submit path, the l2cap_conn_del() -> cancel_work_sync(&conn->pending_rx_work) teardown path, and the process_pending_rx() -> mutex_lock(&conn->lock) worker edge. Lockdep WARNING: possible circular locking dependency detected process_pending_rx+0x21/0x2a [vuln_msv] l2cap_conn_del.constprop.0+0x3f/0x4e [vuln_msv] *** DEADLOCK *** Cancel pending_rx_work before taking conn->lock, matching the existing lock-before-drain ordering used for the two delayed works in the...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pqq-jprg-84vh

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4pqq-66mf-9h95

больше 4 лет назад

In TrustZone a buffer overflow vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pqp-h39m-gcw4

3 дня назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Previously fsg_num_buffers_validate() was removed as it was not necessary due to Kconfig setting the limits for n from 2 to 256 with default as 2. However, setting the page content in such a way that kstrtou8() reflects n value as either 0 or 1 bypasses these restrictions leading to a null pointer dereference if n is 0. Fix this by adding a check for n < 2 and returning -EINVAL if n is either 0 or 1 consistent with Kconfig logic.

EPSS: Низкий
github логотип

GHSA-4pqp-9qr3-h8vg

больше 4 лет назад

Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17064, CVE-2020-17065, CVE-2020-17066.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pqp-69m3-f8pp

больше 3 лет назад

NotrinosERP vulnerable to SQL Injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pqp-3cv2-mm87

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base register of the device and using it instead of the pointer dereference.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pqm-j46f-795x

3 месяца назад

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pqj-5gg5-44jh

больше 4 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider &#39;\0&#39; characters, as demonstrated by a good.example.com\x00evil.example.com attack.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4pqh-v35r-m9w2

больше 4 лет назад

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4pqh-gmhf-2qvf

больше 1 года назад

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – It might be difficult for an attacker to identify the file structure of the <redated> directory, and then modify the backup to add a new CGI script in the correct directory. Furthermore, the attacker will need an account to restore the settings backup, or convince a user with such access to upload a modified backup file. Impact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services. CVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentic...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pqh-7xgc-j83m

7 месяцев назад

Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-4pqh-76jg-2w88

около 4 лет назад

In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pqh-3f6p-63c5

4 месяца назад

Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including establishing a reverse shell. This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545

EPSS: Низкий
github логотип

GHSA-4pqg-hr8r-h5cw

почти 3 года назад

MediaWiki malicious XML upload leads to privilege escalation

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4pqf-xf6q-8mf6

11 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt-luxa-addons allows Path Traversal.This issue affects PT Luxa Addons: from n/a through <= 1.2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4pqf-x898-75w7

больше 1 года назад

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4pqf-rv7c-5646

больше 4 лет назад

Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.

EPSS: Средний
github логотип

GHSA-4pqf-22vq-mvr9

больше 4 лет назад

Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pqq-wq2g-6rcm

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-4pqq-whjc-554c

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work. process_pending_rx() takes the same mutex, so teardown can deadlock against the worker it is flushing. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the l2cap_conn_ready() -> queue_work(..., &conn->pending_rx_work) submit path, the l2cap_conn_del() -> cancel_work_sync(&conn->pending_rx_work) teardown path, and the process_pending_rx() -> mutex_lock(&conn->lock) worker edge. Lockdep WARNING: possible circular locking dependency detected process_pending_rx+0x21/0x2a [vuln_msv] l2cap_conn_del.constprop.0+0x3f/0x4e [vuln_msv] *** DEADLOCK *** Cancel pending_rx_work before taking conn->lock, matching the existing lock-before-drain ordering used for the two delayed works in the...

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-4pqq-jprg-84vh

Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pqq-66mf-9h95

In TrustZone a buffer overflow vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pqp-h39m-gcw4

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Previously fsg_num_buffers_validate() was removed as it was not necessary due to Kconfig setting the limits for n from 2 to 256 with default as 2. However, setting the page content in such a way that kstrtou8() reflects n value as either 0 or 1 bypasses these restrictions leading to a null pointer dereference if n is 0. Fix this by adding a check for n < 2 and returning -EINVAL if n is either 0 or 1 consistent with Kconfig logic.

3 дня назад
github логотип
GHSA-4pqp-9qr3-h8vg

Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17064, CVE-2020-17065, CVE-2020-17066.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4pqp-69m3-f8pp

NotrinosERP vulnerable to SQL Injection

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-4pqp-3cv2-mm87

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base register of the device and using it instead of the pointer dereference.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4pqm-j46f-795x

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-4pqj-5gg5-44jh

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider &#39;\0&#39; characters, as demonstrated by a good.example.com\x00evil.example.com attack.

CVSS3: 9.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4pqh-v35r-m9w2

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pqh-gmhf-2qvf

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701. Likelihood: Moderate – It might be difficult for an attacker to identify the file structure of the <redated> directory, and then modify the backup to add a new CGI script in the correct directory. Furthermore, the attacker will need an account to restore the settings backup, or convince a user with such access to upload a modified backup file. Impact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services. CVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentic...

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4pqh-7xgc-j83m

Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4
0%
Низкий
7 месяцев назад
github логотип
GHSA-4pqh-76jg-2w88

In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-4pqh-3f6p-63c5

Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including establishing a reverse shell. This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545

1%
Низкий
4 месяца назад
github логотип
GHSA-4pqg-hr8r-h5cw

MediaWiki malicious XML upload leads to privilege escalation

CVSS3: 7.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-4pqf-xf6q-8mf6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt-luxa-addons allows Path Traversal.This issue affects PT Luxa Addons: from n/a through <= 1.2.2.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-4pqf-x898-75w7

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4pqf-rv7c-5646

Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.

10%
Средний
больше 4 лет назад
github логотип
GHSA-4pqf-22vq-mvr9

Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method.

8%
Низкий
больше 4 лет назад

Уязвимостей на страницу