Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4ppq-2435-3w6v

больше 4 лет назад

totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4ppp-pw82-66fj

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS is selected, cpu_max_bits_warn() generates a runtime warning similar as below while we show /proc/cpuinfo. Fix this by using nr_cpu_ids (the runtime limit) instead of NR_CPUS to iterate CPUs. [ 3.052463] ------------[ cut here ]------------ [ 3.059679] WARNING: CPU: 3 PID: 1 at include/linux/cpumask.h:108 show_cpuinfo+0x5e8/0x5f0 [ 3.070072] Modules linked in: efivarfs autofs4 [ 3.076257] CPU: 0 PID: 1 Comm: systemd Not tainted 5.19-rc5+ #1052 [ 3.084034] Hardware name: Loongson Loongson-3A5000-7A1000-1w-V0.1-CRB/Loongson-LS3A5000-7A1000-1w-EVB-V1.21, BIOS Loongson-UDK2018-V2.0.04082-beta7 04/27 [ 3.099465] Stack : 9000000100157b08 9000000000f18530 9000000000cf846c 9000000100154000 [ 3.109127] 9000000100157a50 0000000000000000 9000000100157a58 9000000000ef7430 [ ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4ppp-pmgp-3xch

почти 2 года назад

The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4ppp-gpcr-7qf6

больше 6 лет назад

HTTP Request Smuggling: Content-Length Sent Twice in Waitress

EPSS: Низкий
github логотип

GHSA-4ppm-v6x5-6j4c

больше 4 лет назад

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the GroupId and ConnPoolName parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4ppm-32h4-4764

больше 4 лет назад

An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.

EPSS: Низкий
github логотип

GHSA-4ppj-757r-h8qc

почти 3 года назад

Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

CVSS3: 9.6
EPSS: Средний
github логотип

GHSA-4ppj-6chv-5pgc

6 месяцев назад

Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4ppj-4p4v-jf4p

больше 4 лет назад

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4ppg-c52g-rpx2

больше 3 лет назад

Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4ppg-2mx6-fqx9

больше 4 лет назад

Moodle allows attackers to bypass intended login restrictions

EPSS: Низкий
github логотип

GHSA-4ppf-rv9c-6qjq

больше 3 лет назад

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4ppc-mf9q-3j92

23 дня назад

In the Linux kernel, the following vulnerability has been resolved: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition In atmci_probe, &host->bh_work is bound with atmci_work_func, and atmci_interrupt, atmci_timeout_timer and atmci_dma_complete can all queue this work on system_bh_wq. If we remove the module, atmci_remove makes cleanup and the memory allocated for host with devm_kzalloc() is released after the remove callback returns, while the work mentioned above may still be pending or running. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | atmci_interrupt | queue_work(system_bh_wq, | &host->bh_work) atmci_remove | atmci_cleanup_slot(...) | atmci_writel(host, ATMCI_IDR, ~0UL) | timer_delete_sync(&...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pp9-pcmj-qjgw

больше 4 лет назад

Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pp8-9mjg-pq9p

больше 4 лет назад

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. A local user may be able to read kernel memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pp7-p29p-wcpw

больше 4 лет назад

Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4pp7-562r-m34f

больше 4 лет назад

Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pp6-qf76-c236

больше 4 лет назад

interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4pp6-m86c-j4gj

больше 4 лет назад

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

EPSS: Низкий
github логотип

GHSA-4pp6-fg3p-gpgv

около 1 года назад

Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paytiko for WooCommerce: from n/a through 1.3.14.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4ppq-2435-3w6v

totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4ppp-pw82-66fj

In the Linux kernel, the following vulnerability has been resolved: LoongArch: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS is selected, cpu_max_bits_warn() generates a runtime warning similar as below while we show /proc/cpuinfo. Fix this by using nr_cpu_ids (the runtime limit) instead of NR_CPUS to iterate CPUs. [ 3.052463] ------------[ cut here ]------------ [ 3.059679] WARNING: CPU: 3 PID: 1 at include/linux/cpumask.h:108 show_cpuinfo+0x5e8/0x5f0 [ 3.070072] Modules linked in: efivarfs autofs4 [ 3.076257] CPU: 0 PID: 1 Comm: systemd Not tainted 5.19-rc5+ #1052 [ 3.084034] Hardware name: Loongson Loongson-3A5000-7A1000-1w-V0.1-CRB/Loongson-LS3A5000-7A1000-1w-EVB-V1.21, BIOS Loongson-UDK2018-V2.0.04082-beta7 04/27 [ 3.099465] Stack : 9000000100157b08 9000000000f18530 9000000000cf846c 9000000100154000 [ 3.109127] 9000000100157a50 0000000000000000 9000000100157a58 9000000000ef7430 [ ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4ppp-pmgp-3xch

The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-4ppp-gpcr-7qf6

HTTP Request Smuggling: Content-Length Sent Twice in Waitress

2%
Низкий
больше 6 лет назад
github логотип
GHSA-4ppm-v6x5-6j4c

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the GroupId and ConnPoolName parameters.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ppm-32h4-4764

An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4ppj-757r-h8qc

Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

CVSS3: 9.6
49%
Средний
почти 3 года назад
github логотип
GHSA-4ppj-6chv-5pgc

Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values

CVSS3: 7.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-4ppj-4p4v-jf4p

OpenStack Keystone Denial of Service vulnerability via a large HTTP request

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4ppg-c52g-rpx2

Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4ppg-2mx6-fqx9

Moodle allows attackers to bypass intended login restrictions

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4ppf-rv9c-6qjq

A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4ppc-mf9q-3j92

In the Linux kernel, the following vulnerability has been resolved: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition In atmci_probe, &host->bh_work is bound with atmci_work_func, and atmci_interrupt, atmci_timeout_timer and atmci_dma_complete can all queue this work on system_bh_wq. If we remove the module, atmci_remove makes cleanup and the memory allocated for host with devm_kzalloc() is released after the remove callback returns, while the work mentioned above may still be pending or running. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | atmci_interrupt | queue_work(system_bh_wq, | &host->bh_work) atmci_remove | atmci_cleanup_slot(...) | atmci_writel(host, ATMCI_IDR, ~0UL) | timer_delete_sync(&...

CVSS3: 7.8
0%
Низкий
23 дня назад
github логотип
GHSA-4pp9-pcmj-qjgw

Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp8-9mjg-pq9p

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. A local user may be able to read kernel memory.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp7-p29p-wcpw

Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp7-562r-m34f

Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp6-qf76-c236

interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.

CVSS3: 8.8
32%
Средний
больше 4 лет назад
github логотип
GHSA-4pp6-m86c-j4gj

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp6-fg3p-gpgv

Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paytiko for WooCommerce: from n/a through 1.3.14.

CVSS3: 6.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу