Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4fvf-46cq-3pw2

20 дней назад

Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4fvc-w7pw-48q6

больше 1 года назад

Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4fvc-h857-qw9g

больше 4 лет назад

This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.

EPSS: Низкий
github логотип

GHSA-4fvc-83fv-pgq6

больше 4 лет назад

Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4fv9-v5wm-569w

больше 1 года назад

The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4fv8-w65m-3932

больше 3 лет назад

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-4fv8-q23c-jh2m

больше 4 лет назад

Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4fv8-h7r9-m88g

больше 4 лет назад

Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtLoadKey, (4) NtOpenKey, (5) NtQueryValueKey, (6) NtSetValueKey, and (7) NtUnloadKey.

EPSS: Низкий
github логотип

GHSA-4fv8-fm6j-xc9r

больше 2 лет назад

An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4fv7-37f3-c5j6

больше 4 лет назад

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05442022.

EPSS: Низкий
github логотип

GHSA-4fv6-38m4-qgqj

больше 4 лет назад

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4fv6-2265-mqxm

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fv5-wjqm-7f2r

почти 3 года назад

Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4fv5-g6r3-cjxh

больше 4 лет назад

Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175.

EPSS: Низкий
github логотип

GHSA-4fv5-487x-c795

больше 2 лет назад

NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4fv4-gh87-p496

больше 4 лет назад

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4fv4-f7m5-w88w

больше 4 лет назад

The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4fv4-cq5v-x45m

больше 4 лет назад

Improper Authentication in Apache MyFaces

EPSS: Низкий
github логотип

GHSA-4fv4-55mw-p3v4

больше 4 лет назад

modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.

EPSS: Низкий
github логотип

GHSA-4fv3-v4jw-2q2p

больше 1 года назад

A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4fvf-46cq-3pw2

Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
20 дней назад
github логотип
GHSA-4fvc-w7pw-48q6

Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4fvc-h857-qw9g

This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fvc-83fv-pgq6

Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv9-v5wm-569w

The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4fv8-w65m-3932

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

CVSS3: 4.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4fv8-q23c-jh2m

Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv8-h7r9-m88g

Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtLoadKey, (4) NtOpenKey, (5) NtQueryValueKey, (6) NtSetValueKey, and (7) NtUnloadKey.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv8-fm6j-xc9r

An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4fv7-37f3-c5j6

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05442022.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv6-38m4-qgqj

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv6-2265-mqxm

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv5-wjqm-7f2r

Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-4fv5-g6r3-cjxh

Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv5-487x-c795

NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4fv4-gh87-p496

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

CVSS3: 9.8
13%
Средний
больше 4 лет назад
github логотип
GHSA-4fv4-f7m5-w88w

The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv4-cq5v-x45m

Improper Authentication in Apache MyFaces

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv4-55mw-p3v4

modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fv3-v4jw-2q2p

A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

CVSS3: 9.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу