Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4frp-337g-3gxw

больше 4 лет назад

The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4frm-gc48-jwjx

около 3 лет назад

Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-4frm-cwqq-w26g

больше 3 лет назад

SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4frh-rw8g-vq9h

больше 4 лет назад

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

EPSS: Низкий
github логотип

GHSA-4frh-9v5h-wqj6

19 дней назад

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: avoid deadlock when canceling IRQ affinity notifier Unregistering IRQ affinity notifiers waits for the callback synchronously. bnxt takes the netdev instance lock in the notifier (to restart the queue) and cancels the work under the same lock. This may obviously deadlock. Move the restart to the async service task. The queue restart isn't super time sensitive. Store the new TPH tag, schedule the task. Safely canceling the service task is already ironed out. In bnxt_request_irq() the order of registering notifier, affinity and initial TPH programming has to be inverted. I think it was racy previously since user may trigger an update as soon as notifier is installed. There's a small known gap - if pcie_tph_get_cpu_st() fails at init and the target tag is 0 we may miss programming the entry. This does not seem worth fixing, the code has skip-on-failure all over the place, anyway.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4frg-rpx6-96qh

больше 4 лет назад

Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4frf-q9p9-gg69

больше 4 лет назад

SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4frf-ph8g-p825

больше 1 года назад

The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fr9-73w7-j6w3

больше 4 лет назад

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fr9-3x69-36wv

12 месяцев назад

Flowise vulnerable to XSS

EPSS: Низкий
github логотип

GHSA-4fr8-gmqr-2fwp

около 3 лет назад

Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4fr8-c92c-7m76

больше 3 лет назад

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fr7-9qv2-r87x

больше 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4fr6-x37h-wjwr

больше 2 лет назад

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser. 

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4fr6-rgq9-hcp4

больше 4 лет назад

P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with an empty body and a Content-Length greater than 0.

EPSS: Низкий
github логотип

GHSA-4fr6-66x2-m26v

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4fr5-x8r3-mvxg

больше 1 года назад

Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4fr5-6ccq-75w2

больше 2 лет назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4fr4-555r-hrvp

больше 4 лет назад

Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins.

EPSS: Низкий
github логотип

GHSA-4fr3-j6rq-cggr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4frp-337g-3gxw

The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4frm-gc48-jwjx

Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.

CVSS3: 6.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-4frm-cwqq-w26g

SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4frh-rw8g-vq9h

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4frh-9v5h-wqj6

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: avoid deadlock when canceling IRQ affinity notifier Unregistering IRQ affinity notifiers waits for the callback synchronously. bnxt takes the netdev instance lock in the notifier (to restart the queue) and cancels the work under the same lock. This may obviously deadlock. Move the restart to the async service task. The queue restart isn't super time sensitive. Store the new TPH tag, schedule the task. Safely canceling the service task is already ironed out. In bnxt_request_irq() the order of registering notifier, affinity and initial TPH programming has to be inverted. I think it was racy previously since user may trigger an update as soon as notifier is installed. There's a small known gap - if pcie_tph_get_cpu_st() fails at init and the target tag is 0 we may miss programming the entry. This does not seem worth fixing, the code has skip-on-failure all over the place, anyway.

CVSS3: 7.5
0%
Низкий
19 дней назад
github логотип
GHSA-4frg-rpx6-96qh

Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4frf-q9p9-gg69

SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4frf-ph8g-p825

The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4fr9-73w7-j6w3

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fr9-3x69-36wv

Flowise vulnerable to XSS

12 месяцев назад
github логотип
GHSA-4fr8-gmqr-2fwp

Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

CVSS3: 9.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-4fr8-c92c-7m76

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4fr7-9qv2-r87x

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4fr6-x37h-wjwr

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser. 

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4fr6-rgq9-hcp4

P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with an empty body and a Content-Length greater than 0.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fr6-66x2-m26v

Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4fr5-x8r3-mvxg

Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4fr5-6ccq-75w2

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4fr4-555r-hrvp

Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fr3-j6rq-cggr

Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу