Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 342 247

Количество 342 247

github логотип

GHSA-2ww7-hqm8-2qhf

4 месяца назад

An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.

EPSS: Низкий
github логотип

GHSA-2ww6-hf35-mfjm

4 месяца назад

Capsule Namespace Hijacking via subresource

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-2ww6-gh4g-5q93

около 4 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2ww6-g8rg-vh7g

больше 4 лет назад

Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.

EPSS: Низкий
github логотип

GHSA-2ww6-c8hm-gqw6

7 месяцев назад

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.

EPSS: Низкий
github логотип

GHSA-2ww6-868g-2c56

6 месяцев назад

OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2ww6-2gwx-v942

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2ww5-g3p9-xg2r

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.

EPSS: Низкий
github логотип

GHSA-2ww5-c4rg-76jh

больше 1 года назад

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2ww3-fxvq-293j

почти 5 лет назад

NLTK Vulnerable to REDoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ww3-72rp-wpp4

7 месяцев назад

Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2ww2-4h6w-cc6c

около 4 лет назад

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wvx-75wc-hc4w

больше 4 лет назад

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wvw-h8hc-x343

больше 4 лет назад

Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2wvw-246g-ffw7

больше 4 лет назад

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

EPSS: Низкий
github логотип

GHSA-2wvv-vggf-ggr9

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2wvv-pxv7-cgf7

больше 3 лет назад

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2wvv-phhw-qvmc

больше 3 лет назад

Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wvv-6r6q-wwcj

больше 4 лет назад

Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wvv-4p4q-7mq5

больше 1 года назад

Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2ww7-hqm8-2qhf

An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.

1%
Низкий
4 месяца назад
github логотип
GHSA-2ww6-hf35-mfjm

Capsule Namespace Hijacking via subresource

CVSS3: 3.9
0%
Низкий
4 месяца назад
github логотип
GHSA-2ww6-gh4g-5q93

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2ww6-g8rg-vh7g

Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2ww6-c8hm-gqw6

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.

0%
Низкий
7 месяцев назад
github логотип
GHSA-2ww6-868g-2c56

OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation

CVSS3: 4.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-2ww6-2gwx-v942

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ww5-g3p9-xg2r

Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2ww5-c4rg-76jh

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ww3-fxvq-293j

NLTK Vulnerable to REDoS

CVSS3: 7.5
2%
Низкий
почти 5 лет назад
github логотип
GHSA-2ww3-72rp-wpp4

Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK

CVSS3: 9.9
2%
Низкий
7 месяцев назад
github логотип
GHSA-2ww2-4h6w-cc6c

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wvx-75wc-hc4w

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2wvw-h8hc-x343

Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wvw-246g-ffw7

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2wvv-vggf-ggr9

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.

CVSS3: 8.8
19%
Средний
больше 4 лет назад
github логотип
GHSA-2wvv-pxv7-cgf7

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wvv-phhw-qvmc

Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wvv-6r6q-wwcj

Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2wvv-4p4q-7mq5

Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5.

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу