Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-482g-x733-43f8

около 2 лет назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-482g-pf4j-cwfc

больше 4 лет назад

TrueStack Direct Connect 1.4.7 has Incorrect Access Control.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-482g-8988-9gwh

больше 4 лет назад

The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.

EPSS: Низкий
github логотип

GHSA-482f-f22h-3jvq

около 1 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-482f-7ffv-p77p

больше 4 лет назад

Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end Category Editor system, and (4) "Pages that display task status, email addresses, URL, customer, and project information."

EPSS: Низкий
github логотип

GHSA-4829-xxxr-9f4f

около 1 года назад

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4829-ccx4-7c29

больше 4 лет назад

PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the pageURL parameter.

EPSS: Средний
github логотип

GHSA-4828-w5pr-7qgw

больше 4 лет назад

In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of privilege from a malicious proxy configuration with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-132073833.

EPSS: Низкий
github логотип

GHSA-4828-g8j3-35g2

больше 4 лет назад

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4828-5p9m-g4ff

больше 2 лет назад

Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. As part of exploiting this vulnerability, the attacker creates functions that use CREATE RULE to convert the internally-built temporary table to a view. Versions before PostgreSQL 15.6, 14.11, 13.14, and 12.18 are affected. The only known exploit does not work in PostgreSQL 16 and later. For defense in depth, PostgreSQL 16.2 adds the protections that older branches are using to fix their vulnerability.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4828-4rjm-75q4

9 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Retrieve Embedded Sensitive Data.This issue affects Geo Controller: from n/a through <= 8.9.4.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4828-473v-37gh

около 4 лет назад

Unrestricted Upload of File with Dangerous Type in MCMS

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4827-4gjr-3cr2

2 месяца назад

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4827-34pf-wmhw

больше 4 лет назад

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (December 2019).

EPSS: Низкий
github логотип

GHSA-4827-2m3r-j4qh

больше 2 лет назад

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4826-gphh-vw3x

24 дня назад

MQTT 5.0: Receive Maximum zero disables delivery credit

EPSS: Низкий
github логотип

GHSA-4825-mcr8-6gqj

почти 3 года назад

Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4824-pg37-xwx7

1 день назад

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries against cross-company assets if the query-layer scope were bypassed or refactored.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4823-3f87-824g

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: fpga: prevent integer overflow in dfl_feature_ioctl_set_irq() The "hdr.count * sizeof(s32)" multiplication can overflow on 32 bit systems leading to memory corruption. Use array_size() to fix that.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4822-jvwx-w47h

больше 4 лет назад

Uncontrolled Resource Consumption in Matrix Synapse

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-482g-x733-43f8

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 2 лет назад
github логотип
GHSA-482g-pf4j-cwfc

TrueStack Direct Connect 1.4.7 has Incorrect Access Control.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-482g-8988-9gwh

The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-482f-f22h-3jvq

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-482f-7ffv-p77p

Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end Category Editor system, and (4) "Pages that display task status, email addresses, URL, customer, and project information."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4829-xxxr-9f4f

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-4829-ccx4-7c29

PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the pageURL parameter.

24%
Средний
больше 4 лет назад
github логотип
GHSA-4828-w5pr-7qgw

In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of privilege from a malicious proxy configuration with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-132073833.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4828-g8j3-35g2

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4828-5p9m-g4ff

Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. As part of exploiting this vulnerability, the attacker creates functions that use CREATE RULE to convert the internally-built temporary table to a view. Versions before PostgreSQL 15.6, 14.11, 13.14, and 12.18 are affected. The only known exploit does not work in PostgreSQL 16 and later. For defense in depth, PostgreSQL 16.2 adds the protections that older branches are using to fix their vulnerability.

CVSS3: 8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4828-4rjm-75q4

Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Retrieve Embedded Sensitive Data.This issue affects Geo Controller: from n/a through <= 8.9.4.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-4828-473v-37gh

Unrestricted Upload of File with Dangerous Type in MCMS

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-4827-4gjr-3cr2

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
2 месяца назад
github логотип
GHSA-4827-34pf-wmhw

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (December 2019).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4827-2m3r-j4qh

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4826-gphh-vw3x

MQTT 5.0: Receive Maximum zero disables delivery credit

24 дня назад
github логотип
GHSA-4825-mcr8-6gqj

Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-4824-pg37-xwx7

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries against cross-company assets if the query-layer scope were bypassed or refactored.

CVSS3: 5.4
1 день назад
github логотип
GHSA-4823-3f87-824g

In the Linux kernel, the following vulnerability has been resolved: fpga: prevent integer overflow in dfl_feature_ioctl_set_irq() The "hdr.count * sizeof(s32)" multiplication can overflow on 32 bit systems leading to memory corruption. Use array_size() to fix that.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-4822-jvwx-w47h

Uncontrolled Resource Consumption in Matrix Synapse

CVSS3: 5.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу