Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-4585-x37m-6p5h

больше 4 лет назад

The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4585-79j7-22mc

больше 4 лет назад

Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4585-28v2-8h46

больше 2 лет назад

Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4584-7932-cm8g

больше 4 лет назад

A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4583-4mx5-3jcc

больше 4 лет назад

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4582-ff6x-w32x

почти 4 года назад

The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-457x-v5jv-rvr7

больше 4 лет назад

In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. This will trigger a null pointer dereference bug in case of a memory allocation failure.

EPSS: Низкий
github логотип

GHSA-457x-pfmm-7g5g

больше 4 лет назад

A Stored Cross-Site Scripting (XSS) vulnerability in DivvyDrive's "aciklama" parameter could allow anyone to gain users' session informations.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-457w-p2rx-36qq

больше 2 лет назад

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-457v-px4g-7qcg

больше 4 лет назад

An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.

EPSS: Низкий
github логотип

GHSA-457r-j4jw-r8c4

7 месяцев назад

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-457r-cqc8-9vj9

почти 4 года назад

sweetalert2 v10.16.10 and above contains hidden functionality

EPSS: Низкий
github логотип

GHSA-457r-86mp-h5w4

больше 2 лет назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-457q-vj84-7r8r

больше 4 лет назад

A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.

EPSS: Низкий
github логотип

GHSA-457p-q34w-3pc3

11 месяцев назад

A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-457m-vq92-44f4

около 2 лет назад

Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-457m-jpvx-pqx9

3 месяца назад

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-457m-59w6-w674

12 месяцев назад

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-457m-434g-h2h3

больше 4 лет назад

The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

EPSS: Низкий
github логотип

GHSA-457m-2gc9-wrxq

больше 4 лет назад

Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4585-x37m-6p5h

The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4585-79j7-22mc

Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4585-28v2-8h46

Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4584-7932-cm8g

A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation.

CVSS3: 7.5
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4583-4mx5-3jcc

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

CVSS3: 9
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4582-ff6x-w32x

The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-457x-v5jv-rvr7

In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. This will trigger a null pointer dereference bug in case of a memory allocation failure.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-457x-pfmm-7g5g

A Stored Cross-Site Scripting (XSS) vulnerability in DivvyDrive's "aciklama" parameter could allow anyone to gain users' session informations.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-457w-p2rx-36qq

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

CVSS3: 9.1
2%
Низкий
больше 2 лет назад
github логотип
GHSA-457v-px4g-7qcg

An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-457r-j4jw-r8c4

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-457r-cqc8-9vj9

sweetalert2 v10.16.10 and above contains hidden functionality

почти 4 года назад
github логотип
GHSA-457r-86mp-h5w4

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-457q-vj84-7r8r

A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-457p-q34w-3pc3

A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-457m-vq92-44f4

Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-457m-jpvx-pqx9

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
3 месяца назад
github логотип
GHSA-457m-59w6-w674

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-457m-434g-h2h3

The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-457m-2gc9-wrxq

Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу