Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-445f-486h-qh76

10 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Using Malicious Files.This issue affects Atarim: from n/a through <= 4.2.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-445c-vh5m-36rj

5 месяцев назад

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

EPSS: Низкий
github логотип

GHSA-445c-hfjr-5j56

больше 3 лет назад

siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4459-qrcc-vfcf

больше 2 лет назад

TYPO3 Cross-Site Scripting in Form Framework

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4458-ww2x-8wwm

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

EPSS: Низкий
github логотип

GHSA-4458-hg2w-xw4j

больше 4 лет назад

PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4457-rx56-p82r

больше 4 лет назад

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4457-c63h-fr7m

около 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4457-8q65-98hw

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix rtnl deadlock issue Currently, the hibmcge netdev acquires the rtnl_lock in pci_error_handlers.reset_prepare() and releases it in pci_error_handlers.reset_done(). However, in the PCI framework: pci_reset_bus - __pci_reset_slot - pci_slot_save_and_disable_locked - pci_dev_save_and_disable - err_handler->reset_prepare(dev); In pci_slot_save_and_disable_locked(): list_for_each_entry(dev, &slot->bus->devices, bus_list) { if (!dev->slot || dev->slot!= slot) continue; pci_dev_save_and_disable(dev); if (dev->subordinate) pci_bus_save_and_disable_locked(dev->subordinate); } This will iterate through all devices under the current bus and execute err_handler->reset_prepare(), causing two devices of the hibmcge driver to sequentially request the rtnl_lock, leading to a deadlock. Since the driver now executes netif_device_detach() before the reset process, it will not concurrently with oth...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4456-w38r-m53x

почти 4 года назад

Besu VM vulnerable to gas allocation error in CALL operations

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4456-f89c-g4p5

больше 4 лет назад

An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8451.

EPSS: Низкий
github логотип

GHSA-4456-4h4r-g935

больше 4 лет назад

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-4456-27v6-7pqr

4 месяца назад

Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4453-jqxv-ffj9

больше 4 лет назад

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4453-g295-24mh

около 4 лет назад

Cross site scripting in Elefant CMS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4453-3pwj-4w2x

больше 4 лет назад

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

EPSS: Низкий
github логотип

GHSA-4452-v8jv-h496

больше 2 лет назад

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4452-rwq3-2x44

больше 1 года назад

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4452-2568-9wpm

больше 4 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-444x-5q6g-3jr8

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia - idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-445f-486h-qh76

Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Using Malicious Files.This issue affects Atarim: from n/a through <= 4.2.

CVSS3: 4.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-445c-vh5m-36rj

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

1%
Низкий
5 месяцев назад
github логотип
GHSA-445c-hfjr-5j56

siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4459-qrcc-vfcf

TYPO3 Cross-Site Scripting in Form Framework

CVSS3: 6.1
больше 2 лет назад
github логотип
GHSA-4458-ww2x-8wwm

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4458-hg2w-xw4j

PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4457-rx56-p82r

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4457-c63h-fr7m

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-4457-8q65-98hw

In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix rtnl deadlock issue Currently, the hibmcge netdev acquires the rtnl_lock in pci_error_handlers.reset_prepare() and releases it in pci_error_handlers.reset_done(). However, in the PCI framework: pci_reset_bus - __pci_reset_slot - pci_slot_save_and_disable_locked - pci_dev_save_and_disable - err_handler->reset_prepare(dev); In pci_slot_save_and_disable_locked(): list_for_each_entry(dev, &slot->bus->devices, bus_list) { if (!dev->slot || dev->slot!= slot) continue; pci_dev_save_and_disable(dev); if (dev->subordinate) pci_bus_save_and_disable_locked(dev->subordinate); } This will iterate through all devices under the current bus and execute err_handler->reset_prepare(), causing two devices of the hibmcge driver to sequentially request the rtnl_lock, leading to a deadlock. Since the driver now executes netif_device_detach() before the reset process, it will not concurrently with oth...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4456-w38r-m53x

Besu VM vulnerable to gas allocation error in CALL operations

CVSS3: 9.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-4456-f89c-g4p5

An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8451.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4456-4h4r-g935

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4456-27v6-7pqr

Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4453-jqxv-ffj9

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4453-g295-24mh

Cross site scripting in Elefant CMS

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-4453-3pwj-4w2x

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4452-v8jv-h496

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4452-rwq3-2x44

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.

CVSS3: 7.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-4452-2568-9wpm

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-444x-5q6g-3jr8

Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia - idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу