Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43gm-x67w-cjp4

больше 4 лет назад

The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

EPSS: Низкий
github логотип

GHSA-43gm-9rr3-cx7g

19 дней назад

Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-43gj-mj95-qp4h

почти 2 года назад

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43gj-mj2w-wh46

больше 6 лет назад

Cross-Site Scripting in TYPO3 CMS Form Engine

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43gj-jf28-cm95

больше 3 лет назад

A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bookings/manage_booking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227707.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43gh-2c4j-x343

больше 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 4.4 (Availability impacts).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-43gg-m8j9-xmqj

больше 2 лет назад

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260274 is the identifier assigned to this vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-43gg-3jq2-xwfh

почти 4 года назад

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43gf-9mf8-44g5

больше 4 лет назад

IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.

EPSS: Низкий
github логотип

GHSA-43gf-2x57-fwxf

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix missed dmabuf unpinning in error path of prepare_fb() Correct error handling in prepare_fb() to fix leaking resources when error happens.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43gc-mjxg-gvrq

больше 5 лет назад

XStream is vulnerable to an Arbitrary Code Execution attack

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-43g9-xc7g-7r65

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: erofs: fix incorrect early exits for invalid metabox-enabled images Crafted EROFS images with metadata compression enabled can trigger incorrect early returns, leading to folio reference leaks. However, this does not cause system crashes or other severe issues.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43g9-qgw6-3pfp

больше 4 лет назад

Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43g9-fmq9-jjpm

больше 4 лет назад

Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43g9-956r-vq78

больше 4 лет назад

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-43g8-79x3-j898

почти 5 лет назад

Unrestricted access to predictable file paths in hov/jobfair

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43g8-4r39-vq2f

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: parisc: Try to fix random segmentation faults in package builds PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years. Systems with earlier processors are much more stable. Systems with PA8800 and PA8900 processors have a large L2 cache which needs per page flushing for decent performance when a large range is flushed. The combined cache in these systems is also more sensitive to non-equivalent aliases than the caches in earlier systems. The majority of random segmentation faults that I have looked at appear to be memory corruption in memory allocated using mmap and malloc. My first attempt at fixing the random faults didn't work. On reviewing the cache code, I realized that there were two issues which the existing code didn't handle correctly. Both relate to cache move-in. Another issue is that the present bit in PTEs is racy. 1) PA-RISC caches hav...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43g7-vrh8-pwwx

больше 4 лет назад

The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43g7-f6j3-j7xf

около 1 года назад

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-43g7-cwr8-q3jh

4 месяца назад

OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43gm-x67w-cjp4

The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-43gm-9rr3-cx7g

Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover

CVSS3: 8.7
0%
Низкий
19 дней назад
github логотип
GHSA-43gj-mj95-qp4h

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-43gj-mj2w-wh46

Cross-Site Scripting in TYPO3 CMS Form Engine

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
github логотип
GHSA-43gj-jf28-cm95

A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bookings/manage_booking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227707.

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43gh-2c4j-x343

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 4.4 (Availability impacts).

CVSS3: 4.4
4%
Низкий
больше 4 лет назад
github логотип
GHSA-43gg-m8j9-xmqj

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260274 is the identifier assigned to this vulnerability.

CVSS3: 4.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-43gg-3jq2-xwfh

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-43gf-9mf8-44g5

IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43gf-2x57-fwxf

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix missed dmabuf unpinning in error path of prepare_fb() Correct error handling in prepare_fb() to fix leaking resources when error happens.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-43gc-mjxg-gvrq

XStream is vulnerable to an Arbitrary Code Execution attack

CVSS3: 5.3
15%
Средний
больше 5 лет назад
github логотип
GHSA-43g9-xc7g-7r65

In the Linux kernel, the following vulnerability has been resolved: erofs: fix incorrect early exits for invalid metabox-enabled images Crafted EROFS images with metadata compression enabled can trigger incorrect early returns, leading to folio reference leaks. However, this does not cause system crashes or other severe issues.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-43g9-qgw6-3pfp

Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43g9-fmq9-jjpm

Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43g9-956r-vq78

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.

CVSS3: 9.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-43g8-79x3-j898

Unrestricted access to predictable file paths in hov/jobfair

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-43g8-4r39-vq2f

In the Linux kernel, the following vulnerability has been resolved: parisc: Try to fix random segmentation faults in package builds PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years. Systems with earlier processors are much more stable. Systems with PA8800 and PA8900 processors have a large L2 cache which needs per page flushing for decent performance when a large range is flushed. The combined cache in these systems is also more sensitive to non-equivalent aliases than the caches in earlier systems. The majority of random segmentation faults that I have looked at appear to be memory corruption in memory allocated using mmap and malloc. My first attempt at fixing the random faults didn't work. On reviewing the cache code, I realized that there were two issues which the existing code didn't handle correctly. Both relate to cache move-in. Another issue is that the present bit in PTEs is racy. 1) PA-RISC caches hav...

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-43g7-vrh8-pwwx

The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43g7-f6j3-j7xf

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-43g7-cwr8-q3jh

OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI

CVSS3: 7.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу