Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-438w-wmw3-rcp9

10 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-438w-rjj9-5fjf

около 4 лет назад

Cross-site Scripting in Jenkins Repository Connector Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-438w-mprg-3r4x

9 месяцев назад

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-438r-9269-8f2c

больше 4 лет назад

SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-438q-mx46-fpm4

больше 2 лет назад

In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-438q-mm87-r2p9

5 месяцев назад

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-438q-jx8f-cccv

4 месяца назад

Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-438p-qhhr-8gxm

больше 4 лет назад

Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

EPSS: Низкий
github логотип

GHSA-438p-hr89-q323

26 дней назад

In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-438p-f52x-jj25

больше 3 лет назад

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 before 2022.1.110.1.02. One parameter allows SQL injection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-438m-xgcg-7xx6

больше 4 лет назад

SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.

EPSS: Низкий
github логотип

GHSA-438m-xg9x-7hw2

около 2 лет назад

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-438m-gffq-9866

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.

EPSS: Низкий
github логотип

GHSA-438m-6mhw-hq5w

около 1 года назад

Mautic vulnerable to secret data extraction via elfinder

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-438j-gj6m-538p

больше 4 лет назад

In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-438j-8gh2-h5w4

больше 3 лет назад

The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-438j-3c2r-rp4p

11 месяцев назад

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-438j-26hg-98wc

больше 4 лет назад

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

EPSS: Низкий
github логотип

GHSA-438h-h6xr-v2p3

больше 4 лет назад

In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-438h-3pc3-hx6p

больше 4 лет назад

Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-438w-wmw3-rcp9

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

10 дней назад
github логотип
GHSA-438w-rjj9-5fjf

Cross-site Scripting in Jenkins Repository Connector Plugin

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-438w-mprg-3r4x

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-438r-9269-8f2c

SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-438q-mx46-fpm4

In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-438q-mm87-r2p9

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-438q-jx8f-cccv

Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-438p-qhhr-8gxm

Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-438p-hr89-q323

In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.

CVSS3: 9.8
1%
Низкий
26 дней назад
github логотип
GHSA-438p-f52x-jj25

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 before 2022.1.110.1.02. One parameter allows SQL injection.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-438m-xgcg-7xx6

SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-438m-xg9x-7hw2

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-438m-gffq-9866

Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-438m-6mhw-hq5w

Mautic vulnerable to secret data extraction via elfinder

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-438j-gj6m-538p

In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-438j-8gh2-h5w4

The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-438j-3c2r-rp4p

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-438j-26hg-98wc

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-438h-h6xr-v2p3

In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-438h-3pc3-hx6p

Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу