Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wr4-g3xj-q452

около 4 лет назад

Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wr4-4m2q-j8pw

почти 2 года назад

The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wr4-44h7-86g3

больше 4 лет назад

BabyGekko before 1.2.4 has SQL injection.

EPSS: Низкий
github логотип

GHSA-3wr4-2wwf-jjxw

около 1 месяца назад

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumerating sequential attachment IDs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wr4-2chq-phgj

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. This issue affects ALM Octane Management: from 16.2.100 through 24.4.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3wr3-v78q-x45g

больше 4 лет назад

A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

EPSS: Низкий
github логотип

GHSA-3wr2-rw8c-pv3f

больше 4 лет назад

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wr2-29r4-6pch

больше 1 года назад

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_settings_tab() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wqx-wh6r-cf85

больше 4 лет назад

Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.

EPSS: Низкий
github логотип

GHSA-3wqw-wxm4-g72v

около 1 года назад

A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of the patch is 5705d99cc1f23f36f9a84aab26d1724010b97798. It is recommended to apply a patch to fix this issue. The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-3wqw-8x5p-vv88

около 2 лет назад

Microsoft WS-Discovery Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wqv-wjx5-m93q

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: spi: imx: fix use-after-free on unbind The SPI subsystem frees the controller and any subsystem allocated driver data as part of deregistration (unless the allocation is device managed). Take another reference before deregistering the controller so that the driver data is not freed until the driver is done with it.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wqv-qpc6-2469

10 месяцев назад

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data Import. Performing manipulation of the argument xml_file results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3wqv-g56j-g5xc

больше 4 лет назад

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

EPSS: Низкий
github логотип

GHSA-3wqv-582c-6cpc

около 2 лет назад

In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3wqv-4hq2-7gcp

около 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce allows Phishing. This issue affects WP Gravity Forms Salesforce: from n/a through 1.4.7.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3wqr-pcvr-hx5r

больше 4 лет назад

Sander Bos discovered Apport's lock file was in a world-writable director which allowed all users to prevent crash handling.

EPSS: Низкий
github логотип

GHSA-3wqr-pcph-pf9p

17 дней назад

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3wqr-83x4-348r

5 месяцев назад

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly higher than the actual available stock.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wqr-6335-7cpw

больше 4 лет назад

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wr4-g3xj-q452

Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3wr4-4m2q-j8pw

The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wr4-44h7-86g3

BabyGekko before 1.2.4 has SQL injection.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wr4-2wwf-jjxw

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumerating sequential attachment IDs.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wr4-2chq-phgj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. This issue affects ALM Octane Management: from 16.2.100 through 24.4.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wr3-v78q-x45g

A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wr2-rw8c-pv3f

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-3wr2-29r4-6pch

The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_settings_tab() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wqx-wh6r-cf85

Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3wqw-wxm4-g72v

A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of the patch is 5705d99cc1f23f36f9a84aab26d1724010b97798. It is recommended to apply a patch to fix this issue. The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.

CVSS3: 2.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3wqw-8x5p-vv88

Microsoft WS-Discovery Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
около 2 лет назад
github логотип
GHSA-3wqv-wjx5-m93q

In the Linux kernel, the following vulnerability has been resolved: spi: imx: fix use-after-free on unbind The SPI subsystem frees the controller and any subsystem allocated driver data as part of deregistration (unless the allocation is device managed). Take another reference before deregistering the controller so that the driver data is not freed until the driver is done with it.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3wqv-qpc6-2469

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data Import. Performing manipulation of the argument xml_file results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
10 месяцев назад
github логотип
GHSA-3wqv-g56j-g5xc

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wqv-582c-6cpc

In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wqv-4hq2-7gcp

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce allows Phishing. This issue affects WP Gravity Forms Salesforce: from n/a through 1.4.7.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-3wqr-pcvr-hx5r

Sander Bos discovered Apport's lock file was in a world-writable director which allowed all users to prevent crash handling.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wqr-pcph-pf9p

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.

CVSS3: 5.9
0%
Низкий
17 дней назад
github логотип
GHSA-3wqr-83x4-348r

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly higher than the actual available stock.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3wqr-6335-7cpw

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу