Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wm8-ccjv-8v3m

больше 4 лет назад

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.

EPSS: Низкий
github логотип

GHSA-3wm7-jw5g-v3gq

8 месяцев назад

Missing Authorization vulnerability in Emraan Cheema CubeWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through 1.1.27.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wm7-c6q7-cvwm

11 месяцев назад

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3wm7-5h33-f92f

больше 3 лет назад

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wm7-483h-66xg

3 месяца назад

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3wm6-5f35-v4rp

больше 3 лет назад

An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3wm5-3g94-xp54

почти 3 года назад

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wm4-c4h2-6mcg

больше 4 лет назад

Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3wm3-m3jr-6jpv

больше 4 лет назад

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

EPSS: Низкий
github логотип

GHSA-3wm3-96hr-g3vq

почти 2 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Clayton Feed Comments Number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through 0.2.1.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3wm2-j8jq-jcw8

около 2 месяцев назад

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3wjx-vqf3-h2px

больше 2 лет назад

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3wjw-f8gp-589c

больше 4 лет назад

SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3wjw-649j-2hjx

больше 4 лет назад

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wjv-m5rx-86vp

больше 4 лет назад

Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.

EPSS: Низкий
github логотип

GHSA-3wjv-2739-3h75

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d100d1b started exploiting this behavior to speed up filesystem unmount: gfs2 would simply free glocks it didn't want to unlock and then release the lockspace. This didn't take the bast callbacks for asynchronous lock contention notifications into account, which remain active until until a lock is unlocked or its lockspace is released. To prevent those callbacks from accessing deallocated objects, put the glocks that should not be unlocked on the sd_dead_glocks list, release the lockspace, and only then free those glocks. As an additional measure, ignore unexpected ast and bast callbacks if the receiving glock is dead.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wjr-p76q-rg8q

почти 3 года назад

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3wjr-j39j-wfg8

около 3 лет назад

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.

CVSS3: 1.8
EPSS: Низкий
github логотип

GHSA-3wjr-cm4f-gg8r

больше 4 лет назад

The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3wjr-3jc2-hr84

больше 1 года назад

A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wm8-ccjv-8v3m

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wm7-jw5g-v3gq

Missing Authorization vulnerability in Emraan Cheema CubeWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through 1.1.27.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3wm7-c6q7-cvwm

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-3wm7-5h33-f92f

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wm7-483h-66xg

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)

CVSS3: 6.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3wm6-5f35-v4rp

An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wm5-3g94-xp54

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVSS3: 6.1
2%
Низкий
почти 3 года назад
github логотип
GHSA-3wm4-c4h2-6mcg

Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wm3-m3jr-6jpv

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3wm3-96hr-g3vq

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Clayton Feed Comments Number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through 0.2.1.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-3wm2-j8jq-jcw8

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.

CVSS3: 9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3wjx-vqf3-h2px

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wjw-f8gp-589c

SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjw-649j-2hjx

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjv-m5rx-86vp

Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjv-2739-3h75

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d100d1b started exploiting this behavior to speed up filesystem unmount: gfs2 would simply free glocks it didn't want to unlock and then release the lockspace. This didn't take the bast callbacks for asynchronous lock contention notifications into account, which remain active until until a lock is unlocked or its lockspace is released. To prevent those callbacks from accessing deallocated objects, put the glocks that should not be unlocked on the sd_dead_glocks list, release the lockspace, and only then free those glocks. As an additional measure, ignore unexpected ast and bast callbacks if the receiving glock is dead.

CVSS3: 7.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3wjr-p76q-rg8q

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
40%
Средний
почти 3 года назад
github логотип
GHSA-3wjr-j39j-wfg8

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.

CVSS3: 1.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3wjr-cm4f-gg8r

The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjr-3jc2-hr84

A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 4.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу