Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3q6x-mjrg-68xw

9 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q6x-j6f7-rvxv

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q6x-gxwh-88p9

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure The kcalloc() in dmirror_device_evict_chunk() will return null if the physical memory has run out. As a result, if src_pfns or dst_pfns is dereferenced, the null pointer dereference bug will happen. Moreover, the device is going away. If the kcalloc() fails, the pages mapping a chunk could not be evicted. So add a __GFP_NOFAIL flag in kcalloc(). Finally, as there is no need to have physically contiguous memory, Switch kcalloc() to kvcalloc() in order to avoid failing allocations.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3q6w-vp42-26vx

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3q6v-mwhw-45h2

больше 1 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3q6v-jv77-fpxc

больше 4 лет назад

KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

EPSS: Низкий
github логотип

GHSA-3q6v-gv39-h4r6

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3q6r-ghxh-24g9

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q6q-xxfm-fxqr

больше 4 лет назад

Buffer overflow in AIX xdat gives root access to local users.

EPSS: Низкий
github логотип

GHSA-3q6q-qc68-x6pf

больше 4 лет назад

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3q6q-m779-9qvh

больше 4 лет назад

The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

EPSS: Низкий
github логотип

GHSA-3q6q-gxwr-7gqv

8 месяцев назад

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q6q-8gwq-hrm6

около 2 месяцев назад

The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3q6q-26vg-v97x

около 2 месяцев назад

Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects

EPSS: Низкий
github логотип

GHSA-3q6p-xqh5-xhx5

больше 4 лет назад

Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4774 and CVE-2015-4779.

EPSS: Низкий
github логотип

GHSA-3q6p-r6rr-266x

больше 4 лет назад

Jenkins Deploy to container Plugin stored plain text passwords in job configuration

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3q6p-m26m-f78r

около 1 года назад

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3q6m-v84f-6p9h

почти 3 года назад

quic-go vulnerable to pointer dereference that can lead to panic

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q6m-7jw2-r5m4

3 месяца назад

The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Icon CSS Class' category field in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3q6j-h79v-fffv

больше 4 лет назад

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data as well as unauthorized read access to a subset of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.0 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L).

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q6x-mjrg-68xw

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-3q6x-j6f7-rvxv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q6x-gxwh-88p9

In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure The kcalloc() in dmirror_device_evict_chunk() will return null if the physical memory has run out. As a result, if src_pfns or dst_pfns is dereferenced, the null pointer dereference bug will happen. Moreover, the device is going away. If the kcalloc() fails, the pages mapping a chunk could not be evicted. So add a __GFP_NOFAIL flag in kcalloc(). Finally, as there is no need to have physically contiguous memory, Switch kcalloc() to kvcalloc() in order to avoid failing allocations.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3q6w-vp42-26vx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q6v-mwhw-45h2

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q6v-jv77-fpxc

KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6v-gv39-h4r6

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6r-ghxh-24g9

A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6q-xxfm-fxqr

Buffer overflow in AIX xdat gives root access to local users.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6q-qc68-x6pf

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6q-m779-9qvh

The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6q-gxwr-7gqv

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3q6q-8gwq-hrm6

The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3q6q-26vg-v97x

Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects

около 2 месяцев назад
github логотип
GHSA-3q6p-xqh5-xhx5

Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4774 and CVE-2015-4779.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6p-r6rr-266x

Jenkins Deploy to container Plugin stored plain text passwords in job configuration

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q6p-m26m-f78r

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.

CVSS3: 5.6
0%
Низкий
около 1 года назад
github логотип
GHSA-3q6m-v84f-6p9h

quic-go vulnerable to pointer dereference that can lead to panic

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3q6m-7jw2-r5m4

The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Icon CSS Class' category field in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 4.9
0%
Низкий
3 месяца назад
github логотип
GHSA-3q6j-h79v-fffv

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data as well as unauthorized read access to a subset of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.0 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L).

CVSS3: 5.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу