Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3q26-rw63-5772

почти 2 года назад

There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3q26-f695-pp76

около 1 года назад

@cyanheads/git-mcp-server vulnerable to command injection in several tools

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3q25-m4x5-9jh7

больше 4 лет назад

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

EPSS: Низкий
github логотип

GHSA-3q24-wf35-56h6

больше 1 года назад

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3q24-rrgq-j66h

больше 3 лет назад

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q23-2j2r-mmw3

больше 1 года назад

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3q22-68gw-x3mq

11 месяцев назад

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3pxx-76hx-4rw2

больше 4 лет назад

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

EPSS: Низкий
github логотип

GHSA-3pxv-j5r5-v5qh

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3pxv-834r-692c

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Quanzo quanzo allows PHP Local File Inclusion.This issue affects Quanzo: from n/a through <= 1.0.10.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3pxv-7cmr-fjr4

5 месяцев назад

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

EPSS: Низкий
github логотип

GHSA-3pxr-wpfc-92h9

около 1 месяца назад

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pxr-vgjw-q3f8

больше 4 лет назад

Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-3pxr-3j7f-c35j

около 2 лет назад

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3pxq-xg4j-rgqx

больше 1 года назад

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pxq-f3cp-jmxp

6 месяцев назад

OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pxq-5cc9-p3hw

больше 4 лет назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

EPSS: Низкий
github логотип

GHSA-3pxq-4mq2-m2mc

больше 4 лет назад

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-3pxp-pwrp-2w6f

больше 4 лет назад

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

EPSS: Низкий
github логотип

GHSA-3pxp-6963-46r9

около 8 лет назад

Command Injection in pdfinfojs

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q26-rw63-5772

There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3q26-f695-pp76

@cyanheads/git-mcp-server vulnerable to command injection in several tools

CVSS3: 7.5
27%
Средний
около 1 года назад
github логотип
GHSA-3q25-m4x5-9jh7

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3q24-wf35-56h6

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.

CVSS3: 6
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q24-rrgq-j66h

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q23-2j2r-mmw3

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVSS3: 8.8
12%
Средний
больше 1 года назад
github логотип
GHSA-3q22-68gw-x3mq

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-3pxx-76hx-4rw2

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pxv-j5r5-v5qh

In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee...

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3pxv-834r-692c

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Quanzo quanzo allows PHP Local File Inclusion.This issue affects Quanzo: from n/a through <= 1.0.10.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-3pxv-7cmr-fjr4

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

1%
Низкий
5 месяцев назад
github логотип
GHSA-3pxr-wpfc-92h9

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

CVSS3: 9.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-3pxr-vgjw-q3f8

Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pxr-3j7f-c35j

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

CVSS3: 5.4
2%
Низкий
около 2 лет назад
github логотип
GHSA-3pxq-xg4j-rgqx

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3pxq-f3cp-jmxp

OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3pxq-5cc9-p3hw

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pxq-4mq2-m2mc

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3pxp-pwrp-2w6f

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pxp-6963-46r9

Command Injection in pdfinfojs

CVSS3: 9.8
5%
Низкий
около 8 лет назад

Уязвимостей на страницу