Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 363 419

Количество 363 419

github логотип

GHSA-3m93-m4q6-mc6v

больше 6 лет назад

Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3m93-8pm8-gqxj

больше 4 лет назад

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

EPSS: Низкий
github логотип

GHSA-3m93-68mf-mv6r

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3m8x-jjr4-6gqq

больше 4 лет назад

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

EPSS: Низкий
github логотип

GHSA-3m8x-7qxf-c378

больше 4 лет назад

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3m8w-rwh2-w5q7

14 дней назад

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3m8w-q233-vhrp

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: mixer: oss: Add card disconnect checkpoints ALSA OSS mixer layer calls the kcontrol ops rather individually, and pending calls might be not always caught at disconnecting the device. For avoiding the potential UAF scenarios, add sanity checks of the card disconnection at each entry point of OSS mixer accesses. The rwsem is taken just before that check, hence the rest context should be covered by that properly.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m8w-h8mm-xqvp

9 месяцев назад

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8w-442m-3p2q

больше 4 лет назад

Jenkins Artifactory Plugin missing permission check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8w-2mvj-9q7j

больше 1 года назад

Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8v-mqfw-xp3g

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: PCI: s390: Fix use-after-free of PCI resources with per-function hotplug On s390 PCI functions may be hotplugged individually even when they belong to a multi-function device. In particular on an SR-IOV device VFs may be removed and later re-added. In commit a50297cf8235 ("s390/pci: separate zbus creation from scanning") it was missed however that struct pci_bus and struct zpci_bus's resource list retained a reference to the PCI functions MMIO resources even though those resources are released and freed on hot-unplug. These stale resources may subsequently be claimed when the PCI function re-appears resulting in use-after-free. One idea of fixing this use-after-free in s390 specific code that was investigated was to simply keep resources around from the moment a PCI function first appeared until the whole virtual PCI bus created for a multi-function device disappears. The problem with this however is that due to...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m8v-9pw4-4fx9

больше 4 лет назад

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3m8r-w7xg-jqvw

10 месяцев назад

DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CVSS3: 10
EPSS: Средний
github логотип

GHSA-3m8r-78wv-v278

6 дней назад

A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3m8r-4f2m-v89p

почти 3 года назад

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3m8q-vjx5-jjcc

больше 3 лет назад

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ALPS07628587.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3m8q-g6w4-24q3

больше 4 лет назад

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 and earlier versions, Tecal RH2288H V2 V100R002C00SPC115 and earlier versions, Tecal RH2485 V2 V100R002C00SPC502 and earlier versions, Tecal RH5885 V2 V100R001C02SPC109 and earlier versions, Tecal RH5885 V3 V100R003C01SPC102 and earlier versions, Tecal RH5885H V3 V100R003C00SPC102 and earlier versions, Tecal XH310 V2 V100R001C00SPC110 and earlier versions, Tecal XH311 V2 V100R001C00SPC110 and earlier versions, Tecal XH320 V2 V100R001C00SPC110 and earlier versions, Tecal XH621 V2 V100R001C00SPC106 and earlier versions, Tecal DH310 V2 V100R001C00SPC110 and earlier versions, Tecal DH320 V2 V100R001C00SPC106 and earlier versions, Tecal DH620 V2 V100R001C00SPC106 and earlier versions, Tecal DH621...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3m8p-xpm6-8ww3

больше 4 лет назад

Ansible Arbitrary Code Execution

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3m8p-v336-pmqp

больше 1 года назад

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3m8p-67j9-4fjq

больше 4 лет назад

SQL injection vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to execute arbitrary SQL commands via the user_field parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3m93-m4q6-mc6v

Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
github логотип
GHSA-3m93-8pm8-gqxj

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3m93-68mf-mv6r

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8x-jjr4-6gqq

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8x-7qxf-c378

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8w-rwh2-w5q7

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.

CVSS3: 8.1
1%
Низкий
14 дней назад
github логотип
GHSA-3m8w-q233-vhrp

In the Linux kernel, the following vulnerability has been resolved: ALSA: mixer: oss: Add card disconnect checkpoints ALSA OSS mixer layer calls the kcontrol ops rather individually, and pending calls might be not always caught at disconnecting the device. For avoiding the potential UAF scenarios, add sanity checks of the card disconnection at each entry point of OSS mixer accesses. The rwsem is taken just before that check, hence the rest context should be covered by that properly.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3m8w-h8mm-xqvp

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3m8w-442m-3p2q

Jenkins Artifactory Plugin missing permission check

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8w-2mvj-9q7j

Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3m8v-mqfw-xp3g

In the Linux kernel, the following vulnerability has been resolved: PCI: s390: Fix use-after-free of PCI resources with per-function hotplug On s390 PCI functions may be hotplugged individually even when they belong to a multi-function device. In particular on an SR-IOV device VFs may be removed and later re-added. In commit a50297cf8235 ("s390/pci: separate zbus creation from scanning") it was missed however that struct pci_bus and struct zpci_bus's resource list retained a reference to the PCI functions MMIO resources even though those resources are released and freed on hot-unplug. These stale resources may subsequently be claimed when the PCI function re-appears resulting in use-after-free. One idea of fixing this use-after-free in s390 specific code that was investigated was to simply keep resources around from the moment a PCI function first appeared until the whole virtual PCI bus created for a multi-function device disappears. The problem with this however is that due to...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3m8v-9pw4-4fx9

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

CVSS3: 10
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8r-w7xg-jqvw

DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CVSS3: 10
45%
Средний
10 месяцев назад
github логотип
GHSA-3m8r-78wv-v278

A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

CVSS3: 4.7
0%
Низкий
6 дней назад
github логотип
GHSA-3m8r-4f2m-v89p

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-3m8q-vjx5-jjcc

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ALPS07628587.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8q-g6w4-24q3

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 and earlier versions, Tecal RH2288H V2 V100R002C00SPC115 and earlier versions, Tecal RH2485 V2 V100R002C00SPC502 and earlier versions, Tecal RH5885 V2 V100R001C02SPC109 and earlier versions, Tecal RH5885 V3 V100R003C01SPC102 and earlier versions, Tecal RH5885H V3 V100R003C00SPC102 and earlier versions, Tecal XH310 V2 V100R001C00SPC110 and earlier versions, Tecal XH311 V2 V100R001C00SPC110 and earlier versions, Tecal XH320 V2 V100R001C00SPC110 and earlier versions, Tecal XH621 V2 V100R001C00SPC106 and earlier versions, Tecal DH310 V2 V100R001C00SPC110 and earlier versions, Tecal DH320 V2 V100R001C00SPC106 and earlier versions, Tecal DH620 V2 V100R001C00SPC106 and earlier versions, Tecal DH621...

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8p-xpm6-8ww3

Ansible Arbitrary Code Execution

CVSS3: 8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3m8p-v336-pmqp

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3m8p-67j9-4fjq

SQL injection vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to execute arbitrary SQL commands via the user_field parameter.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу