Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hvf-qx27-92j4

больше 1 года назад

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hvf-c8rp-98pv

больше 4 лет назад

Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3hvc-xwjp-xr8m

больше 4 лет назад

Liquibase Runner Plugin allows users to load arbitrary Java code into controller JVM

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hv9-p65c-7g5r

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Facturante allows SQL Injection. This issue affects Facturante: from n/a through 1.11.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3hv8-cqrj-mwg9

больше 4 лет назад

The Allview X5 Android device with a build fingerprint of ALLVIEW/X5_Soul_Mini/X5_Soul_Mini:8.1.0/O11019/1522468763:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

EPSS: Низкий
github логотип

GHSA-3hv8-6fp5-2gcr

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distinguish resources that are still owned from resources that have already been released. When rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, the sends_out path frees i_sends without clearing the pointer. A later shutdown pass can still treat that stale pointer as a live send ring allocation. Clear i_sends after vfree() in the error unwind path so the existing shutdown logic continues to use the correct ownership state.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hv8-3v7j-3c69

больше 4 лет назад

A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted network traffic.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hv7-66gj-8929

больше 2 лет назад

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hv6-vm7c-38q8

13 дней назад

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.

EPSS: Низкий
github логотип

GHSA-3hv5-9cgc-v44r

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

EPSS: Низкий
github логотип

GHSA-3hv5-2p2f-9642

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.

EPSS: Низкий
github логотип

GHSA-3hv4-r3g6-p2wr

около 2 лет назад

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hv4-r2fm-h27f

больше 2 лет назад

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3hv4-8798-cj3h

больше 4 лет назад

Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDPS HTTP module, via crafted URLs that are "misinterpreted."

EPSS: Низкий
github логотип

GHSA-3hv3-qm2r-7xr8

11 месяцев назад

A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3hv3-pvmg-qv35

почти 4 года назад

The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hv3-jqjm-jhqf

больше 4 лет назад

A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.

EPSS: Низкий
github логотип

GHSA-3hrx-rh52-3vwx

больше 4 лет назад

CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.

EPSS: Низкий
github логотип

GHSA-3hrw-8w6h-x9jc

больше 4 лет назад

An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3hrw-324r-f9xj

больше 4 лет назад

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hvf-qx27-92j4

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hvf-c8rp-98pv

Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

CVSS3: 9.8
86%
Высокий
больше 4 лет назад
github логотип
GHSA-3hvc-xwjp-xr8m

Liquibase Runner Plugin allows users to load arbitrary Java code into controller JVM

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hv9-p65c-7g5r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Facturante allows SQL Injection. This issue affects Facturante: from n/a through 1.11.

CVSS3: 9.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hv8-cqrj-mwg9

The Allview X5 Android device with a build fingerprint of ALLVIEW/X5_Soul_Mini/X5_Soul_Mini:8.1.0/O11019/1522468763:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3hv8-6fp5-2gcr

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distinguish resources that are still owned from resources that have already been released. When rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, the sends_out path frees i_sends without clearing the pointer. A later shutdown pass can still treat that stale pointer as a live send ring allocation. Clear i_sends after vfree() in the error unwind path so the existing shutdown logic continues to use the correct ownership state.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3hv8-3v7j-3c69

A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted network traffic.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hv7-66gj-8929

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hv6-vm7c-38q8

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.

0%
Низкий
13 дней назад
github логотип
GHSA-3hv5-9cgc-v44r

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-3hv5-2p2f-9642

Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hv4-r3g6-p2wr

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 7.2
1%
Низкий
около 2 лет назад
github логотип
GHSA-3hv4-r2fm-h27f

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3hv4-8798-cj3h

Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDPS HTTP module, via crafted URLs that are "misinterpreted."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hv3-qm2r-7xr8

A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3hv3-pvmg-qv35

The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-3hv3-jqjm-jhqf

A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrx-rh52-3vwx

CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrw-8w6h-x9jc

An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.

CVSS3: 4.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrw-324r-f9xj

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу