Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 328

Количество 362 328

github логотип

GHSA-3h32-r78h-g4px

около 4 лет назад

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.

EPSS: Низкий
github логотип

GHSA-3h32-9hq6-4rcq

больше 4 лет назад

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h32-4mhh-8v2f

больше 4 лет назад

The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interaction with the vp3_h_loop_filter_c function in libavcodec/vp3dsp.c in FFmpeg.

EPSS: Низкий
github логотип

GHSA-3h2x-f5p6-82hc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2x-cpjg-qq3m

больше 4 лет назад

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2w-7wcr-vq95

около 4 лет назад

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3h2w-68px-r4v5

10 месяцев назад

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2w-5hmv-xgqc

около 4 лет назад

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2v-h2q9-f9r6

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' should check the return value before examining skb data. So convert the latter to return an appropriate error code and propagate it to return from 'wfx_start_ap()' as well. Compile tested only.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h2r-mh7w-gr5w

почти 4 года назад

Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h2r-h2x2-mg4h

около 3 лет назад

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3h2r-57j7-jcpg

больше 4 лет назад

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006191References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3h2r-2233-77cq

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2q-m63q-9cf6

около 4 лет назад

Missing permission check in Perfecto Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3h2q-j328-63h4

1 день назад

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

EPSS: Низкий
github логотип

GHSA-3h2q-j2v4-6w5r

6 месяцев назад

OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3h2q-4qw3-2f5h

больше 4 лет назад

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h2m-jjrw-87hw

больше 4 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2j-h4g8-5pmr

больше 4 лет назад

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2j-95j8-599v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h32-r78h-g4px

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h32-9hq6-4rcq

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h32-4mhh-8v2f

The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interaction with the vp3_h_loop_filter_c function in libavcodec/vp3dsp.c in FFmpeg.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2x-f5p6-82hc

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2x-cpjg-qq3m

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2w-7wcr-vq95

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3h2w-68px-r4v5

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3h2w-5hmv-xgqc

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h2v-h2q9-f9r6

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' should check the return value before examining skb data. So convert the latter to return an appropriate error code and propagate it to return from 'wfx_start_ap()' as well. Compile tested only.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h2r-mh7w-gr5w

Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3h2r-h2x2-mg4h

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVSS3: 2.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-3h2r-57j7-jcpg

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006191References: N/A

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2r-2233-77cq

Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3h2q-m63q-9cf6

Missing permission check in Perfecto Plugin

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h2q-j328-63h4

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

1 день назад
github логотип
GHSA-3h2q-j2v4-6w5r

OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers

CVSS3: 5
6 месяцев назад
github логотип
GHSA-3h2q-4qw3-2f5h

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2m-jjrw-87hw

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2j-h4g8-5pmr

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h2j-95j8-599v

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу