Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 895

Количество 361 895

github логотип

GHSA-3g52-xh39-r8h9

больше 4 лет назад

An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3g52-7jf9-68rg

10 месяцев назад

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3g4x-5jfv-pg4g

12 месяцев назад

A vulnerability was detected in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3g4x-5gh5-43g8

больше 1 года назад

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3g4w-52x2-m37c

больше 4 лет назад

While loading dynamic fonts, a buffer overflow may occur if the number of segments in the font file is out of range in Snapdragon Mobile and Snapdragon Wear.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g4v-p46q-rp5h

больше 2 лет назад

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3g4v-6jw7-xv32

больше 4 лет назад

Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call.

EPSS: Низкий
github логотип

GHSA-3g4r-x9jc-pp43

около 4 лет назад

An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3g4r-rv7h-cfg3

больше 4 лет назад

PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter.

EPSS: Низкий
github логотип

GHSA-3g4r-mcrh-f8r8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

EPSS: Низкий
github логотип

GHSA-3g4r-f6qv-4g55

4 месяца назад

Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3g4q-gv3v-9pj2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent double queueing of implicit ODP mr destroy work by using __xa_cmpxchg() to make sure this is the only time we are destroying this specific mr. Without this change, we could try to invalidate this mr twice, which in turn could result in queuing a MR work destroy twice, and eventually the second work could execute after the MR was freed due to the first work, causing a user after free and trace below. refcount_t: underflow; use-after-free. WARNING: CPU: 2 PID: 12178 at lib/refcount.c:28 refcount_warn_saturate+0x12b/0x130 Modules linked in: bonding ib_ipoib vfio_pci ip_gre geneve nf_tables ip6_gre gre ip6_tunnel tunnel6 ipip tunnel4 ib_umad rdma_ucm mlx5_vfio_pci vfio_pci_core vfio_iommu_type1 mlx5_ib vfio ib_uverbs mlx5_core iptable_raw openvswitch nsh rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core xt_conntrack xt_MASQUERADE nf_...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g4q-5xwc-2fr8

3 месяца назад

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g4q-2f67-2gvh

около 1 месяца назад

netfoil has a resource leak in LRU cache

EPSS: Низкий
github логотип

GHSA-3g4p-m6j4-fxhj

10 месяцев назад

An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g4p-c74p-mh7x

3 месяца назад

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3g4j-xxgr-w4g3

больше 4 лет назад

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8680.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g4j-rmgh-9r5p

6 месяцев назад

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3g4j-r53p-22wx

10 месяцев назад

Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3g4h-66cq-c8vg

около 2 лет назад

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect Enterprise configuration file is: C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g52-xh39-r8h9

An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g52-7jf9-68rg

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-3g4x-5jfv-pg4g

A vulnerability was detected in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 4.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-3g4x-5gh5-43g8

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

CVSS3: 8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g4w-52x2-m37c

While loading dynamic fonts, a buffer overflow may occur if the number of segments in the font file is out of range in Snapdragon Mobile and Snapdragon Wear.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4v-p46q-rp5h

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3g4v-6jw7-xv32

Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4r-x9jc-pp43

An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3g4r-rv7h-cfg3

PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4r-mcrh-f8r8

Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4r-f6qv-4g55

Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.2
0%
Низкий
4 месяца назад
github логотип
GHSA-3g4q-gv3v-9pj2

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent double queueing of implicit ODP mr destroy work by using __xa_cmpxchg() to make sure this is the only time we are destroying this specific mr. Without this change, we could try to invalidate this mr twice, which in turn could result in queuing a MR work destroy twice, and eventually the second work could execute after the MR was freed due to the first work, causing a user after free and trace below. refcount_t: underflow; use-after-free. WARNING: CPU: 2 PID: 12178 at lib/refcount.c:28 refcount_warn_saturate+0x12b/0x130 Modules linked in: bonding ib_ipoib vfio_pci ip_gre geneve nf_tables ip6_gre gre ip6_tunnel tunnel6 ipip tunnel4 ib_umad rdma_ucm mlx5_vfio_pci vfio_pci_core vfio_iommu_type1 mlx5_ib vfio ib_uverbs mlx5_core iptable_raw openvswitch nsh rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core xt_conntrack xt_MASQUERADE nf_...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g4q-5xwc-2fr8

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3g4q-2f67-2gvh

netfoil has a resource leak in LRU cache

около 1 месяца назад
github логотип
GHSA-3g4p-m6j4-fxhj

An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3g4p-c74p-mh7x

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

CVSS3: 4.9
0%
Низкий
3 месяца назад
github логотип
GHSA-3g4j-xxgr-w4g3

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8680.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4j-rmgh-9r5p

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS3: 7
2%
Низкий
6 месяцев назад
github логотип
GHSA-3g4j-r53p-22wx

Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution

CVSS3: 9.1
10 месяцев назад
github логотип
GHSA-3g4h-66cq-c8vg

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect Enterprise configuration file is: C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

CVSS3: 7.7
0%
Низкий
около 2 лет назад

Уязвимостей на страницу