Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-37mw-ccj4-5q2g

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Email Notification on Login allows Stored XSS. This issue affects Email Notification on Login: from n/a through 1.6.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-37mw-44qp-f5jm

около 1 года назад

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-37mv-q3x5-3mwg

больше 3 лет назад

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37mr-x34h-hmq5

больше 4 лет назад

The MediaTek hardware sensor driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28174490 and MediaTek internal bug ALPS02703105.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37mr-g2c4-w7wf

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB. This avoids a potential TOCTOU issue if the IB contents change between reads. (cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37mq-vvr9-ppr8

3 месяца назад

Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-37mq-hr48-xhmc

3 месяца назад

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-37mq-9v9g-wmfw

больше 4 лет назад

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

EPSS: Низкий
github логотип

GHSA-37mp-pj43-3c3x

больше 4 лет назад

Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.

EPSS: Низкий
github логотип

GHSA-37mp-2f5m-44h4

5 месяцев назад

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37mm-gc69-pw8r

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

EPSS: Низкий
github логотип

GHSA-37mm-fhp7-qvxr

12 месяцев назад

Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37mm-53pr-gqf6

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones Featured Image Thumbnail Grid allows Stored XSS. This issue affects Featured Image Thumbnail Grid: from n/a through 6.6.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37mj-rp29-9w5h

около 4 лет назад

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

EPSS: Низкий
github логотип

GHSA-37mj-c2wf-cx96

5 месяцев назад

Parse Server exposes auth data via /users/me endpoint

EPSS: Низкий
github логотип

GHSA-37mj-762c-hqp3

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster Elementor Addon jobmonster-addon allows PHP Local File Inclusion.This issue affects Jobmonster Elementor Addon: from n/a through <= 1.1.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37mj-2pf9-8q24

больше 4 лет назад

The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.

EPSS: Низкий
github логотип

GHSA-37mh-m4cp-8v5p

около 4 лет назад

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, an XML External Entity Injection vulnerability exists that allows an attacker to read or call arbitrary files from the license server and/or from the network and also block the license handling.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37mh-6cwh-pwc5

больше 4 лет назад

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

EPSS: Средний
github логотип

GHSA-37mg-956f-9m7p

больше 1 года назад

An issue in the dfe_unit_gb_dependant component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37mw-ccj4-5q2g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Email Notification on Login allows Stored XSS. This issue affects Email Notification on Login: from n/a through 1.6.1.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-37mw-44qp-f5jm

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-37mv-q3x5-3mwg

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-37mr-x34h-hmq5

The MediaTek hardware sensor driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28174490 and MediaTek internal bug ALPS02703105.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37mr-g2c4-w7wf

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length returned by vcn_v4_0_enc_find_ib_param() instead of rereading it from the IB. This avoids a potential TOCTOU issue if the IB contents change between reads. (cherry picked from commit dbb02b4755f8c1f3773263f2d779872c1c0c073a)

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-37mq-vvr9-ppr8

Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.8
0%
Низкий
3 месяца назад
github логотип
GHSA-37mq-hr48-xhmc

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.7
0%
Низкий
3 месяца назад
github логотип
GHSA-37mq-9v9g-wmfw

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-37mp-pj43-3c3x

Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37mp-2f5m-44h4

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-37mm-gc69-pw8r

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37mm-fhp7-qvxr

Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-37mm-53pr-gqf6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones Featured Image Thumbnail Grid allows Stored XSS. This issue affects Featured Image Thumbnail Grid: from n/a through 6.6.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-37mj-rp29-9w5h

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

0%
Низкий
около 4 лет назад
github логотип
GHSA-37mj-c2wf-cx96

Parse Server exposes auth data via /users/me endpoint

0%
Низкий
5 месяцев назад
github логотип
GHSA-37mj-762c-hqp3

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster Elementor Addon jobmonster-addon allows PHP Local File Inclusion.This issue affects Jobmonster Elementor Addon: from n/a through <= 1.1.4.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-37mj-2pf9-8q24

The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37mh-m4cp-8v5p

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, an XML External Entity Injection vulnerability exists that allows an attacker to read or call arbitrary files from the license server and/or from the network and also block the license handling.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-37mh-6cwh-pwc5

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

10%
Средний
больше 4 лет назад
github логотип
GHSA-37mg-956f-9m7p

An issue in the dfe_unit_gb_dependant component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу