Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34g8-9fpp-46ch

5 месяцев назад

Mattermost fails to limit the size of responses from integration action endpoints

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34g8-99rj-74rm

около 4 лет назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214770

EPSS: Низкий
github логотип

GHSA-34g8-8p3v-fxw2

4 месяца назад

A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation of the argument VEHICLE_ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-34g8-74vq-q8mf

больше 2 лет назад

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34g7-pg9j-pxgp

больше 1 года назад

Moodle allows IDOR when accessing the cohorts report

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34g7-gffm-5gm5

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and ru...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34g7-g5m3-mfmr

около 4 лет назад

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34g6-xv7x-r7fm

около 4 лет назад

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions for IPv4 or IPv6 packets that are received on the external management interface. An attacker could exploit these vulnerabilities by sending specific traffic to this interface on an affected device. A successful exploit could allow the attacker to access sensitive internal services and make configuration changes on the affected device.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-34g6-m4cp-w5c9

22 дня назад

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34g6-cvrg-j3q3

больше 1 года назад

Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-34g5-7wwm-mgrr

около 4 лет назад

The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service (device hang) by leveraging login access.

EPSS: Низкий
github логотип

GHSA-34g5-52c8-jghg

около 4 лет назад

Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

EPSS: Низкий
github логотип

GHSA-34g4-wcj4-64vj

около 4 лет назад

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34g4-3jrw-9qgp

больше 2 лет назад

lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34g3-9529-6r2w

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matiskiba Ravpage ravpage allows Reflected XSS.This issue affects Ravpage: from n/a through <= 2.33.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34g3-7wch-4ww8

20 дней назад

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-34g2-p88j-292j

около 4 лет назад

Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

EPSS: Средний
github логотип

GHSA-34g2-8x4r-2hc9

больше 4 лет назад

Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.

EPSS: Низкий
github логотип

GHSA-34fx-r4jh-7jxc

около 4 лет назад

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

EPSS: Низкий
github логотип

GHSA-34fw-v4pg-vc94

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34g8-9fpp-46ch

Mattermost fails to limit the size of responses from integration action endpoints

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-34g8-99rj-74rm

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214770

1%
Низкий
около 4 лет назад
github логотип
GHSA-34g8-8p3v-fxw2

A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation of the argument VEHICLE_ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-34g8-74vq-q8mf

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34g7-pg9j-pxgp

Moodle allows IDOR when accessing the cohorts report

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-34g7-gffm-5gm5

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and ru...

CVSS3: 5.3
2%
Низкий
почти 4 года назад
github логотип
GHSA-34g7-g5m3-mfmr

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-34g6-xv7x-r7fm

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions for IPv4 or IPv6 packets that are received on the external management interface. An attacker could exploit these vulnerabilities by sending specific traffic to this interface on an affected device. A successful exploit could allow the attacker to access sensitive internal services and make configuration changes on the affected device.

CVSS3: 8.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-34g6-m4cp-w5c9

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.

CVSS3: 7.1
0%
Низкий
22 дня назад
github логотип
GHSA-34g6-cvrg-j3q3

Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

CVSS3: 5.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-34g5-7wwm-mgrr

The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service (device hang) by leveraging login access.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34g5-52c8-jghg

Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34g4-wcj4-64vj

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-34g4-3jrw-9qgp

lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34g3-9529-6r2w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matiskiba Ravpage ravpage allows Reflected XSS.This issue affects Ravpage: from n/a through <= 2.33.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-34g3-7wch-4ww8

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
20 дней назад
github логотип
GHSA-34g2-p88j-292j

Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

19%
Средний
около 4 лет назад
github логотип
GHSA-34g2-8x4r-2hc9

Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-34fx-r4jh-7jxc

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

0%
Низкий
около 4 лет назад
github логотип
GHSA-34fw-v4pg-vc94

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу