Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-349j-652r-ghg9

больше 4 лет назад

The Clear Channel Assessment (CCA) algorithm in the IEEE 802.11 wireless protocol, when using DSSS transmission encoding, allows remote attackers to cause a denial of service via a certain RF signal that causes a channel to appear busy (aka "jabber"), which prevents devices from transmitting data.

EPSS: Низкий
github логотип

GHSA-349h-vrrw-f3cp

больше 1 года назад

IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-349h-phx6-ghfj

около 4 лет назад

A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-349h-m66g-cww7

больше 4 лет назад

SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

EPSS: Низкий
github логотип

GHSA-349h-ggfr-h55v

15 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-349g-pr27-x5hf

больше 4 лет назад

DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

EPSS: Низкий
github логотип

GHSA-349c-6q2h-wwhm

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-349c-4hpx-25pr

около 4 лет назад

The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-349c-2h2f-mxf6

4 месяца назад

Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3499-p3c4-fxgm

около 4 лет назад

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-3499-h62c-hg29

около 4 лет назад

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was redacted for privacy. This has been fixed (in 5.5.4 and 6.0.1) so that usernames are tagged properly in the logs and are hashed out when the logs are redacted.

EPSS: Низкий
github логотип

GHSA-3499-gp69-ggq6

около 4 лет назад

The mintToken function of a smart contract implementation for SemainToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3498-94v2-7qqw

около 4 лет назад

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3497-8jvc-w33p

больше 4 лет назад

Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.

EPSS: Низкий
github логотип

GHSA-3496-pjp5-xxqp

почти 4 года назад

An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes messages were not properly escaped and allowed for users to inject HTML and JavaScript.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3496-jvg8-8254

больше 4 лет назад

The Webgais program allows a remote user to execute arbitrary commands.

EPSS: Низкий
github логотип

GHSA-3496-765w-5xgq

около 4 лет назад

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. One can escape from a shell and acquire root privileges by leveraging the TFTP download configuration.

EPSS: Низкий
github логотип

GHSA-3495-g4f4-35vh

10 месяцев назад

A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing manipulation of the argument pid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3494-rgjv-74f5

около 4 лет назад

Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via vectors related to a dialog box.

EPSS: Низкий
github логотип

GHSA-3494-cfwf-56hw

больше 2 лет назад

mdanter/ecc affected by timing vulnerability in cryptographic side-channels

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-349j-652r-ghg9

The Clear Channel Assessment (CCA) algorithm in the IEEE 802.11 wireless protocol, when using DSSS transmission encoding, allows remote attackers to cause a denial of service via a certain RF signal that causes a channel to appear busy (aka "jabber"), which prevents devices from transmitting data.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-349h-vrrw-f3cp

IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-349h-phx6-ghfj

A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-349h-m66g-cww7

SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-349h-ggfr-h55v

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.

CVSS3: 4.3
0%
Низкий
15 дней назад
github логотип
GHSA-349g-pr27-x5hf

DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-349c-6q2h-wwhm

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

CVSS3: 9.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-349c-4hpx-25pr

The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.

CVSS3: 8.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-349c-2h2f-mxf6

Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3499-p3c4-fxgm

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

CVSS3: 9.1
60%
Средний
около 4 лет назад
github логотип
GHSA-3499-h62c-hg29

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was redacted for privacy. This has been fixed (in 5.5.4 and 6.0.1) so that usernames are tagged properly in the logs and are hashed out when the logs are redacted.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3499-gp69-ggq6

The mintToken function of a smart contract implementation for SemainToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3498-94v2-7qqw

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVSS3: 6.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-3497-8jvc-w33p

Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3496-pjp5-xxqp

An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes messages were not properly escaped and allowed for users to inject HTML and JavaScript.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-3496-jvg8-8254

The Webgais program allows a remote user to execute arbitrary commands.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3496-765w-5xgq

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. One can escape from a shell and acquire root privileges by leveraging the TFTP download configuration.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3495-g4f4-35vh

A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing manipulation of the argument pid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3494-rgjv-74f5

Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via vectors related to a dialog box.

4%
Низкий
около 4 лет назад
github логотип
GHSA-3494-cfwf-56hw

mdanter/ecc affected by timing vulnerability in cryptographic side-channels

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу