Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33g4-2m49-x49h

больше 2 лет назад

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor level access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33g3-x95c-mp5m

больше 1 года назад

Rejected reason: withdraw

EPSS: Низкий
github логотип

GHSA-33g3-59w3-q9cj

около 4 лет назад

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3510.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-33g2-mrr9-4jv5

около 1 года назад

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. This issue affects some unknown processing of the file /intranet/educar_usuario_lst.php. The manipulation of the argument nm_pessoa/matricula/matricula_interna leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-33g2-gx67-c2h3

2 месяца назад

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33g2-9gvg-pqfw

около 4 лет назад

Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33g2-5xpr-jrcj

около 4 лет назад

SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

EPSS: Низкий
github логотип

GHSA-33fw-w4q9-fhpq

19 дней назад

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-33fw-34vg-hgjh

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like 0xFFF0 and a reasonable length for a fragment. In the sanity check as formulated now, this will create an integer overflow, defeating the sanity check. Both offset and offset + len need to be checked in such a manner that no overflow can occur. And those quantities should be unsigned.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33fr-rpxm-q4fp

больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33fr-2jgq-xxjj

около 4 лет назад

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-10031.

EPSS: Низкий
github логотип

GHSA-33fq-qm4m-cjw3

около 4 лет назад

baserCMS Access Control Bypass

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33fq-h3x2-m8v9

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf sixpack_receive_buf() does not properly skip bytes with TTY error flags. The while loop iterates through the flags buffer but never advances the data pointer (cp), and passes the original count (including error bytes) to sixpack_decode(). This causes sixpack_decode() to process bytes that should have been skipped due to TTY errors. The TTY layer does not guarantee that cp[i] holds a meaningful value when fp[i] is set, so passing those positions to sixpack_decode() results in KMSAN reporting an uninit-value read. Fix this by processing bytes one at a time, advancing cp on each iteration, and only passing valid (non-error) bytes to sixpack_decode(). This matches the pattern used by slip_receive_buf() and mkiss_receive_buf() for the same purpose.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33fq-cj88-4v27

почти 3 года назад

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33fp-rvp9-r3r8

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Disqus Conditional Load plugin <= 11.0.6 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-33fp-fhhx-5667

около 4 лет назад

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overwrite may occur in ProcSetReqInternal() due to missing length check.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33fm-9xj7-6vfq

около 4 лет назад

SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-33fm-6gp7-4p47

6 месяцев назад

Weblate has an argument injection in management console

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-33fj-x2h7-rxj3

больше 4 лет назад

Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

EPSS: Низкий
github логотип

GHSA-33fh-jhp9-q8w6

около 3 лет назад

Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33g4-2m49-x49h

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor level access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33g3-x95c-mp5m

Rejected reason: withdraw

больше 1 года назад
github логотип
GHSA-33g3-59w3-q9cj

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3510.

CVSS3: 9.8
20%
Средний
около 4 лет назад
github логотип
GHSA-33g2-mrr9-4jv5

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. This issue affects some unknown processing of the file /intranet/educar_usuario_lst.php. The manipulation of the argument nm_pessoa/matricula/matricula_interna leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-33g2-gx67-c2h3

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-33g2-9gvg-pqfw

Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-33g2-5xpr-jrcj

SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33fw-w4q9-fhpq

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

CVSS3: 5
0%
Низкий
19 дней назад
github логотип
GHSA-33fw-34vg-hgjh

In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like 0xFFF0 and a reasonable length for a fragment. In the sanity check as formulated now, this will create an integer overflow, defeating the sanity check. Both offset and offset + len need to be checked in such a manner that no overflow can occur. And those quantities should be unsigned.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-33fr-rpxm-q4fp

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33fr-2jgq-xxjj

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-10031.

0%
Низкий
около 4 лет назад
github логотип
GHSA-33fq-qm4m-cjw3

baserCMS Access Control Bypass

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-33fq-h3x2-m8v9

In the Linux kernel, the following vulnerability has been resolved: net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf sixpack_receive_buf() does not properly skip bytes with TTY error flags. The while loop iterates through the flags buffer but never advances the data pointer (cp), and passes the original count (including error bytes) to sixpack_decode(). This causes sixpack_decode() to process bytes that should have been skipped due to TTY errors. The TTY layer does not guarantee that cp[i] holds a meaningful value when fp[i] is set, so passing those positions to sixpack_decode() results in KMSAN reporting an uninit-value read. Fix this by processing bytes one at a time, advancing cp on each iteration, and only passing valid (non-error) bytes to sixpack_decode(). This matches the pattern used by slip_receive_buf() and mkiss_receive_buf() for the same purpose.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-33fq-cj88-4v27

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-33fp-rvp9-r3r8

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Disqus Conditional Load plugin <= 11.0.6 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-33fp-fhhx-5667

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overwrite may occur in ProcSetReqInternal() due to missing length check.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-33fm-9xj7-6vfq

SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33fm-6gp7-4p47

Weblate has an argument injection in management console

CVSS3: 6.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-33fj-x2h7-rxj3

Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-33fh-jhp9-q8w6

Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

CVSS3: 6.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу