Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-32cc-x95p-fxcg

6 месяцев назад

FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration

EPSS: Низкий
github логотип

GHSA-32cc-f5gm-cv4r

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers allows SQL Injection. This issue affects Daisycon prijsvergelijkers: from n/a through 4.8.4.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-32c9-pf87-q237

около 4 лет назад

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.

EPSS: Низкий
github логотип

GHSA-32c9-9352-jvgc

8 месяцев назад

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-32c9-8jgc-9c8c

больше 4 лет назад

heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.

EPSS: Низкий
github логотип

GHSA-32c8-f69v-cf4f

больше 3 лет назад

Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32c8-2q94-9pqj

около 4 лет назад

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

EPSS: Низкий
github логотип

GHSA-32c7-mv5c-m5rr

больше 4 лет назад

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32c7-72q6-p3cg

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-32c6-pxw7-2477

около 4 лет назад

Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.

EPSS: Низкий
github логотип

GHSA-32c6-653x-x3pm

почти 4 года назад

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-32c5-v2g2-22x7

больше 2 лет назад

Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-32c5-q8cj-xx83

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: mhi: fix memory leak in mhi_mbim_dellink MHI driver registers network device without setting the needs_free_netdev flag, and does NOT call free_netdev() when unregisters network device, which causes a memory leak. This patch sets needs_free_netdev to true when registers network device, which makes netdev subsystem call free_netdev() automatically after unregister_netdevice().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32c4-v26c-m9ch

почти 3 года назад

A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32c4-pxr5-p8gv

около 1 года назад

Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-32c4-4mxh-crc8

около 3 лет назад

The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-32c3-w8ww-p5r9

больше 1 года назад

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument search leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-32c2-v3m4-9q5j

больше 4 лет назад

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-32c2-3jm4-f9rp

больше 4 лет назад

SQL injection vulnerability in the Myth download (myth_download) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-329x-vfj9-wrpq

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32cc-x95p-fxcg

FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration

1%
Низкий
6 месяцев назад
github логотип
GHSA-32cc-f5gm-cv4r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers allows SQL Injection. This issue affects Daisycon prijsvergelijkers: from n/a through 4.8.4.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-32c9-pf87-q237

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.

2%
Низкий
около 4 лет назад
github логотип
GHSA-32c9-9352-jvgc

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-32c9-8jgc-9c8c

heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-32c8-f69v-cf4f

Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32c8-2q94-9pqj

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

1%
Низкий
около 4 лет назад
github логотип
GHSA-32c7-mv5c-m5rr

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-32c7-72q6-p3cg

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

1%
Низкий
около 4 лет назад
github логотип
GHSA-32c6-pxw7-2477

Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inject arbitrary web script or HTML via the modhash parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-32c6-653x-x3pm

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-32c5-v2g2-22x7

Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32c5-q8cj-xx83

In the Linux kernel, the following vulnerability has been resolved: net: wwan: mhi: fix memory leak in mhi_mbim_dellink MHI driver registers network device without setting the needs_free_netdev flag, and does NOT call free_netdev() when unregisters network device, which causes a memory leak. This patch sets needs_free_netdev to true when registers network device, which makes netdev subsystem call free_netdev() automatically after unregister_netdevice().

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-32c4-v26c-m9ch

A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-32c4-pxr5-p8gv

Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

CVSS3: 6.5
1%
Низкий
около 1 года назад
github логотип
GHSA-32c4-4mxh-crc8

The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-32c3-w8ww-p5r9

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument search leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-32c2-v3m4-9q5j

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
github логотип
GHSA-32c2-3jm4-f9rp

SQL injection vulnerability in the Myth download (myth_download) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-329x-vfj9-wrpq

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу