Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-2w8h-77mr-j4fw

больше 4 лет назад

Microsoft PowerShell Spoofing Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2w8g-v9pc-7jpq

больше 4 лет назад

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w8g-m5j8-7m87

больше 4 лет назад

Zalgo-like output that crashes the server

EPSS: Низкий
github логотип

GHSA-2w8f-9fpf-qq4v

около 4 лет назад

sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2w8f-25gq-9g77

больше 2 лет назад

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2w8c-hj6v-28vw

около 3 лет назад

A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2w89-g5fw-9c76

больше 4 лет назад

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.

EPSS: Низкий
github логотип

GHSA-2w89-7wx5-gppj

около 4 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.

EPSS: Низкий
github логотип

GHSA-2w89-5px3-fvx6

больше 1 года назад

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

EPSS: Низкий
github логотип

GHSA-2w88-g477-cxmj

9 дней назад

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2w88-9jch-6jfv

около 4 лет назад

omx/SimpleSoftOMXComponent.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not prevent input-port changes, which allows attackers to gain privileges via a crafted application, aka internal bug 29421804.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2w88-4wpv-5768

больше 1 года назад

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2w87-fjj9-j39h

больше 2 лет назад

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2w87-6hh6-mqrj

больше 2 лет назад

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have the intended permissions. If you’re not using Windows or haven’t changed the temporary directory location then you aren’t affected by this vulnerability. On other platforms the returned directory is consistently readable and writable only by the current user. This issue was caused by Python not supporting Unix permissions on Windows. The fix adds support for Unix “700” for the mkdir function on Windows which is used by mkdtemp() to ensure the newly created directory has the proper permissions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2w87-5qcj-j6gx

около 4 лет назад

OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image

EPSS: Низкий
github логотип

GHSA-2w86-wv37-w7h5

больше 2 лет назад

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w86-r6rm-76wr

8 месяцев назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in uixthemes Sober sober allows Retrieve Embedded Sensitive Data.This issue affects Sober: from n/a through <= 3.5.11.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2w86-q89h-9668

больше 4 лет назад

Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

EPSS: Средний
github логотип

GHSA-2w86-3xc7-pmwq

около 4 лет назад

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2w86-3rvw-q3cw

12 месяцев назад

Missing Authorization vulnerability in VeronaLabs WP Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Statistics: from n/a through 14.15.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2w8h-77mr-j4fw

Microsoft PowerShell Spoofing Vulnerability

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2w8g-v9pc-7jpq

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2w8g-m5j8-7m87

Zalgo-like output that crashes the server

больше 4 лет назад
github логотип
GHSA-2w8f-9fpf-qq4v

sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.

CVSS3: 6.2
0%
Низкий
около 4 лет назад
github логотип
GHSA-2w8f-25gq-9g77

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2w8c-hj6v-28vw

A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2w89-g5fw-9c76

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2w89-7wx5-gppj

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2w89-5px3-fvx6

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

1%
Низкий
больше 1 года назад
github логотип
GHSA-2w88-g477-cxmj

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.

CVSS3: 3.7
0%
Низкий
9 дней назад
github логотип
GHSA-2w88-9jch-6jfv

omx/SimpleSoftOMXComponent.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not prevent input-port changes, which allows attackers to gain privileges via a crafted application, aka internal bug 29421804.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2w88-4wpv-5768

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2w87-fjj9-j39h

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2w87-6hh6-mqrj

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have the intended permissions. If you’re not using Windows or haven’t changed the temporary directory location then you aren’t affected by this vulnerability. On other platforms the returned directory is consistently readable and writable only by the current user. This issue was caused by Python not supporting Unix permissions on Windows. The fix adds support for Unix “700” for the mkdir function on Windows which is used by mkdtemp() to ensure the newly created directory has the proper permissions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2w87-5qcj-j6gx

OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image

0%
Низкий
около 4 лет назад
github логотип
GHSA-2w86-wv37-w7h5

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2w86-r6rm-76wr

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in uixthemes Sober sober allows Retrieve Embedded Sensitive Data.This issue affects Sober: from n/a through <= 3.5.11.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2w86-q89h-9668

Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

19%
Средний
больше 4 лет назад
github логотип
GHSA-2w86-3xc7-pmwq

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2w86-3rvw-q3cw

Missing Authorization vulnerability in VeronaLabs WP Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Statistics: from n/a through 14.15.

CVSS3: 4.3
0%
Низкий
12 месяцев назад

Уязвимостей на страницу