Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-xxhf-v2m2-422x

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: sfc: fix TX channel offset when using legacy interrupts In legacy interrupt mode the tx_channel_offset was hardcoded to 1, but that's not correct if efx_sepparate_tx_channels is false. In that case, the offset is 0 because the tx queues are in the single existing channel at index 0, together with the rx queue. Without this fix, as soon as you try to send any traffic, it tries to get the tx queues from an uninitialized channel getting these errors: WARNING: CPU: 1 PID: 0 at drivers/net/ethernet/sfc/tx.c:540 efx_hard_start_xmit+0x12e/0x170 [sfc] [...] RIP: 0010:efx_hard_start_xmit+0x12e/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_start_xmit+0xd7/0x230 sch_direct_xmit+0x9f/0x360 __dev_queue_xmit+0x890/0xa40 [...] BUG: unable to handle kernel NULL pointer dereference at 0000000000000020 [...] RIP: 0010:efx_hard_start_xmit+0x153/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_star...

EPSS: Низкий
github логотип

GHSA-xxhf-rfmq-fqmc

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxhf-r9rq-5rj8

почти 3 года назад

Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxhf-g47w-wq3j

20 дней назад

Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxhc-wx4f-q7f9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php.

EPSS: Низкий
github логотип

GHSA-xxhc-h629-rhgx

11 месяцев назад

An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xxh9-gmrj-66fq

почти 4 года назад

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxh9-45q4-7wjc

7 месяцев назад

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxh7-3px8-x367

почти 3 года назад

A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. Affected by this issue is some unknown functionality of the file services/view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227702 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxh6-f3x3-2xgf

почти 3 года назад

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxh6-2g83-jp5x

28 дней назад

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxh5-92qj-c4gh

больше 3 лет назад

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxh4-gjrf-3883

почти 4 года назад

Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.

EPSS: Низкий
github логотип

GHSA-xxh4-727v-gjcv

6 месяцев назад

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xxh4-49r4-6rx5

около 4 лет назад

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxh2-qf6g-36xp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.

EPSS: Низкий
github логотип

GHSA-xxh2-9vx8-x442

5 месяцев назад

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxh2-5857-h7jc

около 2 месяцев назад

Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.50.07.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxgx-gq2c-x92j

больше 3 лет назад

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxgx-ggrx-m55g

больше 3 лет назад

In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-129475100

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxhf-v2m2-422x

In the Linux kernel, the following vulnerability has been resolved: sfc: fix TX channel offset when using legacy interrupts In legacy interrupt mode the tx_channel_offset was hardcoded to 1, but that's not correct if efx_sepparate_tx_channels is false. In that case, the offset is 0 because the tx queues are in the single existing channel at index 0, together with the rx queue. Without this fix, as soon as you try to send any traffic, it tries to get the tx queues from an uninitialized channel getting these errors: WARNING: CPU: 1 PID: 0 at drivers/net/ethernet/sfc/tx.c:540 efx_hard_start_xmit+0x12e/0x170 [sfc] [...] RIP: 0010:efx_hard_start_xmit+0x12e/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_start_xmit+0xd7/0x230 sch_direct_xmit+0x9f/0x360 __dev_queue_xmit+0x890/0xa40 [...] BUG: unable to handle kernel NULL pointer dereference at 0000000000000020 [...] RIP: 0010:efx_hard_start_xmit+0x153/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_star...

0%
Низкий
почти 2 года назад
github логотип
GHSA-xxhf-rfmq-fqmc

A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhf-r9rq-5rj8

Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxhf-g47w-wq3j

Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

CVSS3: 7.8
0%
Низкий
20 дней назад
github логотип
GHSA-xxhc-wx4f-q7f9

Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhc-h629-rhgx

An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

CVSS3: 6.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxh9-gmrj-66fq

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxh9-45q4-7wjc

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xxh7-3px8-x367

A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. Affected by this issue is some unknown functionality of the file services/view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227702 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxh6-f3x3-2xgf

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxh6-2g83-jp5x

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

CVSS3: 9.8
0%
Низкий
28 дней назад
github логотип
GHSA-xxh5-92qj-c4gh

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxh4-gjrf-3883

Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxh4-727v-gjcv

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVSS3: 8
9%
Низкий
6 месяцев назад
github логотип
GHSA-xxh4-49r4-6rx5

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxh2-qf6g-36xp

Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxh2-9vx8-x442

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxh2-5857-h7jc

Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.50.07.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xxgx-gq2c-x92j

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-xxgx-ggrx-m55g

In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-129475100

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу