Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-xxjx-gf9q-559x

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes Threads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or sc_send_wait can hang indefinitely in TASK_UNINTERRUPTIBLE state across transport teardown, pinning svc_xprt references and blocking svc_rdma_free(). The close path sets XPT_CLOSE before invoking xpo_detach and both wait_event predicates include an XPT_CLOSE term, but the predicates are re-evaluated only on wakeup. sc_sq_ticket_wait has no completion-driven wake path; it is advanced solely by the chained ticket handoff inside svc_rdma_sq_wait() itself. Without an explicit wake at close, parked threads never observe XPT_CLOSE, hold their svc_xprt_get reference forever, and svc_rdma_free() blocks on xpt_ref dropping to zero. Two close entry points reach this transport. Local teardown runs svc_rdma_detach() from svc_handle_xprt() -> svc_delete_xprt() -> xpo_detach() on a worker thread. A remote disconnect...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-vw5q-j33v

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxjw-qxjg-jpcw

4 месяца назад

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker can bypass authentication by supplying a crafted username (e.g. admin'--) or extract the full contents of the database including user credentials via UNION-based injection at the /search endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxjw-q2gq-6w22

больше 4 лет назад

Windows Kernel Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28309.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxjw-mqrg-2r3c

больше 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xxjw-jpj3-73mg

около 4 лет назад

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-jphq-5x96

больше 4 лет назад

The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

EPSS: Низкий
github логотип

GHSA-xxjw-fx2f-9c38

больше 1 года назад

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-6qx2-crcm

больше 4 лет назад

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxjv-vh49-qq33

больше 2 лет назад

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxjv-pwp6-p43h

больше 4 лет назад

The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

EPSS: Низкий
github логотип

GHSA-xxjv-9p3v-x2hv

больше 1 года назад

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjv-752h-3vp2

около 2 месяцев назад

Gitea: Public-only repository tokens can update private PR head branches

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xxjr-mmjv-4gpg

8 месяцев назад

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxjr-c99v-4h9c

около 3 лет назад

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxjm-jvw6-6mm7

больше 3 лет назад

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxjj-jhgc-r68f

больше 4 лет назад

Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter

EPSS: Низкий
github логотип

GHSA-xxjj-gr7j-h6p2

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue affects Fiorello: from n/a through <= 1.0.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xxjj-crx8-rwgg

больше 4 лет назад

mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

EPSS: Низкий
github логотип

GHSA-xxjj-3mqq-qmc5

больше 4 лет назад

hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxjx-gf9q-559x

In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes Threads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or sc_send_wait can hang indefinitely in TASK_UNINTERRUPTIBLE state across transport teardown, pinning svc_xprt references and blocking svc_rdma_free(). The close path sets XPT_CLOSE before invoking xpo_detach and both wait_event predicates include an XPT_CLOSE term, but the predicates are re-evaluated only on wakeup. sc_sq_ticket_wait has no completion-driven wake path; it is advanced solely by the chained ticket handoff inside svc_rdma_sq_wait() itself. Without an explicit wake at close, parked threads never observe XPT_CLOSE, hold their svc_xprt_get reference forever, and svc_rdma_free() blocks on xpt_ref dropping to zero. Two close entry points reach this transport. Local teardown runs svc_rdma_detach() from svc_handle_xprt() -> svc_delete_xprt() -> xpo_detach() on a worker thread. A remote disconnect...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xxjw-vw5q-j33v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxjw-qxjg-jpcw

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker can bypass authentication by supplying a crafted username (e.g. admin'--) or extract the full contents of the database including user credentials via UNION-based injection at the /search endpoint.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xxjw-q2gq-6w22

Windows Kernel Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28309.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxjw-mqrg-2r3c

Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.

CVSS3: 9.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxjw-jpj3-73mg

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxjw-jphq-5x96

The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxjw-fx2f-9c38

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxjw-6qx2-crcm

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxjv-vh49-qq33

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxjv-pwp6-p43h

The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxjv-9p3v-x2hv

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxjv-752h-3vp2

Gitea: Public-only repository tokens can update private PR head branches

CVSS3: 9.6
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xxjr-mmjv-4gpg

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

CVSS3: 6.5
2%
Низкий
8 месяцев назад
github логотип
GHSA-xxjr-c99v-4h9c

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxjm-jvw6-6mm7

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxjj-jhgc-r68f

Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxjj-gr7j-h6p2

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue affects Fiorello: from n/a through <= 1.0.

CVSS3: 8.1
1%
Низкий
7 месяцев назад
github логотип
GHSA-xxjj-crx8-rwgg

mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xxjj-3mqq-qmc5

hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу