Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2v74-gvxm-8wmq

около 4 лет назад

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v74-9vqm-pm8p

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace fw->size by m3_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.

EPSS: Низкий
github логотип

GHSA-2v73-9rwq-75qc

больше 4 лет назад

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

EPSS: Низкий
github логотип

GHSA-2v73-958c-qpgj

около 2 месяцев назад

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v73-62r7-82cv

больше 4 лет назад

SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.

EPSS: Низкий
github логотип

GHSA-2v72-mg9p-jmxc

17 дней назад

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v72-cqvg-78vr

около 4 лет назад

SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login.

EPSS: Низкий
github логотип

GHSA-2v6x-frw8-7r7f

около 5 лет назад

Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v6w-2mr8-f976

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

EPSS: Низкий
github логотип

GHSA-2v6v-q994-xvxx

больше 4 лет назад

Privilege escalation in beego

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2v6v-j3q5-hq45

около 4 лет назад

There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

EPSS: Низкий
github логотип

GHSA-2v6r-qcvm-x943

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond setting the rlimit. Refactor the code so its clear when what code is setting the limit and conditionally update the posix cpu timers when appropriate.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2v6r-jf2g-j5q5

около 4 лет назад

Cross-site Scripting in Jenkins Rich Text Publisher Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2v6m-6xw3-6467

5 месяцев назад

Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users

EPSS: Низкий
github логотип

GHSA-2v6m-48p8-wjx7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2v6m-44mf-8673

больше 4 лет назад

Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.

EPSS: Низкий
github логотип

GHSA-2v6j-q8j6-q6m9

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v6j-6m6r-28qj

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.

EPSS: Низкий
github логотип

GHSA-2v6h-6jq5-f6mw

около 4 лет назад

PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v6h-53v9-2vvc

около 2 лет назад

Improper Privilege Management vulnerability in DeluxeThemes Userpro allows Privilege Escalation.This issue affects Userpro: from n/a through 5.1.8.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v74-gvxm-8wmq

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

CVSS3: 8.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-2v74-9vqm-pm8p

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace fw->size by m3_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.

0%
Низкий
10 месяцев назад
github логотип
GHSA-2v73-9rwq-75qc

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2v73-958c-qpgj

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-2v73-62r7-82cv

SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v72-mg9p-jmxc

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
17 дней назад
github логотип
GHSA-2v72-cqvg-78vr

SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v6x-frw8-7r7f

Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information

CVSS3: 6.5
около 5 лет назад
github логотип
GHSA-2v6w-2mr8-f976

Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v6v-q994-xvxx

Privilege escalation in beego

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2v6v-j3q5-hq45

There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v6r-qcvm-x943

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond setting the rlimit. Refactor the code so its clear when what code is setting the limit and conditionally update the posix cpu timers when appropriate.

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2v6r-jf2g-j5q5

Cross-site Scripting in Jenkins Rich Text Publisher Plugin

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2v6m-6xw3-6467

Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users

0%
Низкий
5 месяцев назад
github логотип
GHSA-2v6m-48p8-wjx7

Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v6m-44mf-8673

Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2v6j-q8j6-q6m9

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v6j-6m6r-28qj

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v6h-6jq5-f6mw

PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2v6h-53v9-2vvc

Improper Privilege Management vulnerability in DeluxeThemes Userpro allows Privilege Escalation.This issue affects Userpro: from n/a through 5.1.8.

CVSS3: 9.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу