Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 347 891

Количество 347 891

github логотип

GHSA-2crp-r6g2-9c5p

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix memory leak in ipc_wwan_dellink IOSM driver registers network device without setting the needs_free_netdev flag, and does NOT call free_netdev() when unregisters network device, which causes a memory leak. This patch sets needs_free_netdev to true when registers network device, which makes netdev subsystem call free_netdev() automatically after unregister_netdevice().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2crp-qj3p-4444

почти 2 года назад

Windows DNS Spoofing Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2crp-c7w4-2c48

почти 2 года назад

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() function in all versions up to, and including, 5.0.48. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the booking form's CSS.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2crp-9jmr-vp26

больше 4 лет назад

Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.

EPSS: Низкий
github логотип

GHSA-2crm-qxx4-6cp4

около 4 лет назад

u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer device.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in QCA6390, QCN7605, QCS404, SA415M, SA515M, SC8180X, SDX55, SM8250

EPSS: Низкий
github логотип

GHSA-2crj-6275-fwfr

около 4 лет назад

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

EPSS: Низкий
github логотип

GHSA-2crj-4cj6-f7cw

около 4 лет назад

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2crh-r3wq-qg9g

около 4 лет назад

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2crh-j3fx-xcfh

больше 4 лет назад

Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2crh-858w-x2v9

больше 4 лет назад

SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page.

EPSS: Низкий
github логотип

GHSA-2crh-849q-gg8v

больше 4 лет назад

Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2crg-hfx3-g5gv

больше 4 лет назад

Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.

EPSS: Низкий
github логотип

GHSA-2crg-3p73-43xp

4 месяца назад

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

EPSS: Низкий
github логотип

GHSA-2crf-qc6j-j2rv

12 месяцев назад

Substance3D - Viewer versions 0.25 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2crf-gcjf-2wmp

около 4 лет назад

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

EPSS: Низкий
github логотип

GHSA-2crf-7pw9-c88r

3 месяца назад

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2crc-x37f-94vp

больше 4 лет назад

The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.

EPSS: Низкий
github логотип

GHSA-2crc-fjgx-mwvq

около 4 лет назад

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-2crc-5vq6-386r

около 4 лет назад

Magento 2 Community Edition RCE Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2cr9-jmh7-jr7x

около 2 лет назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2crp-r6g2-9c5p

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix memory leak in ipc_wwan_dellink IOSM driver registers network device without setting the needs_free_netdev flag, and does NOT call free_netdev() when unregisters network device, which causes a memory leak. This patch sets needs_free_netdev to true when registers network device, which makes netdev subsystem call free_netdev() automatically after unregister_netdevice().

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2crp-qj3p-4444

Windows DNS Spoofing Vulnerability

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-2crp-c7w4-2c48

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() function in all versions up to, and including, 5.0.48. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the booking form's CSS.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2crp-9jmr-vp26

Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2crm-qxx4-6cp4

u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer device.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in QCA6390, QCN7605, QCS404, SA415M, SA515M, SC8180X, SDX55, SM8250

0%
Низкий
около 4 лет назад
github логотип
GHSA-2crj-6275-fwfr

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2crj-4cj6-f7cw

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2crh-r3wq-qg9g

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2crh-j3fx-xcfh

Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2crh-858w-x2v9

SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2crh-849q-gg8v

Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2crg-hfx3-g5gv

Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-2crg-3p73-43xp

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

1%
Низкий
4 месяца назад
github логотип
GHSA-2crf-qc6j-j2rv

Substance3D - Viewer versions 0.25 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2crf-gcjf-2wmp

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2crf-7pw9-c88r

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2crc-x37f-94vp

The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-2crc-fjgx-mwvq

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

25%
Средний
около 4 лет назад
github логотип
GHSA-2crc-5vq6-386r

Magento 2 Community Edition RCE Vulnerability

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2cr9-jmh7-jr7x

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу