Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-3v3x-mvj6-m5jc

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v3x-cm3g-974v

больше 4 лет назад

** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue.

EPSS: Низкий
github логотип

GHSA-3v3q-h6jq-r694

27 дней назад

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3v3q-fq2w-23r5

11 месяцев назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3v3p-g3ch-4rcq

больше 2 лет назад

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3v3p-5qg2-fr76

больше 4 лет назад

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

EPSS: Низкий
github логотип

GHSA-3v3m-wc6v-x4x3

5 месяцев назад

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3v3m-pj2m-g57g

20 дней назад

Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v3m-cp4r-m942

больше 4 лет назад

Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

EPSS: Низкий
github логотип

GHSA-3v3m-75mh-5x2r

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: iommu: Clear iommu-dma ops on cleanup If iommu_device_register() encounters an error, it can end up tearing down already-configured groups and default domains, however this currently still leaves devices hooked up to iommu-dma (and even historically the behaviour in this area was at best inconsistent across architectures/drivers...) Although in the case that an IOMMU is present whose driver has failed to probe, users cannot necessarily expect DMA to work anyway, it's still arguable that we should do our best to put things back as if the IOMMU driver was never there at all, and certainly the potential for crashing in iommu-dma itself is undesirable. Make sure we clean up the dev->dma_iommu flag along with everything else.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v3j-hr3p-qv6j

больше 4 лет назад

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v3j-737j-7g74

3 месяца назад

Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3v3h-r6wq-rvgg

больше 2 лет назад

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-3v3h-h6x7-96rv

больше 4 лет назад

In ip6_xmit of ip6_output.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168607263References: Upstream kernel

EPSS: Низкий
github логотип

GHSA-3v3h-h6m5-g9w5

больше 4 лет назад

ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in a header.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v3g-wjq6-79v9

больше 4 лет назад

The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.

EPSS: Низкий
github логотип

GHSA-3v3g-3pf9-fgcf

1 день назад

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v3f-r75q-x3fq

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BurgerThemes StoreBiz allows DOM-Based XSS.This issue affects StoreBiz: from n/a through 1.0.32.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v3f-g56p-vw6w

13 дней назад

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3v3f-887c-p9f4

около 1 месяца назад

Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v3x-mvj6-m5jc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3v3x-cm3g-974v

** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3q-h6jq-r694

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android File Copy Routine. The manipulation of the argument _display_name results in path traversal. The attack requires a local approach. Upgrading to version 8.0.1 is able to mitigate this issue. The patch is identified as c6900b1ed06fcc3ca4b09651348974ac5b95e4e6. The affected component should be upgraded.

CVSS3: 4.4
0%
Низкий
27 дней назад
github логотип
GHSA-3v3q-fq2w-23r5

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

CVSS3: 9.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-3v3p-g3ch-4rcq

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v3p-5qg2-fr76

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3m-wc6v-x4x3

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

CVSS3: 9.6
1%
Низкий
5 месяцев назад
github логотип
GHSA-3v3m-pj2m-g57g

Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 7.5
0%
Низкий
20 дней назад
github логотип
GHSA-3v3m-cp4r-m942

Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3m-75mh-5x2r

In the Linux kernel, the following vulnerability has been resolved: iommu: Clear iommu-dma ops on cleanup If iommu_device_register() encounters an error, it can end up tearing down already-configured groups and default domains, however this currently still leaves devices hooked up to iommu-dma (and even historically the behaviour in this area was at best inconsistent across architectures/drivers...) Although in the case that an IOMMU is present whose driver has failed to probe, users cannot necessarily expect DMA to work anyway, it's still arguable that we should do our best to put things back as if the IOMMU driver was never there at all, and certainly the potential for crashing in iommu-dma itself is undesirable. Make sure we clean up the dev->dma_iommu flag along with everything else.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3v3j-hr3p-qv6j

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3j-737j-7g74

Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns

CVSS3: 8.3
3 месяца назад
github логотип
GHSA-3v3h-r6wq-rvgg

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
27%
Средний
больше 2 лет назад
github логотип
GHSA-3v3h-h6x7-96rv

In ip6_xmit of ip6_output.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168607263References: Upstream kernel

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3h-h6m5-g9w5

ReadWEBPImage in coders/webp.c in ImageMagick 7.0.6-5 has an issue where memory allocation is excessive because it depends only on a length field in a header.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3g-wjq6-79v9

The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3v3g-3pf9-fgcf

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

CVSS3: 7.5
0%
Низкий
1 день назад
github логотип
GHSA-3v3f-r75q-x3fq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BurgerThemes StoreBiz allows DOM-Based XSS.This issue affects StoreBiz: from n/a through 1.0.32.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3v3f-g56p-vw6w

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

CVSS3: 8.4
0%
Низкий
13 дней назад
github логотип
GHSA-3v3f-887c-p9f4

Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу