Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 344 475

Количество 344 475

github логотип

GHSA-26jh-3pw8-9r3f

около 4 лет назад

The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26jh-23q3-rwhv

почти 4 года назад

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26jg-rrff-qqvf

около 4 лет назад

FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.

EPSS: Низкий
github логотип

GHSA-26jg-m265-j4mh

около 4 лет назад

An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.

EPSS: Низкий
github логотип

GHSA-26jg-9qwc-5jwv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.

EPSS: Низкий
github логотип

GHSA-26jg-99jv-7wgw

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: akcipher - default implementation for setting a private key Changes from v1: * removed the default implementation from set_pub_key: it is assumed that an implementation must always have this callback defined as there are no use case for an algorithm, which doesn't need a public key Many akcipher implementations (like ECDSA) support only signature verifications, so they don't have all callbacks defined. Commit 78a0324f4a53 ("crypto: akcipher - default implementations for request callbacks") introduced default callbacks for sign/verify operations, which just return an error code. However, these are not enough, because before calling sign the caller would likely call set_priv_key first on the instantiated transform (as the in-kernel testmgr does). This function does not have a default stub, so the kernel crashes, when trying to set a private key on an akcipher, which doesn't support signature gen...

EPSS: Низкий
github логотип

GHSA-26jg-59fg-3j5v

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php.

EPSS: Низкий
github логотип

GHSA-26jg-48xv-2wqr

около 4 лет назад

An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.

EPSS: Низкий
github логотип

GHSA-26jf-v4w3-xhqx

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: media: iris: Add buffer to list only after successful allocation Move `list_add_tail()` to after `dma_alloc_attrs()` succeeds when creating internal buffers. Previously, the buffer was enqueued in `buffers->list` before the DMA allocation. If the allocation failed, the function returned `-ENOMEM` while leaving a partially initialized buffer in the list, which could lead to inconsistent state and potential leaks. By adding the buffer to the list only after `dma_alloc_attrs()` succeeds, we ensure the list contains only valid, fully initialized buffers.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26jf-gmgg-9m8f

около 4 лет назад

The Elementor Website Builder WordPress plugin before 3.1.4 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue

EPSS: Средний
github логотип

GHSA-26jc-rvr3-77x3

около 4 лет назад

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-26jc-h8ww-vpqm

8 месяцев назад

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-26jc-6p9c-5pc3

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check allows Cross Site Request Forgery. This issue affects WP Spell Check: from n/a through 9.21.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26jc-3hwx-x659

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Fusion allows Stored XSS.This issue affects Fusion: from n/a through 1.6.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26jc-2mw8-4jp3

около 4 лет назад

All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26j9-qcx5-q7g6

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26j9-g42j-hj28

около 2 лет назад

A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an unknown function of the file /admin/category_save.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273144.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-26j8-73j7-ppfr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.

EPSS: Низкий
github логотип

GHSA-26j8-6884-fcqw

около 4 лет назад

A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affected devices improperly handles excessive ARP broadcast requests. This could allow an attacker to create a denial of service condition by performing ARP storming attacks, which can cause the device to reboot.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26j8-22rg-rw9p

больше 4 лет назад

Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26jh-3pw8-9r3f

The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-26jh-23q3-rwhv

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-26jg-rrff-qqvf

FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26jg-m265-j4mh

An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-26jg-9qwc-5jwv

Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-26jg-99jv-7wgw

In the Linux kernel, the following vulnerability has been resolved: crypto: akcipher - default implementation for setting a private key Changes from v1: * removed the default implementation from set_pub_key: it is assumed that an implementation must always have this callback defined as there are no use case for an algorithm, which doesn't need a public key Many akcipher implementations (like ECDSA) support only signature verifications, so they don't have all callbacks defined. Commit 78a0324f4a53 ("crypto: akcipher - default implementations for request callbacks") introduced default callbacks for sign/verify operations, which just return an error code. However, these are not enough, because before calling sign the caller would likely call set_priv_key first on the instantiated transform (as the in-kernel testmgr does). This function does not have a default stub, so the kernel crashes, when trying to set a private key on an akcipher, which doesn't support signature gen...

0%
Низкий
7 месяцев назад
github логотип
GHSA-26jg-59fg-3j5v

Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-26jg-48xv-2wqr

An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26jf-v4w3-xhqx

In the Linux kernel, the following vulnerability has been resolved: media: iris: Add buffer to list only after successful allocation Move `list_add_tail()` to after `dma_alloc_attrs()` succeeds when creating internal buffers. Previously, the buffer was enqueued in `buffers->list` before the DMA allocation. If the allocation failed, the function returned `-ENOMEM` while leaving a partially initialized buffer in the list, which could lead to inconsistent state and potential leaks. By adding the buffer to the list only after `dma_alloc_attrs()` succeeds, we ensure the list contains only valid, fully initialized buffers.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-26jf-gmgg-9m8f

The Elementor Website Builder WordPress plugin before 3.1.4 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue

24%
Средний
около 4 лет назад
github логотип
GHSA-26jc-rvr3-77x3

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

CVSS3: 8.8
30%
Средний
около 4 лет назад
github логотип
GHSA-26jc-h8ww-vpqm

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

CVSS3: 8.1
1%
Низкий
8 месяцев назад
github логотип
GHSA-26jc-6p9c-5pc3

Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check allows Cross Site Request Forgery. This issue affects WP Spell Check: from n/a through 9.21.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-26jc-3hwx-x659

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Fusion allows Stored XSS.This issue affects Fusion: from n/a through 1.6.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-26jc-2mw8-4jp3

All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-26j9-qcx5-q7g6

Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-26j9-g42j-hj28

A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an unknown function of the file /admin/category_save.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273144.

CVSS3: 4.7
1%
Низкий
около 2 лет назад
github логотип
GHSA-26j8-73j7-ppfr

Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-26j8-6884-fcqw

A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affected devices improperly handles excessive ARP broadcast requests. This could allow an attacker to create a denial of service condition by performing ARP storming attacks, which can cause the device to reboot.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-26j8-22rg-rw9p

Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу