Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-2qgw-f6xw-qj35

около 4 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to determine kernel memory layout.

EPSS: Низкий
github логотип

GHSA-2qgv-pgxc-xh7j

больше 4 лет назад

The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2qgv-chqp-r2q6

2 месяца назад

The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's comment-display setting via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2qgv-2cv4-g4cg

около 5 лет назад

Out-of-bounds write in ChakraCore

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qgr-rh75-r9jq

2 месяца назад

Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2qgr-m7c7-j745

3 месяца назад

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Field_Calculation class only validates the quantity field (.3) and completely ignores the product name field (.1), allowing malicious HTML to pass through validation. When the value is saved, the sanitize_entry_value() method returns the raw value without sanitization for fields where HTML is not expected. Subsequently, when an entry is viewed in wp-admin, the get_value_entry_detail() method concatenates the unescaped product name directly into the output string, which is then rendered by the repeater's get_value_entry_detail() method without further escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via form submissions that w...

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2qgr-gfvj-qpcr

11 месяцев назад

Dragonfly incorrectly handles a task structure’s usedTrac field

EPSS: Низкий
github логотип

GHSA-2qgr-4j3q-qhg6

около 4 лет назад

On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There is no control plane exposure, this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-2qgr-37h8-x3w9

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are expecting NULL returns from nfs_get_client() so this code will lead to an Oops. It's better to return an error pointer. I expect that this is dead code so hopefully no one is affected.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2qgq-6952-hvw2

больше 1 года назад

Missing Authorization vulnerability in VibeThemes WPLMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qgp-6j4f-cwcw

около 4 лет назад

Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2qgp-6c6g-cmwv

около 1 месяца назад

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2qgp-5cvv-jv79

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2qgm-x7hp-jc9q

около 4 лет назад

The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.

EPSS: Низкий
github логотип

GHSA-2qgm-m29m-cj2h

больше 1 года назад

uptime-kuma vulnerable to Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitor

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2qgh-j9vp-6pwj

больше 4 лет назад

SQL injection vulnerability in Spey before 0.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to MessageProcessor.cc and possibly other components.

EPSS: Низкий
github логотип

GHSA-2qgh-55fc-jw7c

почти 4 года назад

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qgh-37rm-mv6x

больше 1 года назад

Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may allow an attacker to shut down or otherwise impact the availability of the system. Note: BD Synapsys™ Informatics Solution is only in scope of this vulnerability when installed on a NUC server. BD Synapsys™ Informatics Solution installed on a customer-provided virtual machine or on the BD Kiestra™ SCU hardware is not in scope.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2qgg-rrhg-f2j5

около 4 лет назад

The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2qgg-rg5j-rxrv

около 4 лет назад

Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qgw-f6xw-qj35

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to determine kernel memory layout.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2qgv-pgxc-xh7j

The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2qgv-chqp-r2q6

The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's comment-display setting via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2qgv-2cv4-g4cg

Out-of-bounds write in ChakraCore

CVSS3: 7.5
9%
Низкий
около 5 лет назад
github логотип
GHSA-2qgr-rh75-r9jq

Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
0%
Низкий
2 месяца назад
github логотип
GHSA-2qgr-m7c7-j745

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Field_Calculation class only validates the quantity field (.3) and completely ignores the product name field (.1), allowing malicious HTML to pass through validation. When the value is saved, the sanitize_entry_value() method returns the raw value without sanitization for fields where HTML is not expected. Subsequently, when an entry is viewed in wp-admin, the get_value_entry_detail() method concatenates the unescaped product name directly into the output string, which is then rendered by the repeater's get_value_entry_detail() method without further escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via form submissions that w...

CVSS3: 7.2
0%
Низкий
3 месяца назад
github логотип
GHSA-2qgr-gfvj-qpcr

Dragonfly incorrectly handles a task structure’s usedTrac field

0%
Низкий
11 месяцев назад
github логотип
GHSA-2qgr-4j3q-qhg6

On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There is no control plane exposure, this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qgr-37h8-x3w9

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are expecting NULL returns from nfs_get_client() so this code will lead to an Oops. It's better to return an error pointer. I expect that this is dead code so hopefully no one is affected.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2qgq-6952-hvw2

Missing Authorization vulnerability in VibeThemes WPLMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2qgp-6j4f-cwcw

Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qgp-6c6g-cmwv

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2qgp-5cvv-jv79

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-2qgm-x7hp-jc9q

The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qgm-m29m-cj2h

uptime-kuma vulnerable to Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitor

CVSS3: 6.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-2qgh-j9vp-6pwj

SQL injection vulnerability in Spey before 0.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to MessageProcessor.cc and possibly other components.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2qgh-55fc-jw7c

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2qgh-37rm-mv6x

Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may allow an attacker to shut down or otherwise impact the availability of the system. Note: BD Synapsys™ Informatics Solution is only in scope of this vulnerability when installed on a NUC server. BD Synapsys™ Informatics Solution installed on a customer-provided virtual machine or on the BD Kiestra™ SCU hardware is not in scope.

CVSS3: 8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qgg-rrhg-f2j5

The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qgg-rg5j-rxrv

Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 7.8
0%
Низкий
около 4 лет назад

Уязвимостей на страницу