Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3qpw-79h9-q4jc

больше 4 лет назад

IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3qpw-7686-5984

больше 4 лет назад

A Malformed Lua script can crash Redis

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3qpv-xf3v-mm45

6 месяцев назад

OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qpv-c5f2-gmjg

около 2 месяцев назад

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3qpv-49m3-3h75

почти 4 года назад

NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabilities can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qpv-3xc9-766w

больше 4 лет назад

Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

EPSS: Средний
github логотип

GHSA-3qpv-2q49-9qj8

больше 1 года назад

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qpr-v3fc-q5q5

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivileged load workaround Implement the workaround for ARM Cortex-A520 erratum 2966298. On an affected Cortex-A520 core, a speculatively executed unprivileged load might leak data from a privileged load via a cache side channel. The issue only exists for loads within a translation regime with the same translation (e.g. same ASID and VMID). Therefore, the issue only affects the return to EL0. The workaround is to execute a TLBI before returning to EL0 after all loads of privileged data. A non-shareable TLBI to any address is sufficient. The workaround isn't necessary if page table isolation (KPTI) is enabled, but for simplicity it will be. Page table isolation should normally be disabled for Cortex-A520 as it supports the CSV3 feature and the E0PD feature (used when KASLR is enabled).

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3qpr-rxgf-wxq6

больше 1 года назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3qpr-9m66-7297

12 месяцев назад

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single container allows direct access to internal services (HTTP, Redis, MySQL, etc.) on the overlay network. From a compromised container, an attacker can reach and exploit other services, enabling lateral movement, data theft, and system-wide compromise.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qpr-7rmg-73v8

около 8 лет назад

Plone and Zope2 affected by Race Condition

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qpq-w8fc-xx86

больше 4 лет назад

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qpq-r242-jqj7

5 месяцев назад

phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qpq-p293-rrm4

больше 3 лет назад

The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qpq-hc75-5535

почти 2 года назад

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qpq-9423-wfmq

больше 4 лет назад

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

EPSS: Низкий
github логотип

GHSA-3qpq-7p5h-2xmj

11 месяцев назад

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-3qpq-6w89-f7mx

больше 2 лет назад

Pimcore Host Header Injection in user invitation link

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qpq-4m92-9c3w

10 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3qpp-cfg4-r2ww

больше 4 лет назад

The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers to cause a denial of service (overflow, insufficient memory allocation, and segmentation fault) or possibly have unspecified other impact via a crafted mp4 file.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qpw-79h9-q4jc

IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qpw-7686-5984

A Malformed Lua script can crash Redis

CVSS3: 3.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qpv-xf3v-mm45

OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-3qpv-c5f2-gmjg

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3qpv-49m3-3h75

NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabilities can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3qpv-3xc9-766w

Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

15%
Средний
больше 4 лет назад
github логотип
GHSA-3qpv-2q49-9qj8

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qpr-v3fc-q5q5

In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivileged load workaround Implement the workaround for ARM Cortex-A520 erratum 2966298. On an affected Cortex-A520 core, a speculatively executed unprivileged load might leak data from a privileged load via a cache side channel. The issue only exists for loads within a translation regime with the same translation (e.g. same ASID and VMID). Therefore, the issue only affects the return to EL0. The workaround is to execute a TLBI before returning to EL0 after all loads of privileged data. A non-shareable TLBI to any address is sufficient. The workaround isn't necessary if page table isolation (KPTI) is enabled, but for simplicity it will be. Page table isolation should normally be disabled for Cortex-A520 as it supports the CSV3 feature and the E0PD feature (used when KASLR is enabled).

CVSS3: 4.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qpr-rxgf-wxq6

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qpr-9m66-7297

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single container allows direct access to internal services (HTTP, Redis, MySQL, etc.) on the overlay network. From a compromised container, an attacker can reach and exploit other services, enabling lateral movement, data theft, and system-wide compromise.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-3qpr-7rmg-73v8

Plone and Zope2 affected by Race Condition

CVSS3: 7.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-3qpq-w8fc-xx86

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qpq-r242-jqj7

phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3qpq-p293-rrm4

The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qpq-hc75-5535

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3qpq-9423-wfmq

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qpq-7p5h-2xmj

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

CVSS3: 5.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-3qpq-6w89-f7mx

Pimcore Host Header Injection in user invitation link

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qpq-4m92-9c3w

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.

CVSS3: 6.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-3qpp-cfg4-r2ww

The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers to cause a denial of service (overflow, insufficient memory allocation, and segmentation fault) or possibly have unspecified other impact via a crafted mp4 file.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу