Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3qmm-r55x-hpxx

8 месяцев назад

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qmj-w8xr-h39r

больше 4 лет назад

Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."

EPSS: Низкий
github логотип

GHSA-3qmj-w5mh-5gv3

больше 2 лет назад

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qmj-rc63-mhjw

5 месяцев назад

A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qmj-qw66-fwx8

4 месяца назад

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out of bound (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap-OOB-WRITE would be triggered which could have Remote Code Execution (RCE) potential.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qmj-gxp7-229g

больше 4 лет назад

SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

EPSS: Низкий
github логотип

GHSA-3qmj-8cpx-9xxp

больше 4 лет назад

VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.

EPSS: Низкий
github логотип

GHSA-3qmh-69j2-8hj7

больше 4 лет назад

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

EPSS: Низкий
github логотип

GHSA-3qmg-wxq2-g22p

почти 3 года назад

Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qmg-c9vc-r47j

больше 4 лет назад

Mercurial is vulnerable to shell injection attack

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qmg-867g-8xrq

почти 3 года назад

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qmf-g4j6-v744

17 дней назад

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qmf-fj65-6vmf

больше 2 лет назад

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qmf-6344-4f7m

больше 4 лет назад

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).

EPSS: Низкий
github логотип

GHSA-3qmc-vv7g-wccj

почти 3 года назад

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qmc-cj7q-62hv

3 месяца назад

Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3qmc-2r76-4rqp

почти 4 года назад

Redwood is vulnerable to account takeover via dbAuth "forgot-password"

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3qm9-v325-gx6g

почти 5 лет назад

OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

EPSS: Низкий
github логотип

GHSA-3qm9-8m3h-5r34

больше 4 лет назад

In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541

EPSS: Низкий
github логотип

GHSA-3qm9-52c7-2c7g

больше 4 лет назад

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qmm-r55x-hpxx

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-3qmj-w8xr-h39r

Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qmj-w5mh-5gv3

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

CVSS3: 9.8
6%
Низкий
больше 2 лет назад
github логотип
GHSA-3qmj-rc63-mhjw

A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3qmj-qw66-fwx8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out of bound (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap-OOB-WRITE would be triggered which could have Remote Code Execution (RCE) potential.

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-3qmj-gxp7-229g

SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qmj-8cpx-9xxp

VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qmh-69j2-8hj7

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qmg-wxq2-g22p

Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload.

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-3qmg-c9vc-r47j

Mercurial is vulnerable to shell injection attack

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-3qmg-867g-8xrq

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3qmf-g4j6-v744

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.

CVSS3: 7.1
0%
Низкий
17 дней назад
github логотип
GHSA-3qmf-fj65-6vmf

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qmf-6344-4f7m

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qmc-vv7g-wccj

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-3qmc-cj7q-62hv

Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

CVSS3: 5.9
0%
Низкий
3 месяца назад
github логотип
GHSA-3qmc-2r76-4rqp

Redwood is vulnerable to account takeover via dbAuth "forgot-password"

CVSS3: 8.2
почти 4 года назад
github логотип
GHSA-3qm9-v325-gx6g

OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-3qm9-8m3h-5r34

In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qm9-52c7-2c7g

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу