Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2j53-64jx-6w47

около 4 лет назад

Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.

EPSS: Низкий
github логотип

GHSA-2j53-2c28-g9v2

4 месяца назад

Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j52-jv7p-x34h

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.

EPSS: Низкий
github логотип

GHSA-2j4x-8g92-58rm

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2j4w-p7qh-8g4g

около 4 лет назад

Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j4w-p5m4-8q93

около 4 лет назад

Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.

EPSS: Низкий
github логотип

GHSA-2j4v-jvmw-mq8v

около 4 лет назад

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.

EPSS: Низкий
github логотип

GHSA-2j4r-v4xj-p2f4

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j4r-j436-59p3

около 4 лет назад

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j4q-9fff-236j

около 4 лет назад

Apache Struts XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j4p-5xx5-582x

около 4 лет назад

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.

EPSS: Низкий
github логотип

GHSA-2j4p-2hc9-62f4

больше 3 лет назад

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j4j-cgfm-hpg2

около 4 лет назад

SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

EPSS: Низкий
github логотип

GHSA-2j4h-qfp4-82q7

около 4 лет назад

Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

EPSS: Высокий
github логотип

GHSA-2j4h-p58q-g7mp

около 4 лет назад

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.

EPSS: Низкий
github логотип

GHSA-2j4h-mgwq-9x58

около 4 лет назад

The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.

EPSS: Низкий
github логотип

GHSA-2j4h-cjgh-659v

около 4 лет назад

Reflected XSS vulnerability in Jenkins VncViewer Plugin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j4h-89r3-h3f3

больше 4 лет назад

The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

EPSS: Низкий
github логотип

GHSA-2j4h-4639-xjfj

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2j4g-v4fv-rhwg

больше 2 лет назад

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j53-64jx-6w47

Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j53-2c28-g9v2

Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement

CVSS3: 6.5
4 месяца назад
github логотип
GHSA-2j52-jv7p-x34h

Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2j4x-8g92-58rm

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-2j4w-p7qh-8g4g

Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j4w-p5m4-8q93

Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2j4v-jvmw-mq8v

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j4r-v4xj-p2f4

Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2j4r-j436-59p3

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-2j4q-9fff-236j

Apache Struts XSS Vulnerability

CVSS3: 6.1
8%
Низкий
около 4 лет назад
github логотип
GHSA-2j4p-5xx5-582x

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j4p-2hc9-62f4

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4j-cgfm-hpg2

SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2j4h-qfp4-82q7

Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

80%
Высокий
около 4 лет назад
github логотип
GHSA-2j4h-p58q-g7mp

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j4h-mgwq-9x58

The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.

10%
Низкий
около 4 лет назад
github логотип
GHSA-2j4h-cjgh-659v

Reflected XSS vulnerability in Jenkins VncViewer Plugin

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j4h-89r3-h3f3

The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2j4h-4639-xjfj

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2j4g-v4fv-rhwg

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability

CVSS3: 7.2
53%
Средний
больше 2 лет назад

Уязвимостей на страницу