Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2j46-6r67-vrpr

больше 1 года назад

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2j46-43q5-rfcp

больше 1 года назад

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2j45-xr49-x8qc

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the interrupt context, the machine_kexec_mask_interrupts() function will trigger a deadlock while trying to acquire the irqdesc spinlock and then deactivate irqchip in irq_set_irqchip_state() function. Unlike arm64, riscv only requires irq_eoi handler to complete EOI and keeping irq_set_irqchip_state() will only leave this possible deadlock without any use. So we simply remove it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j45-pj39-84jw

около 4 лет назад

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2j44-h693-7vr3

больше 2 лет назад

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2j44-cf99-2fgr

8 дней назад

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-2j44-59r4-mjvh

около 4 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j43-x625-hw9q

около 2 месяцев назад

A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.

EPSS: Низкий
github логотип

GHSA-2j42-h78h-q4fg

больше 1 года назад

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2j3x-r9v2-2733

около 4 лет назад

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:18:11.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j3x-ghj2-35fv

около 4 лет назад

On Juniper Networks Junos OS devices, receipt of a malformed IPv6 packet may cause the system to crash and restart (vmcore). This issue can be trigged by a malformed IPv6 packet destined to the Routing Engine or a transit packet that is sampled using sFlow/jFlow or processed by firewall filter with the syslog and/or log action. An attacker can repeatedly send the offending packet resulting in an extended Denial of Service condition. Only IPv6 packets can trigger this issue. IPv4 packets cannot trigger this issue. This issue affects Juniper Networks Junos OS 18.4 versions prior to 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2. This issue does not affect Juniper Networks Junos OS prior to 18.4R1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j3x-fvgp-v399

около 1 года назад

Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.

EPSS: Низкий
github логотип

GHSA-2j3v-cxmf-cmp7

7 месяцев назад

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j3v-9566-775v

больше 1 года назад

A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j3v-48pv-mvcj

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: protect device queue against concurrent access In dasd_profile_start() the amount of requests on the device queue are counted. The access to the device queue is unprotected against concurrent access. With a lot of parallel I/O, especially with alias devices enabled, the device queue can change while dasd_profile_start() is accessing the queue. In the worst case this leads to a kernel panic due to incorrect pointer accesses. Fix this by taking the device lock before accessing the queue and counting the requests. Additionally the check for a valid profile data pointer can be done earlier to avoid unnecessary locking in a hot path.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j3r-x6xc-qqqj

около 4 лет назад

Credential stored in plain text by BMC Release Package and Deployment Plugin

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2j3r-x22c-hqx9

9 месяцев назад

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j3r-j4h7-v6hh

около 4 лет назад

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

EPSS: Низкий
github логотип

GHSA-2j3q-vc9h-xvcv

около 4 лет назад

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

EPSS: Низкий
github логотип

GHSA-2j3q-chq2-h2fc

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j46-6r67-vrpr

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2j46-43q5-rfcp

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2j45-xr49-x8qc

In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the interrupt context, the machine_kexec_mask_interrupts() function will trigger a deadlock while trying to acquire the irqdesc spinlock and then deactivate irqchip in irq_set_irqchip_state() function. Unlike arm64, riscv only requires irq_eoi handler to complete EOI and keeping irq_set_irqchip_state() will only leave this possible deadlock without any use. So we simply remove it.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2j45-pj39-84jw

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

CVSS3: 9.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-2j44-h693-7vr3

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVSS3: 9.6
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2j44-cf99-2fgr

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
1%
Низкий
8 дней назад
github логотип
GHSA-2j44-59r4-mjvh

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j43-x625-hw9q

A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2j42-h78h-q4fg

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

CVSS3: 9.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2j3x-r9v2-2733

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:18:11.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2j3x-ghj2-35fv

On Juniper Networks Junos OS devices, receipt of a malformed IPv6 packet may cause the system to crash and restart (vmcore). This issue can be trigged by a malformed IPv6 packet destined to the Routing Engine or a transit packet that is sampled using sFlow/jFlow or processed by firewall filter with the syslog and/or log action. An attacker can repeatedly send the offending packet resulting in an extended Denial of Service condition. Only IPv6 packets can trigger this issue. IPv4 packets cannot trigger this issue. This issue affects Juniper Networks Junos OS 18.4 versions prior to 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2. This issue does not affect Juniper Networks Junos OS prior to 18.4R1.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j3x-fvgp-v399

Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature.

0%
Низкий
около 1 года назад
github логотип
GHSA-2j3v-cxmf-cmp7

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.

CVSS3: 5.9
1%
Низкий
7 месяцев назад
github логотип
GHSA-2j3v-9566-775v

A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2j3v-48pv-mvcj

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: protect device queue against concurrent access In dasd_profile_start() the amount of requests on the device queue are counted. The access to the device queue is unprotected against concurrent access. With a lot of parallel I/O, especially with alias devices enabled, the device queue can change while dasd_profile_start() is accessing the queue. In the worst case this leads to a kernel panic due to incorrect pointer accesses. Fix this by taking the device lock before accessing the queue and counting the requests. Additionally the check for a valid profile data pointer can be done earlier to avoid unnecessary locking in a hot path.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2j3r-x6xc-qqqj

Credential stored in plain text by BMC Release Package and Deployment Plugin

CVSS3: 3.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2j3r-x22c-hqx9

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2j3r-j4h7-v6hh

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

9%
Низкий
около 4 лет назад
github логотип
GHSA-2j3q-vc9h-xvcv

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j3q-chq2-h2fc

Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.

CVSS3: 5.4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу