Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2hfm-w8q2-965h

больше 4 лет назад

Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

EPSS: Средний
github логотип

GHSA-2hfm-pcvh-xc2h

около 4 лет назад

Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."

EPSS: Низкий
github логотип

GHSA-2hfj-jv6q-762v

10 месяцев назад

Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key

EPSS: Низкий
github логотип

GHSA-2hfj-cxw7-g45p

больше 4 лет назад

Unsafe inline XSS in pasting DOM element into chat

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2hfj-84hx-9426

около 4 лет назад

The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2hfh-9h53-qc24

3 месяца назад

Apache Neethi does not properly detect circular references in policy definitions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hfh-94w5-wxvf

около 1 года назад

ZPan Uses Hard-Coded Password

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2hfg-pw5c-5cwc

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid accessing uninitialized arvif->ar during beacon miss During beacon miss handling, ath12k driver iterates over active virtual interfaces (vifs) and attempts to access the radio object (ar) via arvif->deflink->ar. However, after commit aa80f12f3bed ("wifi: ath12k: defer vdev creation for MLO"), arvif is linked to a radio only after vdev creation, typically when a channel is assigned or a scan is requested. For P2P capable devices, a default P2P interface is created by wpa_supplicant along with regular station interfaces, these serve as dummy interfaces for P2P-capable stations, lack an associated netdev and initiate frequent scans to discover neighbor p2p devices. When a scan is initiated on such P2P vifs, driver selects destination radio (ar) based on scan frequency, creates a scan vdev, and attaches arvif to the radio. Once the scan completes or is aborted, the scan vdev is deleted, detaching ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2hfg-hghr-46wq

больше 3 лет назад

BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hfg-6q5v-4492

6 месяцев назад

A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2hfg-4m2j-678g

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: wl128x: Fix atomicity violation in fmc_send_cmd() Atomicity violation occurs when the fmc_send_cmd() function is executed simultaneously with the modification of the fmdev->resp_skb value. Consider a scenario where, after passing the validity check within the function, a non-null fmdev->resp_skb variable is assigned a null value. This results in an invalid fmdev->resp_skb variable passing the validity check. As seen in the later part of the function, skb = fmdev->resp_skb; when the invalid fmdev->resp_skb passes the check, a null pointer dereference error may occur at line 478, evt_hdr = (void *)skb->data; To address this issue, it is recommended to include the validity check of fmdev->resp_skb within the locked section of the function. This modification ensures that the value of fmdev->resp_skb does not change during the validation process, thereby maintaining its validity. This possible bug is found by ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2hfg-4fh4-qp7f

около 1 месяца назад

OpenClaw's browser act interactions could bypass private-network navigation checks

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2hff-rr39-hph8

6 месяцев назад

Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.

EPSS: Низкий
github логотип

GHSA-2hff-q8hc-g254

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hff-p384-25wq

больше 4 лет назад

wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.

EPSS: Низкий
github логотип

GHSA-2hff-34p4-2jhh

около 4 лет назад

In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0. Android ID: A-65174158.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hff-27rx-7v32

около 4 лет назад

Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is also possible to execute JavaScript against unauthenticated users of the blog.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hfc-xmh6-q9f9

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for hrtimer. Such a situation may lead to an unexpected RCU stall, where the callback repeatedly queuing the expire update, as reported by fuzzer. This patch introduces a sanity check of the timer start tick time, so that the system returns an error when a too small start size is set. As of this patch, the lower limit is hard-coded to 100us, which is small enough but can still work somehow.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2hfc-prjx-wjcx

больше 1 года назад

WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hfc-mwf6-hhw3

2 месяца назад

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hfm-w8q2-965h

Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

13%
Средний
больше 4 лет назад
github логотип
GHSA-2hfm-pcvh-xc2h

Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."

4%
Низкий
около 4 лет назад
github логотип
GHSA-2hfj-jv6q-762v

Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key

0%
Низкий
10 месяцев назад
github логотип
GHSA-2hfj-cxw7-g45p

Unsafe inline XSS in pasting DOM element into chat

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hfj-84hx-9426

The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hfh-9h53-qc24

Apache Neethi does not properly detect circular references in policy definitions.

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-2hfh-94w5-wxvf

ZPan Uses Hard-Coded Password

CVSS3: 3.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2hfg-pw5c-5cwc

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid accessing uninitialized arvif->ar during beacon miss During beacon miss handling, ath12k driver iterates over active virtual interfaces (vifs) and attempts to access the radio object (ar) via arvif->deflink->ar. However, after commit aa80f12f3bed ("wifi: ath12k: defer vdev creation for MLO"), arvif is linked to a radio only after vdev creation, typically when a channel is assigned or a scan is requested. For P2P capable devices, a default P2P interface is created by wpa_supplicant along with regular station interfaces, these serve as dummy interfaces for P2P-capable stations, lack an associated netdev and initiate frequent scans to discover neighbor p2p devices. When a scan is initiated on such P2P vifs, driver selects destination radio (ar) based on scan frequency, creates a scan vdev, and attaches arvif to the radio. Once the scan completes or is aborted, the scan vdev is deleted, detaching ...

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2hfg-hghr-46wq

BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hfg-6q5v-4492

A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2hfg-4m2j-678g

In the Linux kernel, the following vulnerability has been resolved: media: wl128x: Fix atomicity violation in fmc_send_cmd() Atomicity violation occurs when the fmc_send_cmd() function is executed simultaneously with the modification of the fmdev->resp_skb value. Consider a scenario where, after passing the validity check within the function, a non-null fmdev->resp_skb variable is assigned a null value. This results in an invalid fmdev->resp_skb variable passing the validity check. As seen in the later part of the function, skb = fmdev->resp_skb; when the invalid fmdev->resp_skb passes the check, a null pointer dereference error may occur at line 478, evt_hdr = (void *)skb->data; To address this issue, it is recommended to include the validity check of fmdev->resp_skb within the locked section of the function. This modification ensures that the value of fmdev->resp_skb does not change during the validation process, thereby maintaining its validity. This possible bug is found by ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hfg-4fh4-qp7f

OpenClaw's browser act interactions could bypass private-network navigation checks

CVSS3: 7.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2hff-rr39-hph8

Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2hff-q8hc-g254

Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hff-p384-25wq

wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-2hff-34p4-2jhh

In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0. Android ID: A-65174158.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hff-27rx-7v32

Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is also possible to execute JavaScript against unauthenticated users of the blog.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hfc-xmh6-q9f9

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for hrtimer. Such a situation may lead to an unexpected RCU stall, where the callback repeatedly queuing the expire update, as reported by fuzzer. This patch introduces a sanity check of the timer start tick time, so that the system returns an error when a too small start size is set. As of this patch, the lower limit is hard-coded to 100us, which is small enough but can still work somehow.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-2hfc-prjx-wjcx

WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hfc-mwf6-hhw3

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details.

CVSS3: 8.2
0%
Низкий
2 месяца назад

Уязвимостей на страницу