Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-3mwv-hq37-h7fr

больше 4 лет назад

SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500.

EPSS: Низкий
github логотип

GHSA-3mwv-2gpx-w3rp

21 день назад

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3mwr-g9f4-vwj8

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz allows Stored XSS. This issue affects OnionBuzz: from n/a through 1.0.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3mwq-qhjc-cmfx

больше 4 лет назад

Reflected XSS in wordpress plugin photoxhibit v2.1.8

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mwq-h3g6-ffhm

почти 3 года назад

Vapor's incorrect request error handling triggers server crash

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mwp-xqp2-q6ph

6 месяцев назад

ImageMagick: MSL attribute stack buffer overflow leads to out of bounds write.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3mwp-wvh9-7528

6 месяцев назад

vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mwp-vjrv-6crj

больше 4 лет назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.78, D6200 before 1.1.00.32, D7000 before 1.0.1.68, D7800 before 1.0.1.56, DM200 before 1.0.0.61, EX2700 before 1.0.1.52, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.74, EX6400 before 1.0.2.140, EX7300 before 1.0.2.140, EX8000 before 1.0.1.186, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, R7500v2 before 1.0.3.40, R7800 before 1.0.2.62, R8900 before 1.0.4.12, R9000 before 1.0.4.12, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBR40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 ...

EPSS: Низкий
github логотип

GHSA-3mwp-qw92-xgwg

больше 4 лет назад

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mwp-gjqm-h3xp

больше 4 лет назад

An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.

EPSS: Низкий
github логотип

GHSA-3mwp-7c29-vp5v

2 месяца назад

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mwp-4m88-3vhv

больше 4 лет назад

Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-3mwm-pxvj-5v4x

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. The wrapping link is unnecessary if end = 0. end is the entry after the last one used so end = 0 means there's nothing pushed after the wrap: end start i v v v [ ]...[ ][ d ][ d ][ d ][ d ][rsv for wrap] Skip the wrapping in this case. TLS 1.3 can use the "wrapping slot" for it's chaining if end = 0. This avoids the chain-after-chain. Move the wrap chaining before marking END and chaining off content type, that feels like more logical ordering to me, ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mwm-gvjc-9x56

больше 4 лет назад

app/operator_panel/index_inc.php in the Operator Panel module in FreePBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3mwj-wx8p-p57v

больше 4 лет назад

Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.

EPSS: Низкий
github логотип

GHSA-3mwj-prww-7q68

больше 4 лет назад

Magnolia CMS From 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

EPSS: Низкий
github логотип

GHSA-3mwj-g532-hjvp

4 месяца назад

STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.

EPSS: Низкий
github логотип

GHSA-3mwj-7vmq-w43p

больше 4 лет назад

Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3mwj-25mw-j4g4

больше 4 лет назад

Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.

EPSS: Низкий
github логотип

GHSA-3mwh-xgcp-8q55

больше 4 лет назад

An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mwv-hq37-h7fr

SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwv-2gpx-w3rp

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.

CVSS3: 8.2
0%
Низкий
21 день назад
github логотип
GHSA-3mwr-g9f4-vwj8

Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz allows Stored XSS. This issue affects OnionBuzz: from n/a through 1.0.7.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3mwq-qhjc-cmfx

Reflected XSS in wordpress plugin photoxhibit v2.1.8

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwq-h3g6-ffhm

Vapor's incorrect request error handling triggers server crash

CVSS3: 5.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-3mwp-xqp2-q6ph

ImageMagick: MSL attribute stack buffer overflow leads to out of bounds write.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3mwp-wvh9-7528

vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3mwp-vjrv-6crj

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.78, D6200 before 1.1.00.32, D7000 before 1.0.1.68, D7800 before 1.0.1.56, DM200 before 1.0.0.61, EX2700 before 1.0.1.52, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.74, EX6400 before 1.0.2.140, EX7300 before 1.0.2.140, EX8000 before 1.0.1.186, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, R7500v2 before 1.0.3.40, R7800 before 1.0.2.62, R8900 before 1.0.4.12, R9000 before 1.0.4.12, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBR40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 ...

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwp-qw92-xgwg

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwp-gjqm-h3xp

An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwp-7c29-vp5v

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-3mwp-4m88-3vhv

Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwm-pxvj-5v4x

In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. The wrapping link is unnecessary if end = 0. end is the entry after the last one used so end = 0 means there's nothing pushed after the wrap: end start i v v v [ ]...[ ][ d ][ d ][ d ][ d ][rsv for wrap] Skip the wrapping in this case. TLS 1.3 can use the "wrapping slot" for it's chaining if end = 0. This avoids the chain-after-chain. Move the wrap chaining before marking END and chaining off content type, that feels like more logical ordering to me, ...

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-3mwm-gvjc-9x56

app/operator_panel/index_inc.php in the Operator Panel module in FreePBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwj-wx8p-p57v

Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwj-prww-7q68

Magnolia CMS From 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwj-g532-hjvp

STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.

0%
Низкий
4 месяца назад
github логотип
GHSA-3mwj-7vmq-w43p

Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin

CVSS3: 8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwj-25mw-j4g4

Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3mwh-xgcp-8q55

An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу