Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 345 180

Количество 345 180

github логотип

GHSA-2382-6vwc-h973

около 4 лет назад

The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

EPSS: Низкий
github логотип

GHSA-237x-ggj9-vvhf

около 4 лет назад

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-237x-6c63-mfj6

около 4 лет назад

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

EPSS: Низкий
github логотип

GHSA-237w-fwrp-rqvw

больше 4 лет назад

Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."

EPSS: Низкий
github логотип

GHSA-237w-63m6-9xcp

около 4 лет назад

The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.

EPSS: Низкий
github логотип

GHSA-237v-gpwr-jc57

больше 1 года назад

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-237r-v2jq-99fc

6 месяцев назад

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-237r-rx7w-5j6c

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Stop job scheduling across aie2_release_resource() Running jobs on a hardware context while it is in the process of releasing resources can lead to use-after-free and crashes. Fix this by stopping job scheduling before calling aie2_release_resource() and restarting it after the release completes. Additionally, aie2_sched_job_run() now checks whether the hardware context is still active.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-237r-r8m4-4q88

больше 1 года назад

Guzzle OAuth Subscriber has insufficient nonce entropy

EPSS: Низкий
github логотип

GHSA-237r-mx84-7x8c

почти 4 года назад

VNCAuthProxy authentication bypass vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-237r-7322-3fvf

5 месяцев назад

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-237r-5vv2-cjj5

около 4 лет назад

Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing command to reset in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, QCS405, QCS605, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX20, SDX24

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-237q-6hjp-pchq

около 4 лет назад

JBoss KeyCloak is vulnerable to soft token deletion via CSRF

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-237p-qjh7-f926

3 месяца назад

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-237m-vv9j-66q2

около 4 лет назад

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

EPSS: Низкий
github логотип

GHSA-237m-m5vm-9wrc

около 4 лет назад

The UTSA Mobile (aka com.dub.app.utsa) application 1.4.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-237m-4vqc-855x

4 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-237j-pjh8-mjr2

12 месяцев назад

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-237j-ffh5-w965

около 4 лет назад

Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-237h-73gr-5r5j

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250130 is the identifier assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2382-6vwc-h973

The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

1%
Низкий
около 4 лет назад
github логотип
GHSA-237x-ggj9-vvhf

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVSS3: 9.8
9%
Низкий
около 4 лет назад
github логотип
GHSA-237x-6c63-mfj6

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

0%
Низкий
около 4 лет назад
github логотип
GHSA-237w-fwrp-rqvw

Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-237w-63m6-9xcp

The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.

0%
Низкий
около 4 лет назад
github логотип
GHSA-237v-gpwr-jc57

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-237r-v2jq-99fc

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-237r-rx7w-5j6c

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Stop job scheduling across aie2_release_resource() Running jobs on a hardware context while it is in the process of releasing resources can lead to use-after-free and crashes. Fix this by stopping job scheduling before calling aie2_release_resource() and restarting it after the release completes. Additionally, aie2_sched_job_run() now checks whether the hardware context is still active.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-237r-r8m4-4q88

Guzzle OAuth Subscriber has insufficient nonce entropy

0%
Низкий
больше 1 года назад
github логотип
GHSA-237r-mx84-7x8c

VNCAuthProxy authentication bypass vulnerability

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-237r-7322-3fvf

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter).

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-237r-5vv2-cjj5

Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing command to reset in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, QCS405, QCS605, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX20, SDX24

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-237q-6hjp-pchq

JBoss KeyCloak is vulnerable to soft token deletion via CSRF

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-237p-qjh7-f926

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-237m-vv9j-66q2

In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-237m-m5vm-9wrc

The UTSA Mobile (aka com.dub.app.utsa) application 1.4.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-237m-4vqc-855x

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-237j-pjh8-mjr2

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-237j-ffh5-w965

Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.

7%
Низкий
около 4 лет назад
github логотип
GHSA-237h-73gr-5r5j

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250130 is the identifier assigned to this vulnerability.

CVSS3: 5.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу