Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-3967-4r54-74c9

больше 2 лет назад

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3966-q7xr-5r3x

больше 4 лет назад

SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.

EPSS: Низкий
github логотип

GHSA-3966-f6p6-2qr9

8 месяцев назад

Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3965-x5g2-56x2

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap/vunmap Acquire and release the GEM object's reservation lock around vmap and vunmap operations. The tests use vmap_locked, which led to errors such as show below. [ 122.292030] WARNING: CPU: 3 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:390 drm_gem_shmem_vmap_locked+0x3a3/0x6f0 [ 122.468066] WARNING: CPU: 3 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:293 drm_gem_shmem_pin_locked+0x1fe/0x350 [ 122.563504] WARNING: CPU: 3 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:234 drm_gem_shmem_get_pages_locked+0x23c/0x370 [ 122.662248] WARNING: CPU: 2 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:452 drm_gem_shmem_vunmap_locked+0x101/0x330 Only export the new vmap/vunmap helpers for Kunit tests. These are not interfaces for regular drivers.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3965-hpx2-q597

больше 2 лет назад

Pug allows JavaScript code execution if an application accepts untrusted input

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3965-7vwp-wr38

больше 4 лет назад

class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

EPSS: Низкий
github логотип

GHSA-3964-29ff-vwff

около 2 месяцев назад

SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3963-94c4-r6r8

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx() We don't currently validate that the values being set are within the range we advertised to userspace as being valid, do so and reject any values that are out of range.

EPSS: Низкий
github логотип

GHSA-3963-6mf6-92mq

20 дней назад

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3963-57mq-56wf

больше 4 лет назад

A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

EPSS: Низкий
github логотип

GHSA-3962-w3j2-98vq

больше 2 лет назад

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3962-mvm3-c84q

больше 4 лет назад

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3962-mh6m-87qj

6 месяцев назад

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the vulnerability through the Create SC feature by selecting a crafted BMP file with an oversized buffer, causing the application to crash.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-3962-gjv5-4r4p

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ZenphotoPress allows Reflected XSS. This issue affects ZenphotoPress: from n/a through 1.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-395x-wv32-44v5

почти 4 года назад

baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-395x-8q95-8h46

больше 1 года назад

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Multiple parameters might be affected.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-395x-4p37-wm78

больше 3 лет назад

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assign/assign.php. The manipulation of the argument sid leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223559.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-395x-3x8q-mv38

больше 4 лет назад

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-395w-rp4r-w5q9

больше 4 лет назад

cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.

EPSS: Низкий
github логотип

GHSA-395w-qhqr-9fr6

больше 5 лет назад

Path Traversal in Apache Flink

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3967-4r54-74c9

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVSS3: 8.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3966-q7xr-5r3x

SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3966-f6p6-2qr9

Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS3: 7
0%
Низкий
8 месяцев назад
github логотип
GHSA-3965-x5g2-56x2

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap/vunmap Acquire and release the GEM object's reservation lock around vmap and vunmap operations. The tests use vmap_locked, which led to errors such as show below. [ 122.292030] WARNING: CPU: 3 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:390 drm_gem_shmem_vmap_locked+0x3a3/0x6f0 [ 122.468066] WARNING: CPU: 3 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:293 drm_gem_shmem_pin_locked+0x1fe/0x350 [ 122.563504] WARNING: CPU: 3 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:234 drm_gem_shmem_get_pages_locked+0x23c/0x370 [ 122.662248] WARNING: CPU: 2 PID: 1413 at drivers/gpu/drm/drm_gem_shmem_helper.c:452 drm_gem_shmem_vunmap_locked+0x101/0x330 Only export the new vmap/vunmap helpers for Kunit tests. These are not interfaces for regular drivers.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3965-hpx2-q597

Pug allows JavaScript code execution if an application accepts untrusted input

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3965-7vwp-wr38

class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3964-29ff-vwff

SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.

CVSS3: 4.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3963-94c4-r6r8

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx() We don't currently validate that the values being set are within the range we advertised to userspace as being valid, do so and reject any values that are out of range.

больше 2 лет назад
github логотип
GHSA-3963-6mf6-92mq

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.

CVSS3: 8.1
0%
Низкий
20 дней назад
github логотип
GHSA-3963-57mq-56wf

A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3962-w3j2-98vq

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3962-mvm3-c84q

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3962-mh6m-87qj

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the vulnerability through the Create SC feature by selecting a crafted BMP file with an oversized buffer, causing the application to crash.

CVSS3: 6.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-3962-gjv5-4r4p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ZenphotoPress allows Reflected XSS. This issue affects ZenphotoPress: from n/a through 1.8.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-395x-wv32-44v5

baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

CVSS3: 4.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-395x-8q95-8h46

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Multiple parameters might be affected.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-395x-4p37-wm78

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assign/assign.php. The manipulation of the argument sid leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223559.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-395x-3x8q-mv38

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-395w-rp4r-w5q9

cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-395w-qhqr-9fr6

Path Traversal in Apache Flink

CVSS3: 7.5
98%
Критический
больше 5 лет назад

Уязвимостей на страницу