Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-24xm-58mr-jc27

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: add NULL check in DT parse Add a NULL check for the return value of of_get_property() when retrieving the "pinmux" property in the group parser. This avoids a potential NULL pointer dereference if the property is missing from the device tree node. Also fix a typo ("sintenel") in the device ID match table comment, correcting it to "sentinel".

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24xj-r6rg-2w25

больше 1 года назад

Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-24xj-hpq7-7f3v

почти 3 года назад

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24xj-5pqv-grgf

почти 4 года назад

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24xg-hcwc-cpv6

больше 1 года назад

Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24xg-98w5-96c8

около 4 лет назад

0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference.

EPSS: Низкий
github логотип

GHSA-24xg-93rh-whf7

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in icyleaf WS Audio Player allows Stored XSS. This issue affects WS Audio Player: from n/a through 1.1.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24xf-h5qf-w44w

около 2 месяцев назад

Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24xf-f6x5-p9rf

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget allows Cross Site Request Forgery. This issue affects Info Boxes Shortcode and Widget: from n/a through 1.15.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24xc-rjq3-m9pj

около 4 лет назад

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.

EPSS: Низкий
github логотип

GHSA-24xc-5f2v-5mc5

около 1 года назад

A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-24xc-3gmc-877f

около 4 лет назад

The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24x9-r6q4-q93w

2 месяца назад

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

EPSS: Низкий
github логотип

GHSA-24x9-9gx2-3g25

около 4 лет назад

The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24x8-vf4r-m3v5

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24x8-275w-hwpr

больше 2 лет назад

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24x7-gxr3-5r7r

около 4 лет назад

The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24x7-c4mf-44m6

больше 1 года назад

A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-24x7-8mv3-v5xj

больше 3 лет назад

A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-24x6-8c7m-hv3f

около 5 лет назад

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

CVSS3: 2.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24xm-58mr-jc27

In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: add NULL check in DT parse Add a NULL check for the return value of of_get_property() when retrieving the "pinmux" property in the group parser. This avoids a potential NULL pointer dereference if the property is missing from the device tree node. Also fix a typo ("sintenel") in the device ID match table comment, correcting it to "sentinel".

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-24xj-r6rg-2w25

Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.

CVSS3: 9.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-24xj-hpq7-7f3v

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-24xj-5pqv-grgf

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-24xg-hcwc-cpv6

Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24xg-98w5-96c8

0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference.

7%
Низкий
около 4 лет назад
github логотип
GHSA-24xg-93rh-whf7

Cross-Site Request Forgery (CSRF) vulnerability in icyleaf WS Audio Player allows Stored XSS. This issue affects WS Audio Player: from n/a through 1.1.8.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-24xf-h5qf-w44w

Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-24xf-f6x5-p9rf

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget allows Cross Site Request Forgery. This issue affects Info Boxes Shortcode and Widget: from n/a through 1.15.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-24xc-rjq3-m9pj

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.

1%
Низкий
около 4 лет назад
github логотип
GHSA-24xc-5f2v-5mc5

A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-24xc-3gmc-877f

The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-24x9-r6q4-q93w

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

0%
Низкий
2 месяца назад
github логотип
GHSA-24x9-9gx2-3g25

The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-24x8-vf4r-m3v5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-24x8-275w-hwpr

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-24x7-gxr3-5r7r

The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-24x7-c4mf-44m6

A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
больше 1 года назад
github логотип
GHSA-24x7-8mv3-v5xj

A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.

CVSS3: 2.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24x6-8c7m-hv3f

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

CVSS3: 2.5
0%
Низкий
около 5 лет назад

Уязвимостей на страницу