Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-24q7-hvmv-5rmp

9 месяцев назад

A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-24q7-5rc2-3hrp

8 месяцев назад

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24q6-h6j8-wpf6

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: block, bfq: Fix division by zero error on zero wsum When the weighted sum is zero the calculation of limit causes a division by zero error. Fix this by continuing to the next level. This was discovered by running as root: stress-ng --ioprio 0 Fixes divison by error oops: [ 521.450556] divide error: 0000 [#1] SMP NOPTI [ 521.450766] CPU: 2 PID: 2684464 Comm: stress-ng-iopri Not tainted 6.2.1-1280.native #1 [ 521.451117] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 [ 521.451627] RIP: 0010:bfqq_request_over_limit+0x207/0x400 [ 521.451875] Code: 01 48 8d 0c c8 74 0b 48 8b 82 98 00 00 00 48 8d 0c c8 8b 85 34 ff ff ff 48 89 ca 41 0f af 41 50 48 d1 ea 48 98 48 01 d0 31 d2 <48> f7 f1 41 39 41 48 89 85 34 ff ff ff 0f 8c 7b 01 00 00 49 8b 44 [ 521.452699] RSP: 0018:ffffb1af84eb3948 EFLAGS: 00010046 [ 521.452938] RAX: 000000000000003c RBX: 0000...

EPSS: Низкий
github логотип

GHSA-24q6-6vv9-w6vj

около 4 лет назад

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24q6-4w37-557f

около 1 года назад

A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24q5-v927-9w6j

около 1 года назад

Missing Authorization vulnerability in Mitchell Bennis Simple File List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple File List: from n/a through 6.1.13.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-24q5-7fw8-5m7f

больше 3 лет назад

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented comparison. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-16152.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24q4-rxhj-p299

больше 4 лет назад

Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.

EPSS: Низкий
github логотип

GHSA-24q4-mvc8-82fw

около 1 месяца назад

Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-24q4-gxqx-jxh8

около 4 лет назад

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24q3-549v-f57v

больше 4 лет назад

SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

EPSS: Низкий
github логотип

GHSA-24q3-2w85-x8p7

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24q2-qw2x-xxpj

около 4 лет назад

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

EPSS: Низкий
github логотип

GHSA-24q2-h758-fvwc

5 месяцев назад

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24q2-f22j-vg5m

около 4 лет назад

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass.

EPSS: Низкий
github логотип

GHSA-24q2-6x37-cgcx

около 4 лет назад

Dolibarr SQL injection vulnerability in product/card.php

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24q2-59hm-rh9r

почти 3 года назад

Strapi Improper Rate Limiting vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-24q2-4vqq-qcx6

больше 3 лет назад

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24px-m2q8-87hf

больше 1 года назад

Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24px-fh32-jvj7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24q7-hvmv-5rmp

A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-24q7-5rc2-3hrp

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-24q6-h6j8-wpf6

In the Linux kernel, the following vulnerability has been resolved: block, bfq: Fix division by zero error on zero wsum When the weighted sum is zero the calculation of limit causes a division by zero error. Fix this by continuing to the next level. This was discovered by running as root: stress-ng --ioprio 0 Fixes divison by error oops: [ 521.450556] divide error: 0000 [#1] SMP NOPTI [ 521.450766] CPU: 2 PID: 2684464 Comm: stress-ng-iopri Not tainted 6.2.1-1280.native #1 [ 521.451117] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 [ 521.451627] RIP: 0010:bfqq_request_over_limit+0x207/0x400 [ 521.451875] Code: 01 48 8d 0c c8 74 0b 48 8b 82 98 00 00 00 48 8d 0c c8 8b 85 34 ff ff ff 48 89 ca 41 0f af 41 50 48 d1 ea 48 98 48 01 d0 31 d2 <48> f7 f1 41 39 41 48 89 85 34 ff ff ff 0f 8c 7b 01 00 00 49 8b 44 [ 521.452699] RSP: 0018:ffffb1af84eb3948 EFLAGS: 00010046 [ 521.452938] RAX: 000000000000003c RBX: 0000...

0%
Низкий
7 месяцев назад
github логотип
GHSA-24q6-6vv9-w6vj

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-24q6-4w37-557f

A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-24q5-v927-9w6j

Missing Authorization vulnerability in Mitchell Bennis Simple File List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple File List: from n/a through 6.1.13.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-24q5-7fw8-5m7f

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented comparison. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-16152.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-24q4-rxhj-p299

Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-24q4-mvc8-82fw

Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-24q4-gxqx-jxh8

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-24q3-549v-f57v

SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-24q3-2w85-x8p7

Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-24q2-qw2x-xxpj

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

4%
Низкий
около 4 лет назад
github логотип
GHSA-24q2-h758-fvwc

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-24q2-f22j-vg5m

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass.

1%
Низкий
около 4 лет назад
github логотип
GHSA-24q2-6x37-cgcx

Dolibarr SQL injection vulnerability in product/card.php

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-24q2-59hm-rh9r

Strapi Improper Rate Limiting vulnerability

CVSS3: 7.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-24q2-4vqq-qcx6

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24px-m2q8-87hf

Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-24px-fh32-jvj7

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу