Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-37m6-8rw8-wh8f

5 месяцев назад

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-37m6-73f6-jm7w

больше 4 лет назад

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

EPSS: Низкий
github логотип

GHSA-37m6-2cm3-x5m2

больше 4 лет назад

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

EPSS: Низкий
github логотип

GHSA-37m5-m4q3-fc6x

4 месяца назад

Froxlor: BIND Zone File Injection via TXT Record Content

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-37m5-593h-89wf

больше 4 лет назад

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37m5-42qp-4qpr

больше 5 лет назад

Cross-site scripting in LocalStack

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37m4-w5jp-r3px

больше 2 лет назад

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37m4-hvw3-vwmc

9 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37m4-hqxv-w26g

больше 2 лет назад

XWiki Platform CSRF remote code execution through scheduler job's document reference

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-37m3-qp37-x3c6

больше 4 лет назад

Apache Geode gfsh query vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37m3-29m6-vgxq

больше 4 лет назад

PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.

EPSS: Низкий
github логотип

GHSA-37m2-v8vp-gx9v

10 месяцев назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-37m2-9j5v-c4v4

больше 1 года назад

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.

EPSS: Низкий
github логотип

GHSA-37jx-v87h-x8gc

больше 4 лет назад

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37jx-fgfr-x4xh

больше 4 лет назад

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-37jw-xgjq-3fmq

больше 4 лет назад

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37jw-9hhw-q8w8

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-37jv-v9vv-wxwv

4 месяца назад

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-37jv-rq4h-f78r

почти 2 года назад

Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-37jr-rxv8-wwqj

больше 4 лет назад

In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37m6-8rw8-wh8f

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

CVSS3: 3.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-37m6-73f6-jm7w

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37m6-2cm3-x5m2

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37m5-m4q3-fc6x

Froxlor: BIND Zone File Injection via TXT Record Content

CVSS3: 7.6
0%
Низкий
4 месяца назад
github логотип
GHSA-37m5-593h-89wf

In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37m5-42qp-4qpr

Cross-site scripting in LocalStack

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-37m4-w5jp-r3px

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37m4-hvw3-vwmc

Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-37m4-hqxv-w26g

XWiki Platform CSRF remote code execution through scheduler job's document reference

CVSS3: 9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37m3-qp37-x3c6

Apache Geode gfsh query vulnerability

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37m3-29m6-vgxq

PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37m2-v8vp-gx9v

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

10 месяцев назад
github логотип
GHSA-37m2-9j5v-c4v4

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.

2%
Низкий
больше 1 года назад
github логотип
GHSA-37jx-v87h-x8gc

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37jx-fgfr-x4xh

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.

CVSS3: 7.5
14%
Средний
больше 4 лет назад
github логотип
GHSA-37jw-xgjq-3fmq

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37jw-9hhw-q8w8

An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37jv-v9vv-wxwv

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CVSS3: 5.1
0%
Низкий
4 месяца назад
github логотип
GHSA-37jv-rq4h-f78r

Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-37jr-rxv8-wwqj

In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу