Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36m2-6ffw-3pwx

больше 4 лет назад

Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36jx-769r-m5fx

11 месяцев назад

Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Forms - Frontend Listing: from n/a through <= 1.0.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36jv-w59f-85w3

больше 1 года назад

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-36jv-3f2h-6vpg

почти 4 года назад

A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212681 was assigned to this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36jr-mh4h-2g58

почти 4 года назад

d3-color vulnerable to ReDoS

EPSS: Низкий
github логотип

GHSA-36jr-8w83-wr8q

почти 2 года назад

Visual Studio Code Python Extension Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36jr-35r6-vp2p

10 месяцев назад

Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36jp-c3g9-9g26

больше 1 года назад

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36jp-7r52-9h73

больше 4 лет назад

GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-36jj-qr3q-4cm4

больше 4 лет назад

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."

EPSS: Низкий
github логотип

GHSA-36jj-p27h-fh24

больше 4 лет назад

The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36jj-jw5h-6rp8

около 1 месяца назад

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36jj-833r-p2f4

больше 4 лет назад

openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.

EPSS: Низкий
github логотип

GHSA-36jj-6rjq-5jrm

больше 2 лет назад

An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-36jg-fqm9-hv24

8 месяцев назад

Missing Authorization vulnerability in WANotifier WANotifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WANotifier: from n/a through <= 2.7.12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36jg-66x9-j4gg

около 2 лет назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-36jf-c365-9q55

10 дней назад

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the WebRTC2RTMP helper binary (revealing the document-root path), the configured WebRTC port, file_exists/is_executable status for the binary, the contents of the WebRTC log/JSON files (videos/WebRTC2RTMP.log) when present, and whether the configured port is reachable on loopback (127.0.0.1) and on the public address. The endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() check. The issue was unfixed at the time of reporting.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36jc-62gq-crx2

больше 4 лет назад

Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-36j9-v89w-79c6

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ptp_qoriq: fix memory leak in probe() Smatch complains that: drivers/ptp/ptp_qoriq.c ptp_qoriq_probe() warn: 'base' from ioremap() not released. Fix this by revising the parameter from 'ptp_qoriq->base' to 'base'. This is only a bug if ptp_qoriq_init() returns on the first -ENODEV error path. For other error paths ptp_qoriq->base and base are the same. And this change makes the code more readable.

EPSS: Низкий
github логотип

GHSA-36j9-mx87-2cff

8 месяцев назад

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36m2-6ffw-3pwx

Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36jx-769r-m5fx

Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Forms - Frontend Listing: from n/a through <= 1.0.5.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-36jv-w59f-85w3

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-36jv-3f2h-6vpg

A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212681 was assigned to this vulnerability.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-36jr-mh4h-2g58

d3-color vulnerable to ReDoS

почти 4 года назад
github логотип
GHSA-36jr-8w83-wr8q

Visual Studio Code Python Extension Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-36jr-35r6-vp2p

Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-36jp-c3g9-9g26

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-36jp-7r52-9h73

GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36jj-qr3q-4cm4

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36jj-p27h-fh24

The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-36jj-jw5h-6rp8

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-36jj-833r-p2f4

openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36jj-6rjq-5jrm

An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.

CVSS3: 7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36jg-fqm9-hv24

Missing Authorization vulnerability in WANotifier WANotifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WANotifier: from n/a through <= 2.7.12.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-36jg-66x9-j4gg

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

около 2 лет назад
github логотип
GHSA-36jf-c365-9q55

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the WebRTC2RTMP helper binary (revealing the document-root path), the configured WebRTC port, file_exists/is_executable status for the binary, the contents of the WebRTC log/JSON files (videos/WebRTC2RTMP.log) when present, and whether the configured port is reachable on loopback (127.0.0.1) and on the public address. The endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() check. The issue was unfixed at the time of reporting.

CVSS3: 5.3
0%
Низкий
10 дней назад
github логотип
GHSA-36jc-62gq-crx2

Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36j9-v89w-79c6

In the Linux kernel, the following vulnerability has been resolved: ptp_qoriq: fix memory leak in probe() Smatch complains that: drivers/ptp/ptp_qoriq.c ptp_qoriq_probe() warn: 'base' from ioremap() not released. Fix this by revising the parameter from 'ptp_qoriq->base' to 'base'. This is only a bug if ptp_qoriq_init() returns on the first -ENODEV error path. For other error paths ptp_qoriq->base and base are the same. And this change makes the code more readable.

0%
Низкий
9 месяцев назад
github логотип
GHSA-36j9-mx87-2cff

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

CVSS3: 6.7
8 месяцев назад

Уязвимостей на страницу