Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-22p8-j48p-jr45

больше 4 лет назад

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

EPSS: Низкий
github логотип

GHSA-22p7-jgf7-772h

3 месяца назад

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers to update the plugin's settings, including injecting malicious scripts that will be stored and executed in the admin area, via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22p7-7xrf-xxhr

около 4 лет назад

The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

EPSS: Низкий
github логотип

GHSA-22p7-26xx-rjp2

9 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.

EPSS: Низкий
github логотип

GHSA-22p7-2347-c784

больше 3 лет назад

A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22p6-w2px-4gj3

11 месяцев назад

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22p6-rw8w-cm9m

около 4 лет назад

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22p6-c9vr-pq5x

около 2 лет назад

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22p6-5mp7-g3v6

почти 4 года назад

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22p5-hr7r-x3qv

около 4 лет назад

The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22p5-88qf-j835

около 4 лет назад

Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.

EPSS: Низкий
github логотип

GHSA-22p3-qrh9-cx32

около 4 лет назад

URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22p3-cw83-672h

5 месяцев назад

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-22p2-wgx4-4rg8

около 4 лет назад

SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

EPSS: Низкий
github логотип

GHSA-22mx-qh6h-fcv2

больше 3 лет назад

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22mx-9r92-42g8

около 4 лет назад

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-22mx-7hxm-5fcw

больше 1 года назад

IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-22mx-5372-vwv3

10 месяцев назад

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT AUTHORITY\NetworkService' privileges. In Newforma before 2023.1, anonymous access is enabled by default (CVE-2025-35062), allowing an otherwise unauthenticated attacker to effectively authenticate as 'anonymous' and exploit this file upload vulnerability.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-22mx-4vrq-5mfr

около 4 лет назад

In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220011.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22mx-2pf3-v75r

около 4 лет назад

Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before 2.1.0.9, Docker Desktop for Windows Stable before 2.2.0.4, and Docker Desktop for Windows Edge before 2.2.2.0.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22p8-j48p-jr45

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-22p7-jgf7-772h

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers to update the plugin's settings, including injecting malicious scripts that will be stored and executed in the admin area, via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-22p7-7xrf-xxhr

The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

0%
Низкий
около 4 лет назад
github логотип
GHSA-22p7-26xx-rjp2

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.

0%
Низкий
9 месяцев назад
github логотип
GHSA-22p7-2347-c784

A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22p6-w2px-4gj3

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-22p6-rw8w-cm9m

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-22p6-c9vr-pq5x

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-22p6-5mp7-g3v6

IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-22p5-hr7r-x3qv

The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

CVSS3: 7.8
8%
Низкий
около 4 лет назад
github логотип
GHSA-22p5-88qf-j835

Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22p3-qrh9-cx32

URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-22p3-cw83-672h

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel.

CVSS3: 8.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-22p2-wgx4-4rg8

SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22mx-qh6h-fcv2

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22mx-9r92-42g8

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
7%
Низкий
около 4 лет назад
github логотип
GHSA-22mx-7hxm-5fcw

IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-22mx-5372-vwv3

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT AUTHORITY\NetworkService' privileges. In Newforma before 2023.1, anonymous access is enabled by default (CVE-2025-35062), allowing an otherwise unauthenticated attacker to effectively authenticate as 'anonymous' and exploit this file upload vulnerability.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-22mx-4vrq-5mfr

In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220011.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-22mx-2pf3-v75r

Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before 2.1.0.9, Docker Desktop for Windows Stable before 2.2.0.4, and Docker Desktop for Windows Edge before 2.2.2.0.

CVSS3: 6.7
1%
Низкий
около 4 лет назад

Уязвимостей на страницу