Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35rc-qr7q-j9jm

больше 4 лет назад

Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130

EPSS: Низкий
github логотип

GHSA-35rc-fmpw-cvfv

больше 1 года назад

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35rc-2vcv-r6q5

2 месяца назад

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-35r9-gfqf-r6cw

около 4 лет назад

Missing permission check in Jenkins vRealize Orchestrator Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35r8-c3gc-mfvr

больше 2 лет назад

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35r7-w24m-px2g

больше 4 лет назад

A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

EPSS: Средний
github логотип

GHSA-35r7-vh9q-xpf7

почти 3 года назад

Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-35r7-4rp8-9885

больше 4 лет назад

Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-35r6-wcp2-v9mw

2 месяца назад

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35r6-q59h-rp4f

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz allows PHP Local File Inclusion. This issue affects Avaz: from n/a through 2.8.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-35r6-7qjq-22gr

11 дней назад

The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-35r5-x2r5-c49q

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35r5-pw6j-5f37

больше 4 лет назад

Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.

EPSS: Низкий
github логотип

GHSA-35r5-j2wv-ff34

больше 1 года назад

Missing Authorization vulnerability in quillforms.com Quill Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through 3.3.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35r4-97wh-88x3

больше 4 лет назад

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

EPSS: Низкий
github логотип

GHSA-35r4-377q-pc5v

почти 2 года назад

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35r3-xfww-vf6j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35qx-qjjj-9pfh

около 1 года назад

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35qx-pprw-fwph

больше 3 лет назад

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-35qx-m8hh-rrjv

больше 4 лет назад

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35rc-qr7q-j9jm

Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35rc-fmpw-cvfv

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-35rc-2vcv-r6q5

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS3: 10
85%
Высокий
2 месяца назад
github логотип
GHSA-35r9-gfqf-r6cw

Missing permission check in Jenkins vRealize Orchestrator Plugin

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-35r8-c3gc-mfvr

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35r7-w24m-px2g

A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

12%
Средний
больше 4 лет назад
github логотип
GHSA-35r7-vh9q-xpf7

Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
25%
Средний
почти 3 года назад
github логотип
GHSA-35r7-4rp8-9885

Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35r6-wcp2-v9mw

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-35r6-q59h-rp4f

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz allows PHP Local File Inclusion. This issue affects Avaz: from n/a through 2.8.

CVSS3: 8.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-35r6-7qjq-22gr

The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.

CVSS3: 4.9
0%
Низкий
11 дней назад
github логотип
GHSA-35r5-x2r5-c49q

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35r5-pw6j-5f37

Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35r5-j2wv-ff34

Missing Authorization vulnerability in quillforms.com Quill Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through 3.3.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35r4-97wh-88x3

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35r4-377q-pc5v

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-35r3-xfww-vf6j

In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35qx-qjjj-9pfh

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-35qx-pprw-fwph

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164.

CVSS3: 2.4
2%
Низкий
больше 3 лет назад
github логотип
GHSA-35qx-m8hh-rrjv

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу