Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35p6-xmwp-9g52

3 месяца назад

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-35p6-x466-363j

больше 1 года назад

Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35p6-jmhj-fg2v

больше 4 лет назад

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.

EPSS: Низкий
github логотип

GHSA-35p6-jj8w-qmx6

больше 4 лет назад

A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-35p5-87vc-w659

больше 1 года назад

The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35p5-4434-v68p

больше 4 лет назад

A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.

EPSS: Низкий
github логотип

GHSA-35p4-v2g5-v64x

больше 4 лет назад

tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.

EPSS: Низкий
github логотип

GHSA-35p4-hgm9-xjp2

больше 4 лет назад

The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35p4-9mmc-6xh6

больше 4 лет назад

SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-35p4-8325-mm2c

больше 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35p3-6j45-prwm

больше 1 года назад

Aim Uncontrolled Resource Consumption vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35p2-v8mc-67vh

больше 1 года назад

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-35p2-9fg3-f2p2

около 3 лет назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35p2-8gmg-pp6j

больше 2 лет назад

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35p2-5vrh-m3p6

больше 1 года назад

DevDojo Voyager Arbitrary File Write

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-35mx-p6x7-pwmc

больше 4 лет назад

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35mw-8r7p-2p48

25 дней назад

Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mw-5vvr-vrxc

5 месяцев назад

OpenClaw contains a symlink traversal vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mv-vrc8-4x74

больше 4 лет назад

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35mv-px68-wh6h

больше 4 лет назад

SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35p6-xmwp-9g52

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-35p6-x466-363j

Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35p6-jmhj-fg2v

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35p6-jj8w-qmx6

A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35p5-87vc-w659

The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35p5-4434-v68p

A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35p4-v2g5-v64x

tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35p4-hgm9-xjp2

The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35p4-9mmc-6xh6

SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35p4-8325-mm2c

Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35p3-6j45-prwm

Aim Uncontrolled Resource Consumption vulnerability

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-35p2-v8mc-67vh

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-35p2-9fg3-f2p2

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-35p2-8gmg-pp6j

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35p2-5vrh-m3p6

DevDojo Voyager Arbitrary File Write

CVSS3: 4.3
14%
Средний
больше 1 года назад
github логотип
GHSA-35mx-p6x7-pwmc

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-35mw-8r7p-2p48

Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
25 дней назад
github логотип
GHSA-35mw-5vvr-vrxc

OpenClaw contains a symlink traversal vulnerability

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-35mv-vrc8-4x74

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mv-px68-wh6h

SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу