Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-34rf-vmxr-2fgx

больше 3 лет назад

The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34rf-p3r3-58x2

больше 2 лет назад

Gradio's Component Server does not properly consider` _is_server_fn` for functions

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34rf-84wq-9pwq

больше 1 года назад

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

EPSS: Низкий
github логотип

GHSA-34rf-7q76-c7fw

5 месяцев назад

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34rf-57fh-w2wg

10 месяцев назад

The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.com), an attacker can assume the session and gain full access to the target user's data and privileges. Also, if the email parameter is left blank, the application defaults to the first user in the list, who is typically the application administrator, resulting in an immediate Privilege Escalation to the highest level.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34rc-q3mr-hpv6

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15040.

EPSS: Низкий
github логотип

GHSA-34rc-844x-w698

больше 4 лет назад

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-34r9-jr37-pmrf

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: fix mes ring buffer overflow wait memory room until enough before writing mes packets to avoid ring buffer overflow. v2: squash in sched_hw_submission fix (cherry picked from commit 34e087e8920e635c62e2ed6a758b0cd27f836d13)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34r8-jwpj-vw8q

больше 4 лет назад

DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php. NOTE: this information leak might be resultant from a global variable overwrite issue.

EPSS: Низкий
github логотип

GHSA-34r8-h3gq-qmjj

больше 4 лет назад

UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34r8-fv4m-hxcv

больше 2 лет назад

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34r8-cjx6-5m3m

1 день назад

In the Linux kernel, the following vulnerability has been resolved: net: mana: Cap MSI-X vectors to the device MSI-X table size mana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix and the CPU count, but never from the device MSI-X table. On a 1792 vCPU M-series VM that yields 1793 while the table has 1024 entries, and mana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the end of the region mapped by msix_map_region(): BUG: unable to handle page fault for address: ff8e347f8b99800c RIP: 0010:msix_prepare_msi_desc+0x7a/0x90 RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000 Call Trace: <TASK> __msi_domain_alloc_irqs+0x13a/0x440 msi_domain_alloc_irq_at+0x149/0x1b0 mana_gd_setup+0x351/0x890 mana_gd_probe+0x274/0x390 </TASK> RAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table. msi_insert_desc() does range check the index, but only against the MSI domain hwsize, which matches the table on...

EPSS: Низкий
github логотип

GHSA-34r8-4w7f-49v8

больше 4 лет назад

XnView 2.03 has a stack-based buffer overflow vulnerability

EPSS: Низкий
github логотип

GHSA-34r7-v6pv-xq6v

2 месяца назад

Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and copied without bounds checking into a fixed-length stack buffer using strcpy(). Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r7-q49f-h37c

почти 9 лет назад

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34r6-xm35-5vcx

больше 4 лет назад

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r6-q8c8-23mx

около 1 года назад

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34r6-9vgg-pmh3

почти 3 года назад

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r5-q4jw-r36m

4 месяца назад

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

EPSS: Низкий
github логотип

GHSA-34r5-hj3h-jf22

больше 4 лет назад

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34rf-vmxr-2fgx

The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34rf-p3r3-58x2

Gradio's Component Server does not properly consider` _is_server_fn` for functions

CVSS3: 6.5
больше 2 лет назад
github логотип
GHSA-34rf-84wq-9pwq

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

0%
Низкий
больше 1 года назад
github логотип
GHSA-34rf-7q76-c7fw

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-34rf-57fh-w2wg

The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., otheruser@user.com), an attacker can assume the session and gain full access to the target user's data and privileges. Also, if the email parameter is left blank, the application defaults to the first user in the list, who is typically the application administrator, resulting in an immediate Privilege Escalation to the highest level.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-34rc-q3mr-hpv6

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15040.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34rc-844x-w698

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

CVSS3: 9.8
30%
Средний
больше 4 лет назад
github логотип
GHSA-34r9-jr37-pmrf

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: fix mes ring buffer overflow wait memory room until enough before writing mes packets to avoid ring buffer overflow. v2: squash in sched_hw_submission fix (cherry picked from commit 34e087e8920e635c62e2ed6a758b0cd27f836d13)

CVSS3: 7.8
около 2 лет назад
github логотип
GHSA-34r8-jwpj-vw8q

DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php. NOTE: this information leak might be resultant from a global variable overwrite issue.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34r8-h3gq-qmjj

UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-34r8-fv4m-hxcv

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34r8-cjx6-5m3m

In the Linux kernel, the following vulnerability has been resolved: net: mana: Cap MSI-X vectors to the device MSI-X table size mana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix and the CPU count, but never from the device MSI-X table. On a 1792 vCPU M-series VM that yields 1793 while the table has 1024 entries, and mana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the end of the region mapped by msix_map_region(): BUG: unable to handle page fault for address: ff8e347f8b99800c RIP: 0010:msix_prepare_msi_desc+0x7a/0x90 RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000 Call Trace: <TASK> __msi_domain_alloc_irqs+0x13a/0x440 msi_domain_alloc_irq_at+0x149/0x1b0 mana_gd_setup+0x351/0x890 mana_gd_probe+0x274/0x390 </TASK> RAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table. msi_insert_desc() does range check the index, but only against the MSI domain hwsize, which matches the table on...

1 день назад
github логотип
GHSA-34r8-4w7f-49v8

XnView 2.03 has a stack-based buffer overflow vulnerability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34r7-v6pv-xq6v

Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and copied without bounds checking into a fixed-length stack buffer using strcpy(). Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.

CVSS3: 6.5
1%
Низкий
2 месяца назад
github логотип
GHSA-34r7-q49f-h37c

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

CVSS3: 9.8
4%
Низкий
почти 9 лет назад
github логотип
GHSA-34r6-xm35-5vcx

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-34r6-q8c8-23mx

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-34r6-9vgg-pmh3

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-34r5-q4jw-r36m

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

0%
Низкий
4 месяца назад
github логотип
GHSA-34r5-hj3h-jf22

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVSS3: 2.7
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу