Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-23j8-j8rc-c9hw

около 4 лет назад

When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23j8-hxrw-3w4c

4 месяца назад

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-23j7-qm67-668g

6 месяцев назад

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-23j7-px3w-jwp2

около 1 года назад

Jenkins Xooa Plugin vulnerability does not mask its Xooa Deployment Token

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23j7-2rxw-3q84

больше 2 лет назад

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250444.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23j5-p74r-rvqm

около 4 лет назад

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

EPSS: Низкий
github логотип

GHSA-23j5-87fx-hgc9

6 месяцев назад

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in `PayPalSettings.php`). This makes it possible for unauthenticated attackers to send forged PayPal IPN notifications to the publicly accessible IPN endpoint, marking unpaid form submissions as "paid" and triggering post-payment automation (emails, access grants, digital product delivery).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23j5-3m4p-44jj

9 дней назад

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-23j4-mw76-5v7h

около 2 лет назад

Scrapy allows redirect following in protocols other than HTTP

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23j3-qh8r-rpx6

больше 4 лет назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

EPSS: Низкий
github логотип

GHSA-23j2-8hh8-295f

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix possible memory leak in hpsa_init_one() The hpda_alloc_ctlr_info() allocates h and its field reply_map. However, in hpsa_init_one(), if alloc_percpu() failed, the hpsa_init_one() jumps to clean1 directly, which frees h and leaks the h->reply_map. Fix by calling hpda_free_ctlr_info() to release h->replay_map and h instead free h directly.

EPSS: Низкий
github логотип

GHSA-23hx-rv96-mjqx

около 4 лет назад

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

EPSS: Низкий
github логотип

GHSA-23hx-gmq6-vwxq

около 4 лет назад

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

EPSS: Низкий
github логотип

GHSA-23hx-3f44-x72r

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23hw-vp6g-7987

около 1 года назад

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-23hw-462m-2wh4

6 месяцев назад

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23hv-mwm6-g8jf

12 месяцев назад

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23hv-h2r7-ggj5

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23hv-gjhm-8vrh

11 месяцев назад

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23hr-frj7-4j88

больше 4 лет назад

SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23j8-j8rc-c9hw

When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-23j8-hxrw-3w4c

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-23j7-qm67-668g

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

CVSS3: 4.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-23j7-px3w-jwp2

Jenkins Xooa Plugin vulnerability does not mask its Xooa Deployment Token

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-23j7-2rxw-3q84

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250444.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23j5-p74r-rvqm

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

0%
Низкий
около 4 лет назад
github логотип
GHSA-23j5-87fx-hgc9

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in `PayPalSettings.php`). This makes it possible for unauthenticated attackers to send forged PayPal IPN notifications to the publicly accessible IPN endpoint, marking unpaid form submissions as "paid" and triggering post-payment automation (emails, access grants, digital product delivery).

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-23j5-3m4p-44jj

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.

CVSS3: 6
0%
Низкий
9 дней назад
github логотип
GHSA-23j4-mw76-5v7h

Scrapy allows redirect following in protocols other than HTTP

CVSS3: 6.5
около 2 лет назад
github логотип
GHSA-23j3-qh8r-rpx6

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23j2-8hh8-295f

In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix possible memory leak in hpsa_init_one() The hpda_alloc_ctlr_info() allocates h and its field reply_map. However, in hpsa_init_one(), if alloc_percpu() failed, the hpsa_init_one() jumps to clean1 directly, which frees h and leaks the h->reply_map. Fix by calling hpda_free_ctlr_info() to release h->replay_map and h instead free h directly.

0%
Низкий
8 месяцев назад
github логотип
GHSA-23hx-rv96-mjqx

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

0%
Низкий
около 4 лет назад
github логотип
GHSA-23hx-gmq6-vwxq

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

3%
Низкий
около 4 лет назад
github логотип
GHSA-23hx-3f44-x72r

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-23hw-vp6g-7987

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-23hw-462m-2wh4

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-23hv-mwm6-g8jf

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
1%
Низкий
12 месяцев назад
github логотип
GHSA-23hv-h2r7-ggj5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-23hv-gjhm-8vrh

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
4%
Низкий
11 месяцев назад
github логотип
GHSA-23hr-frj7-4j88

SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу