Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-23hm-7w47-xw72

больше 4 лет назад

Out of bounds read in Tensorflow

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23hm-6gvp-w3w5

5 месяцев назад

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23hh-8f6m-x9cp

больше 4 лет назад

ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.

EPSS: Низкий
github логотип

GHSA-23hh-7w49-jrpv

9 месяцев назад

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePath leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The identifier of the patch is 45372aece5e05e04b417442417416a52e90ba174. To fix this issue, it is recommended to deploy a patch.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23hh-6pg2-wjj5

больше 4 лет назад

An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23hh-2f47-3p4h

7 месяцев назад

MineAdmin has Incorrect Privilege Assignment

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23hg-53q6-hqfg

12 месяцев назад

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-23hf-jhww-867g

больше 4 лет назад

The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.

EPSS: Низкий
github логотип

GHSA-23hc-wwmg-vgj2

больше 4 лет назад

SQL injection vulnerability in articles\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE.

EPSS: Низкий
github логотип

GHSA-23hc-w3jx-2m5j

больше 4 лет назад

CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.

EPSS: Низкий
github логотип

GHSA-23hc-gf5p-jq23

10 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.5.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-23h9-xj7q-3m7r

больше 1 года назад

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23h9-m55m-c5jp

больше 4 лет назад

Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23h9-h5hh-w97x

больше 4 лет назад

Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.

EPSS: Низкий
github логотип

GHSA-23h8-xfh3-46wm

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23h8-ggh4-vmhv

больше 2 лет назад

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-23h8-7x35-v9v9

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy_scheme Currently, damon_destroy_scheme() only cleans up the filter list but leaves ops_filter untouched, which could lead to memory leaks when a scheme is destroyed. This patch ensures both filter and ops_filter are properly freed in damon_destroy_scheme(), preventing potential memory leaks.

EPSS: Низкий
github логотип

GHSA-23h8-4q9g-xc4f

больше 2 лет назад

A maliciously crafted STP file in ASMKERN228A.dll or ASMDATAX228A.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23h7-68rq-jgvf

6 месяцев назад

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-23h5-crhx-4jpw

5 месяцев назад

A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23hm-7w47-xw72

Out of bounds read in Tensorflow

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23hm-6gvp-w3w5

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

CVSS3: 6.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-23hh-8f6m-x9cp

ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23hh-7w49-jrpv

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePath leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The identifier of the patch is 45372aece5e05e04b417442417416a52e90ba174. To fix this issue, it is recommended to deploy a patch.

CVSS3: 8.1
1%
Низкий
9 месяцев назад
github логотип
GHSA-23hh-6pg2-wjj5

An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23hh-2f47-3p4h

MineAdmin has Incorrect Privilege Assignment

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-23hg-53q6-hqfg

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-23hf-jhww-867g

The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-23hc-wwmg-vgj2

SQL injection vulnerability in articles\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23hc-w3jx-2m5j

CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-23hc-gf5p-jq23

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.5.

CVSS3: 7.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-23h9-xj7q-3m7r

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-23h9-m55m-c5jp

Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-23h9-h5hh-w97x

Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23h8-xfh3-46wm

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-23h8-ggh4-vmhv

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.

CVSS3: 4.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23h8-7x35-v9v9

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy_scheme Currently, damon_destroy_scheme() only cleans up the filter list but leaves ops_filter untouched, which could lead to memory leaks when a scheme is destroyed. This patch ensures both filter and ops_filter are properly freed in damon_destroy_scheme(), preventing potential memory leaks.

0%
Низкий
9 месяцев назад
github логотип
GHSA-23h8-4q9g-xc4f

A maliciously crafted STP file in ASMKERN228A.dll or ASMDATAX228A.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23h7-68rq-jgvf

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-23h5-crhx-4jpw

A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу