Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-23fw-5352-7h9v

почти 2 года назад

Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23fv-pj9m-qvh4

больше 3 лет назад

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23fv-m8pv-77j9

около 4 лет назад

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23fr-29gc-hh5j

больше 4 лет назад

McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

EPSS: Низкий
github логотип

GHSA-23fq-q7hc-993r

почти 5 лет назад

HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23fq-fj6g-jf68

больше 4 лет назад

IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

EPSS: Низкий
github логотип

GHSA-23fq-26rx-3gc4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.

EPSS: Низкий
github логотип

GHSA-23fp-xqj8-q68w

больше 4 лет назад

SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

EPSS: Низкий
github логотип

GHSA-23fp-wmqj-rfh4

11 месяцев назад

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_LT.ASP'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23fp-mrfv-cwv4

около 1 года назад

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern.

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-23fp-mccx-jgj3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23fp-fmrv-f5px

больше 4 лет назад

Uncontrolled Resource Consumption in strapi

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-23fm-wgmf-mc43

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-23fm-v895-3qxq

около 4 лет назад

jh_captcha for Typo3 XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23fj-h8hh-93x3

3 месяца назад

A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx of the component Generic React API. This manipulation of the argument cancelledBy/rescheduledBy causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23fj-gx6v-3x6c

больше 4 лет назад

The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23fj-6rwp-5rq6

около 1 года назад

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23fg-w3cv-jf6w

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23fg-rq88-2h56

около 4 лет назад

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.

EPSS: Низкий
github логотип

GHSA-23ff-wfv3-xrvg

больше 1 года назад

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23fw-5352-7h9v

Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-23fv-pj9m-qvh4

webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fv-m8pv-77j9

HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-23fr-29gc-hh5j

McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-23fq-q7hc-993r

HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0

CVSS3: 9.8
0%
Низкий
почти 5 лет назад
github логотип
GHSA-23fq-fj6g-jf68

IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-23fq-26rx-3gc4

Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23fp-xqj8-q68w

SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23fp-wmqj-rfh4

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_LT.ASP'.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-23fp-mrfv-cwv4

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern.

CVSS3: 10
77%
Высокий
около 1 года назад
github логотип
GHSA-23fp-mccx-jgj3

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23fp-fmrv-f5px

Uncontrolled Resource Consumption in strapi

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23fm-wgmf-mc43

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-23fm-v895-3qxq

jh_captcha for Typo3 XSS Vulnerability

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-23fj-h8hh-93x3

A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx of the component Generic React API. This manipulation of the argument cancelledBy/rescheduledBy causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-23fj-gx6v-3x6c

The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23fj-6rwp-5rq6

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-23fg-w3cv-jf6w

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-23fg-rq88-2h56

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.

0%
Низкий
около 4 лет назад
github логотип
GHSA-23ff-wfv3-xrvg

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу