Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-23qr-p57h-8gx4

около 4 лет назад

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23qq-wph5-jwww

около 3 лет назад

An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-23qq-p4gq-gc2g

больше 2 лет назад

WordOps has TOCTOU race condition

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-23qp-f5g5-j76h

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix ID register initialization for non-protected pKVM guests In protected mode, the hypervisor maintains a separate instance of the `kvm` structure for each VM. For non-protected VMs, this structure is initialized from the host's `kvm` state. Currently, `pkvm_init_features_from_host()` copies the `KVM_ARCH_FLAG_ID_REGS_INITIALIZED` flag from the host without the underlying `id_regs` data being initialized. This results in the hypervisor seeing the flag as set while the ID registers remain zeroed. Consequently, `kvm_has_feat()` checks at EL2 fail (return 0) for non-protected VMs. This breaks logic that relies on feature detection, such as `ctxt_has_tcrx()` for TCR2_EL1 support. As a result, certain system registers (e.g., TCR2_EL1, PIR_EL1, POR_EL1) are not saved/restored during the world switch, which could lead to state corruption. Fix this by explicitly copying the ID registers from the host `kvm`...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23qp-3c2m-xx6w

больше 1 года назад

wasmvm: Malicious smart contract can crash the chain

EPSS: Низкий
github логотип

GHSA-23qm-j98q-xr7j

больше 3 лет назад

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-23qm-g3r4-35xx

10 месяцев назад

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.4.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23qj-fcjw-2v26

больше 4 лет назад

Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.

EPSS: Низкий
github логотип

GHSA-23qj-c6v6-57hx

около 4 лет назад

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784351; Issue ID: ALPS06784351.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23qj-5qgc-98rc

почти 3 года назад

An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23qh-6x5w-x4r7

больше 3 лет назад

Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager. While the vulnerability is in Oracle Database Recovery Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database Recovery Manager. CVSS 3.1 Base Score 6.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-23qf-p445-3vhr

больше 4 лет назад

An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23qf-mx2g-p3gq

больше 2 лет назад

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-23qf-cvxj-h26r

8 месяцев назад

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The vulnerability can be triggered by providing a maliciously crafted auth.ini file on the device's SD card.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-23qf-8c5g-2ccx

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks allows Stored XSS. This issue affects Arkhe Blocks: from n/a through 2.27.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23qf-3jf9-h3q9

около 3 лет назад

Apache NiFi Insufficient Property Validation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23qc-j7fh-79jg

больше 4 лет назад

IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918

EPSS: Низкий
github логотип

GHSA-23qc-j55g-qfm7

больше 4 лет назад

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

EPSS: Низкий
github логотип

GHSA-23qc-7hjx-vwmv

почти 2 года назад

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23q9-v5c2-xg7m

больше 4 лет назад

PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23qr-p57h-8gx4

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-23qq-wph5-jwww

An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-23qq-p4gq-gc2g

WordOps has TOCTOU race condition

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23qp-f5g5-j76h

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix ID register initialization for non-protected pKVM guests In protected mode, the hypervisor maintains a separate instance of the `kvm` structure for each VM. For non-protected VMs, this structure is initialized from the host's `kvm` state. Currently, `pkvm_init_features_from_host()` copies the `KVM_ARCH_FLAG_ID_REGS_INITIALIZED` flag from the host without the underlying `id_regs` data being initialized. This results in the hypervisor seeing the flag as set while the ID registers remain zeroed. Consequently, `kvm_has_feat()` checks at EL2 fail (return 0) for non-protected VMs. This breaks logic that relies on feature detection, such as `ctxt_has_tcrx()` for TCR2_EL1 support. As a result, certain system registers (e.g., TCR2_EL1, PIR_EL1, POR_EL1) are not saved/restored during the world switch, which could lead to state corruption. Fix this by explicitly copying the ID registers from the host `kvm`...

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-23qp-3c2m-xx6w

wasmvm: Malicious smart contract can crash the chain

больше 1 года назад
github логотип
GHSA-23qm-j98q-xr7j

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.

CVSS3: 9.9
3%
Низкий
больше 3 лет назад
github логотип
GHSA-23qm-g3r4-35xx

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.4.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-23qj-fcjw-2v26

Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-23qj-c6v6-57hx

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784351; Issue ID: ALPS06784351.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-23qj-5qgc-98rc

An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
github логотип
GHSA-23qh-6x5w-x4r7

Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager. While the vulnerability is in Oracle Database Recovery Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database Recovery Manager. CVSS 3.1 Base Score 6.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).

CVSS3: 6.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23qf-p445-3vhr

An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-23qf-mx2g-p3gq

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

CVSS3: 4.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23qf-cvxj-h26r

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The vulnerability can be triggered by providing a maliciously crafted auth.ini file on the device's SD card.

CVSS3: 8.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-23qf-8c5g-2ccx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks allows Stored XSS. This issue affects Arkhe Blocks: from n/a through 2.27.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23qf-3jf9-h3q9

Apache NiFi Insufficient Property Validation vulnerability

CVSS3: 6.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-23qc-j7fh-79jg

IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23qc-j55g-qfm7

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-23qc-7hjx-vwmv

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-23q9-v5c2-xg7m

PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу