Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-22j6-v8cr-pvvx

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: locking/csd_lock: Change csdlock_debug from early_param to __setup The csdlock_debug kernel-boot parameter is parsed by the early_param() function csdlock_debug(). If set, csdlock_debug() invokes static_branch_enable() to enable csd_lock_wait feature, which triggers a panic on arm64 for kernels built with CONFIG_SPARSEMEM=y and CONFIG_SPARSEMEM_VMEMMAP=n. With CONFIG_SPARSEMEM_VMEMMAP=n, __nr_to_section is called in static_key_enable() and returns NULL, resulting in a NULL dereference because mem_section is initialized only later in sparse_init(). This is also a problem for powerpc because early_param() functions are invoked earlier than jump_label_init(), also resulting in static_key_enable() failures. These failures cause the warning "static key 'xxx' used before call to jump_label_init()". Thus, early_param is too early for csd_lock_wait to run static_branch_enable(), so changes it to __setup to fix these.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22j6-m7vc-p547

больше 4 лет назад

The faailkhair (aka com.faailkhair.app) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22j5-vqxp-92q2

больше 4 лет назад

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22j5-63rc-6cq9

больше 2 лет назад

Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-22j5-38qv-pxx7

около 8 лет назад

sqliter is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22j4-xx7v-8r2r

больше 4 лет назад

SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-22j4-qc48-j8f8

больше 3 лет назад

Apache InLong vulnerable to Deserialization of Untrusted Data vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22j3-6r5q-rjwj

около 3 лет назад

Local user may lead to privilege escalation using Gaia Portal hostnames page.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-22j3-3q48-2rmj

3 месяца назад

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22j2-rr3r-x36m

около 1 года назад

A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-22j2-mxcq-m52p

больше 2 лет назад

In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22j2-mp37-f8p9

больше 4 лет назад

SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.

EPSS: Низкий
github логотип

GHSA-22j2-jp4f-7gwx

9 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-22j2-46v6-f42v

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

EPSS: Низкий
github логотип

GHSA-22j2-38xj-5937

больше 1 года назад

Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager allows Object Injection. This issue affects Job Board Manager: from n/a through 2.1.60.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22hx-9864-2fvh

больше 4 лет назад

A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22hw-w3w3-w53p

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Carrrot plugin <= 1.1.0 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-22hw-79wf-v743

больше 3 лет назад

The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-22hw-3cx7-9m9g

больше 4 лет назад

The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.

EPSS: Низкий
github логотип

GHSA-22hv-hj5v-qg3v

больше 4 лет назад

The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22j6-v8cr-pvvx

In the Linux kernel, the following vulnerability has been resolved: locking/csd_lock: Change csdlock_debug from early_param to __setup The csdlock_debug kernel-boot parameter is parsed by the early_param() function csdlock_debug(). If set, csdlock_debug() invokes static_branch_enable() to enable csd_lock_wait feature, which triggers a panic on arm64 for kernels built with CONFIG_SPARSEMEM=y and CONFIG_SPARSEMEM_VMEMMAP=n. With CONFIG_SPARSEMEM_VMEMMAP=n, __nr_to_section is called in static_key_enable() and returns NULL, resulting in a NULL dereference because mem_section is initialized only later in sparse_init(). This is also a problem for powerpc because early_param() functions are invoked earlier than jump_label_init(), also resulting in static_key_enable() failures. These failures cause the warning "static key 'xxx' used before call to jump_label_init()". Thus, early_param is too early for csd_lock_wait to run static_branch_enable(), so changes it to __setup to fix these.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-22j6-m7vc-p547

The faailkhair (aka com.faailkhair.app) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-22j5-vqxp-92q2

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-22j5-63rc-6cq9

Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.

CVSS3: 7.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22j5-38qv-pxx7

sqliter is malware

CVSS3: 7.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-22j4-xx7v-8r2r

SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22j4-qc48-j8f8

Apache InLong vulnerable to Deserialization of Untrusted Data vulnerability

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22j3-6r5q-rjwj

Local user may lead to privilege escalation using Gaia Portal hostnames page.

CVSS3: 7.2
21%
Средний
около 3 лет назад
github логотип
GHSA-22j3-3q48-2rmj

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-22j2-rr3r-x36m

A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-22j2-mxcq-m52p

In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-22j2-mp37-f8p9

SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-22j2-jp4f-7gwx

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

9 дней назад
github логотип
GHSA-22j2-46v6-f42v

PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-22j2-38xj-5937

Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager allows Object Injection. This issue affects Job Board Manager: from n/a through 2.1.60.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-22hx-9864-2fvh

A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-22hw-w3w3-w53p

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Carrrot plugin <= 1.1.0 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-22hw-79wf-v743

The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22hw-3cx7-9m9g

The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-22hv-hj5v-qg3v

The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS3: 6.1
34%
Средний
больше 4 лет назад

Уязвимостей на страницу