Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-2645-7hqp-7qr7

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Bounds check struct nfc_target arrays While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported: memcpy: detected field-spanning write (size 129) of single field "target->sensf_res" at net/nfc/nci/ntf.c:260 (size 18) This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2644-jxq3-c5rc

больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2644-f36h-q8x8

около 3 лет назад

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-2643-mcgh-r47h

17 дней назад

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2643-m3hh-2g9v

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2642-rv5v-5j93

около 4 лет назад

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2642-rp37-gfgx

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue affects WP TripAdvisor Review Slider: from n/a through 12.6.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-263x-9fgq-56vg

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1) creating a topic or (2) posting an answer. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-263x-7287-228p

около 2 месяцев назад

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-263w-f6fg-v2x5

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req() This happens when called from SMB2_read() while using rdma and reaching the rdma_readwrite_threshold.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-263w-c8fq-43wx

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in viewtopic.php in phpBB 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.

EPSS: Низкий
github логотип

GHSA-263w-6jpf-2h2q

больше 4 лет назад

The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message.

EPSS: Низкий
github логотип

GHSA-263w-3fx9-r885

больше 4 лет назад

In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892

EPSS: Низкий
github логотип

GHSA-263v-qw54-cmjj

больше 4 лет назад

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

EPSS: Низкий
github логотип

GHSA-263v-6w9h-xf97

больше 4 лет назад

The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Group Info feature, e.g., by adding a significant fraction of a region's assigned phone numbers.

EPSS: Низкий
github логотип

GHSA-263v-2h45-xhrp

около 4 лет назад

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Fabric Layer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-263v-2chg-v88w

5 месяцев назад

A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function queryResult of the file server\app\adminapi\lists\tools\DataTableLists.php of the component dataTable Admin API. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-263q-6c66-xx88

больше 3 лет назад

Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-263q-5pj7-j6hj

больше 4 лет назад

CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-263q-5cv3-xq9g

9 месяцев назад

Gitea allows attackers to add attachments with forbidden file extensions

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2645-7hqp-7qr7

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Bounds check struct nfc_target arrays While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported: memcpy: detected field-spanning write (size 129) of single field "target->sensf_res" at net/nfc/nci/ntf.c:260 (size 18) This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2644-jxq3-c5rc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2644-f36h-q8x8

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.

CVSS3: 9
2%
Низкий
около 3 лет назад
github логотип
GHSA-2643-mcgh-r47h

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.

CVSS3: 7.6
0%
Низкий
17 дней назад
github логотип
GHSA-2643-m3hh-2g9v

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-2642-rv5v-5j93

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2642-rp37-gfgx

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue affects WP TripAdvisor Review Slider: from n/a through 12.6.

CVSS3: 7.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-263x-9fgq-56vg

Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1) creating a topic or (2) posting an answer. NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-263x-7287-228p

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-263w-f6fg-v2x5

In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req() This happens when called from SMB2_read() while using rdma and reaching the rdma_readwrite_threshold.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-263w-c8fq-43wx

Cross-site scripting (XSS) vulnerability in viewtopic.php in phpBB 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-263w-6jpf-2h2q

The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-263w-3fx9-r885

In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892

0%
Низкий
больше 4 лет назад
github логотип
GHSA-263v-qw54-cmjj

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-263v-6w9h-xf97

The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Group Info feature, e.g., by adding a significant fraction of a region's assigned phone numbers.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-263v-2h45-xhrp

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Fabric Layer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-263v-2chg-v88w

A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function queryResult of the file server\app\adminapi\lists\tools\DataTableLists.php of the component dataTable Admin API. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-263q-6c66-xx88

Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-263q-5pj7-j6hj

CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-263q-5cv3-xq9g

Gitea allows attackers to add attachments with forbidden file extensions

CVSS3: 8.2
0%
Низкий
9 месяцев назад

Уязвимостей на страницу