Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-262j-qv9g-9xhx

около 4 лет назад

PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-262j-4hxf-4whv

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in tosend.it Simple Poll allows Stored XSS. This issue affects Simple Poll: from n/a through 1.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-262h-qq26-j72g

больше 2 лет назад

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-262h-gvvr-qmcc

больше 4 лет назад

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-122361504

EPSS: Низкий
github логотип

GHSA-262h-5vgm-7f9h

больше 4 лет назад

PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.

EPSS: Низкий
github логотип

GHSA-262h-4v4x-hrg5

3 дня назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-262g-fr6f-r3xc

почти 2 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Taieb Woolook allows PHP Local File Inclusion.This issue affects Woolook: from n/a through 1.7.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-262g-44pp-38c2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: dsa: Fix possible memory leaks in dsa_loop_init() kmemleak reported memory leaks in dsa_loop_init(): kmemleak: 12 new suspected memory leaks unreferenced object 0xffff8880138ce000 (size 2048): comm "modprobe", pid 390, jiffies 4295040478 (age 238.976s) backtrace: [<000000006a94f1d5>] kmalloc_trace+0x26/0x60 [<00000000a9c44622>] phy_device_create+0x5d/0x970 [<00000000d0ee2afc>] get_phy_device+0xf3/0x2b0 [<00000000dca0c71f>] __fixed_phy_register.part.0+0x92/0x4e0 [<000000008a834798>] fixed_phy_register+0x84/0xb0 [<0000000055223fcb>] dsa_loop_init+0xa9/0x116 [dsa_loop] ... There are two reasons for memleak in dsa_loop_init(). First, fixed_phy_register() create and register phy_device: fixed_phy_register() get_phy_device() phy_device_create() # freed by phy_device_free() phy_device_register() # freed by phy_device_remove() But fixed_phy_unregister() only calls phy_dev...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-262f-77q5-rqv6

почти 3 года назад

Jenkins Build Failure Analyzer Plugin Cross-site Scripting vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-262c-877p-cgmx

больше 4 лет назад

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-262c-7vhp-vjrh

около 3 лет назад

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2628-hv78-qx7g

7 месяцев назад

Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2628-4jvp-96vc

9 месяцев назад

Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2627-h6q4-h8xq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function mtk_dp_wait_hpd_asserted() may be called before the `mtk_dp->drm_dev` pointer is assigned in mtk_dp_bridge_attach(). Specifically it can be called via this callpath: - mtk_edp_wait_hpd_asserted - [panel probe] - dp_aux_ep_probe Using "drm" level prints anywhere in this callpath causes a NULL pointer dereference. Change the error message directly in mtk_dp_wait_hpd_asserted() to dev_err() to avoid this. Also change the error messages in mtk_dp_parse_capabilities(), which is called by mtk_dp_wait_hpd_asserted(). While touching these prints, also add the error code to them to make future debugging easier.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2626-fg73-6xgq

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2625-rw7m-5q5x

около 2 месяцев назад

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

EPSS: Низкий
github логотип

GHSA-2625-j643-gg22

больше 2 лет назад

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2624-69c2-835g

больше 4 лет назад

Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

EPSS: Низкий
github логотип

GHSA-2623-h3mc-wm8w

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in RaymondDesign Post & Page Notes allows Stored XSS.This issue affects Post & Page Notes: from n/a through 0.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2623-fqch-p6pf

больше 4 лет назад

Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-262j-qv9g-9xhx

PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-262j-4hxf-4whv

Cross-Site Request Forgery (CSRF) vulnerability in tosend.it Simple Poll allows Stored XSS. This issue affects Simple Poll: from n/a through 1.1.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-262h-qq26-j72g

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

CVSS3: 7.5
5%
Низкий
больше 2 лет назад
github логотип
GHSA-262h-gvvr-qmcc

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-122361504

0%
Низкий
больше 4 лет назад
github логотип
GHSA-262h-5vgm-7f9h

PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-262h-4v4x-hrg5

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

3 дня назад
github логотип
GHSA-262g-fr6f-r3xc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Taieb Woolook allows PHP Local File Inclusion.This issue affects Woolook: from n/a through 1.7.0.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-262g-44pp-38c2

In the Linux kernel, the following vulnerability has been resolved: net: dsa: Fix possible memory leaks in dsa_loop_init() kmemleak reported memory leaks in dsa_loop_init(): kmemleak: 12 new suspected memory leaks unreferenced object 0xffff8880138ce000 (size 2048): comm "modprobe", pid 390, jiffies 4295040478 (age 238.976s) backtrace: [<000000006a94f1d5>] kmalloc_trace+0x26/0x60 [<00000000a9c44622>] phy_device_create+0x5d/0x970 [<00000000d0ee2afc>] get_phy_device+0xf3/0x2b0 [<00000000dca0c71f>] __fixed_phy_register.part.0+0x92/0x4e0 [<000000008a834798>] fixed_phy_register+0x84/0xb0 [<0000000055223fcb>] dsa_loop_init+0xa9/0x116 [dsa_loop] ... There are two reasons for memleak in dsa_loop_init(). First, fixed_phy_register() create and register phy_device: fixed_phy_register() get_phy_device() phy_device_create() # freed by phy_device_free() phy_device_register() # freed by phy_device_remove() But fixed_phy_unregister() only calls phy_dev...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-262f-77q5-rqv6

Jenkins Build Failure Analyzer Plugin Cross-site Scripting vulnerability

CVSS3: 8
1%
Низкий
почти 3 года назад
github логотип
GHSA-262c-877p-cgmx

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.

CVSS3: 7.2
4%
Низкий
больше 4 лет назад
github логотип
GHSA-262c-7vhp-vjrh

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2628-hv78-qx7g

Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-2628-4jvp-96vc

Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2627-h6q4-h8xq

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function mtk_dp_wait_hpd_asserted() may be called before the `mtk_dp->drm_dev` pointer is assigned in mtk_dp_bridge_attach(). Specifically it can be called via this callpath: - mtk_edp_wait_hpd_asserted - [panel probe] - dp_aux_ep_probe Using "drm" level prints anywhere in this callpath causes a NULL pointer dereference. Change the error message directly in mtk_dp_wait_hpd_asserted() to dev_err() to avoid this. Also change the error messages in mtk_dp_parse_capabilities(), which is called by mtk_dp_wait_hpd_asserted(). While touching these prints, also add the error code to them to make future debugging easier.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2626-fg73-6xgq

An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.

CVSS3: 8.1
8%
Низкий
больше 4 лет назад
github логотип
GHSA-2625-rw7m-5q5x

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

около 2 месяцев назад
github логотип
GHSA-2625-j643-gg22

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2624-69c2-835g

Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2623-h3mc-wm8w

Cross-Site Request Forgery (CSRF) vulnerability in RaymondDesign Post & Page Notes allows Stored XSS.This issue affects Post & Page Notes: from n/a through 0.1.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2623-fqch-p6pf

Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу