Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-25xg-m67p-ppc3

9 месяцев назад

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25xg-52c8-p9q8

6 месяцев назад

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25xf-r6x8-6fw5

около 3 лет назад

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25xc-r4x7-g46h

почти 4 года назад

Fusiondirectory 1.3 suffers from Improper Session Handling.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25xc-jwfq-39jw

больше 5 лет назад

OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-25xc-32vr-fm66

почти 2 года назад

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25x9-fv8f-q329

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter.

EPSS: Низкий
github логотип

GHSA-25x9-7wcv-mf35

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() > ret = brcmf_proto_tx_queue_data(drvr, ifp->ifidx, skb); may be schedule, and then complete before the line > ndev->stats.tx_bytes += skb->len; [ 46.912801] ================================================================== [ 46.920552] BUG: KASAN: use-after-free in brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac] [ 46.928673] Read of size 4 at addr ffffff803f5882e8 by task systemd-resolve/328 [ 46.935991] [ 46.937514] CPU: 1 PID: 328 Comm: systemd-resolve Tainted: G O 5.4.199-[REDACTED] #1 [ 46.947255] Hardware name: [REDACTED] [ 46.954568] Call trace: [ 46.957037] dump_backtrace+0x0/0x2b8 [ 46.960719] show_stack+0x24/0x30 [ 46.964052] dump_stack+0x128/0x194 [ 46.967557] print_address_description.isra.0+0x64/0x380 [ 46.972877] __kasan_report+0x1d4/0x240 [ 46.976723] kasan_report+0xc/0x18 [ 46.980...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25x8-6494-2wgh

8 месяцев назад

Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-25x7-rqcx-mfwh

больше 4 лет назад

A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25x7-jcpc-96r4

почти 2 года назад

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-25x7-989g-366h

около 3 лет назад

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-25x7-2m3g-jhfw

10 месяцев назад

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-25x7-27vj-3vw7

около 1 года назад

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25x6-7vrp-cgpr

больше 3 лет назад

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25x6-6mr7-9jx8

больше 4 лет назад

Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com. This could lead to successful phishing campaigns and create a sense of false security.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25x6-6c2h-m4mm

больше 4 лет назад

An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitialized read resulting in an information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25x6-5f6g-h9pv

почти 3 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-25x6-2hgw-h5x4

больше 4 лет назад

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.

EPSS: Низкий
github логотип

GHSA-25x5-mfj4-w63g

больше 4 лет назад

Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25xg-m67p-ppc3

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-25xg-52c8-p9q8

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-25xf-r6x8-6fw5

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-25xc-r4x7-g46h

Fusiondirectory 1.3 suffers from Improper Session Handling.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-25xc-jwfq-39jw

OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure

CVSS3: 8.6
2%
Низкий
больше 5 лет назад
github логотип
GHSA-25xc-32vr-fm66

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-25x9-fv8f-q329

Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-25x9-7wcv-mf35

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() > ret = brcmf_proto_tx_queue_data(drvr, ifp->ifidx, skb); may be schedule, and then complete before the line > ndev->stats.tx_bytes += skb->len; [ 46.912801] ================================================================== [ 46.920552] BUG: KASAN: use-after-free in brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac] [ 46.928673] Read of size 4 at addr ffffff803f5882e8 by task systemd-resolve/328 [ 46.935991] [ 46.937514] CPU: 1 PID: 328 Comm: systemd-resolve Tainted: G O 5.4.199-[REDACTED] #1 [ 46.947255] Hardware name: [REDACTED] [ 46.954568] Call trace: [ 46.957037] dump_backtrace+0x0/0x2b8 [ 46.960719] show_stack+0x24/0x30 [ 46.964052] dump_stack+0x128/0x194 [ 46.967557] print_address_description.isra.0+0x64/0x380 [ 46.972877] __kasan_report+0x1d4/0x240 [ 46.976723] kasan_report+0xc/0x18 [ 46.980...

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-25x8-6494-2wgh

Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-25x7-rqcx-mfwh

A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25x7-jcpc-96r4

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-25x7-989g-366h

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

CVSS3: 9.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-25x7-2m3g-jhfw

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

CVSS3: 6.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-25x7-27vj-3vw7

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-25x6-7vrp-cgpr

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25x6-6mr7-9jx8

Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com. This could lead to successful phishing campaigns and create a sense of false security.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25x6-6c2h-m4mm

An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitialized read resulting in an information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-25x6-5f6g-h9pv

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.

CVSS3: 4.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-25x6-2hgw-h5x4

Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-25x5-mfj4-w63g

Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS3: 5.6
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу