Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-22xj-68w7-6jjx

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitrary web script or HTML via the search_string parameter.

EPSS: Низкий
github логотип

GHSA-22xh-wmr8-5cwg

больше 4 лет назад

The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

EPSS: Низкий
github логотип

GHSA-22xh-w79g-q63r

больше 3 лет назад

A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-22xh-v97v-2c2w

больше 4 лет назад

Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.

EPSS: Низкий
github логотип

GHSA-22xh-5fc2-2447

больше 4 лет назад

SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.

EPSS: Низкий
github логотип

GHSA-22xg-p4qj-9488

9 дней назад

Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22xf-vh82-92xw

больше 4 лет назад

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22xf-73q7-hrwc

15 дней назад

A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22xf-532v-3xqg

больше 1 года назад

A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-22xc-xg2r-9j7v

2 месяца назад

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-22xc-pf4c-p298

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix stuck flows on cleanup due to pending work To clear the flow table on flow table free, the following sequence normally happens in order: 1) gc_step work is stopped to disable any further stats/del requests. 2) All flow table entries are set to teardown state. 3) Run gc_step which will queue HW del work for each flow table entry. 4) Waiting for the above del work to finish (flush). 5) Run gc_step again, deleting all entries from the flow table. 6) Flow table is freed. But if a flow table entry already has pending HW stats or HW add work step 3 will not queue HW del work (it will be skipped), step 4 will wait for the pending add/stats to finish, and step 5 will queue HW del work which might execute after freeing of the flow table. To fix the above, this patch flushes the pending work, then it sets the teardown flag to all flows in the flowtable and it forces a garbage collect...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22xc-96jv-r6q2

больше 4 лет назад

The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22x9-7gj8-vfqv

больше 4 лет назад

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

EPSS: Низкий
github логотип

GHSA-22x8-gch8-47j2

больше 4 лет назад

customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22x7-x855-m7h7

8 дней назад

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22x7-vwh9-5w4g

больше 4 лет назад

LIEF heap-buffer-overflow

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22x7-r7fc-8grh

больше 4 лет назад

In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22x7-mc8g-7jg9

9 месяцев назад

Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-22x7-95cq-4vqm

больше 3 лет назад

Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22x6-c42f-8q7h

почти 3 года назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An app may be able to cause a denial-of-service.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22xj-68w7-6jjx

Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitrary web script or HTML via the search_string parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22xh-wmr8-5cwg

The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22xh-w79g-q63r

A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

CVSS3: 8.8
10%
Средний
больше 3 лет назад
github логотип
GHSA-22xh-v97v-2c2w

Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-22xh-5fc2-2447

SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-22xg-p4qj-9488

Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
9 дней назад
github логотип
GHSA-22xf-vh82-92xw

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22xf-73q7-hrwc

A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
1%
Низкий
15 дней назад
github логотип
GHSA-22xf-532v-3xqg

A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-22xc-xg2r-9j7v

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

CVSS3: 7.4
0%
Низкий
2 месяца назад
github логотип
GHSA-22xc-pf4c-p298

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix stuck flows on cleanup due to pending work To clear the flow table on flow table free, the following sequence normally happens in order: 1) gc_step work is stopped to disable any further stats/del requests. 2) All flow table entries are set to teardown state. 3) Run gc_step which will queue HW del work for each flow table entry. 4) Waiting for the above del work to finish (flush). 5) Run gc_step again, deleting all entries from the flow table. 6) Flow table is freed. But if a flow table entry already has pending HW stats or HW add work step 3 will not queue HW del work (it will be skipped), step 4 will wait for the pending add/stats to finish, and step 5 will queue HW del work which might execute after freeing of the flow table. To fix the above, this patch flushes the pending work, then it sets the teardown flag to all flows in the flowtable and it forces a garbage collect...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-22xc-96jv-r6q2

The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-22x9-7gj8-vfqv

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-22x8-gch8-47j2

customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22x7-x855-m7h7

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.

CVSS3: 5.5
2%
Низкий
8 дней назад
github логотип
GHSA-22x7-vwh9-5w4g

LIEF heap-buffer-overflow

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22x7-r7fc-8grh

In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22x7-mc8g-7jg9

Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-22x7-95cq-4vqm

Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22x6-c42f-8q7h

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An app may be able to cause a denial-of-service.

CVSS3: 5.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу