Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-239j-g7xf-h6v8

4 дня назад

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress WordPress plugin before 4.4.7 otherwise keeps non-public.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-239j-2cv5-j928

больше 2 лет назад

OS command injection vulnerability in WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands by sending a specially crafted request to the product.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-239h-r383-7fqx

больше 4 лет назад

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

EPSS: Низкий
github логотип

GHSA-239h-g863-fm9x

6 месяцев назад

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-239h-283c-gxph

больше 4 лет назад

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

EPSS: Низкий
github логотип

GHSA-239g-m969-jgx2

почти 2 года назад

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-239g-jrj8-mjwj

больше 4 лет назад

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Низкий
github логотип

GHSA-239g-crqj-qcfp

больше 4 лет назад

Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session.

EPSS: Низкий
github логотип

GHSA-239g-2685-54x3

3 месяца назад

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-239f-qw85-5278

больше 1 года назад

A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-239f-m535-8fmf

больше 4 лет назад

Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-239f-4376-67r8

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-239c-jmhv-334g

больше 4 лет назад

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.

EPSS: Низкий
github логотип

GHSA-239c-9qhp-4xc9

около 1 года назад

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-239c-6cv2-wwx8

больше 3 лет назад

Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2399-234v-9qjj

около 1 года назад

A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /myprofile.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2398-v7wm-x7gr

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix freeing of the HMB descriptor table The HMB descriptor table is sized to the maximum number of descriptors that could be used for a given device, but __nvme_alloc_host_mem could break out of the loop earlier on memory allocation failure and end up using less descriptors than planned for, which leads to an incorrect size passed to dma_free_coherent. In practice this was not showing up because the number of descriptors tends to be low and the dma coherent allocator always allocates and frees at least a page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2398-fmp4-7w9h

больше 4 лет назад

An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.

EPSS: Низкий
github логотип

GHSA-2397-gxj5-7465

8 месяцев назад

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2397-fjxq-4xvj

около 1 года назад

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-239j-g7xf-h6v8

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress WordPress plugin before 4.4.7 otherwise keeps non-public.

CVSS3: 5.3
0%
Низкий
4 дня назад
github логотип
GHSA-239j-2cv5-j928

OS command injection vulnerability in WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands by sending a specially crafted request to the product.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-239h-r383-7fqx

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-239h-g863-fm9x

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-239h-283c-gxph

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-239g-m969-jgx2

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-239g-jrj8-mjwj

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-239g-crqj-qcfp

Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-239g-2685-54x3

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-239f-qw85-5278

A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-239f-m535-8fmf

Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-239f-4376-67r8

Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-239c-jmhv-334g

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-239c-9qhp-4xc9

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-239c-6cv2-wwx8

Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2399-234v-9qjj

A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /myprofile.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
около 1 года назад
github логотип
GHSA-2398-v7wm-x7gr

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix freeing of the HMB descriptor table The HMB descriptor table is sized to the maximum number of descriptors that could be used for a given device, but __nvme_alloc_host_mem could break out of the loop earlier on memory allocation failure and end up using less descriptors than planned for, which leads to an incorrect size passed to dma_free_coherent. In practice this was not showing up because the number of descriptors tends to be low and the dma coherent allocator always allocates and frees at least a page.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2398-fmp4-7w9h

An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-2397-gxj5-7465

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

CVSS3: 6.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-2397-fjxq-4xvj

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system.

CVSS3: 4.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу