Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xqfj-57hg-6v8m

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash in process_v2_sparse_read() for encrypted directories The crash in process_v2_sparse_read() for fscrypt-encrypted directories has been reported. Issue takes place for Ceph msgr2 protocol in secure mode. It can be reproduced by the steps: sudo mount -t ceph :/ /mnt/cephfs/ -o name=admin,fs=cephfs,ms_mode=secure (1) mkdir /mnt/cephfs/fscrypt-test-3 (2) cp area_decrypted.tar /mnt/cephfs/fscrypt-test-3 (3) fscrypt encrypt --source=raw_key --key=./my.key /mnt/cephfs/fscrypt-test-3 (4) fscrypt lock /mnt/cephfs/fscrypt-test-3 (5) fscrypt unlock --key=my.key /mnt/cephfs/fscrypt-test-3 (6) cat /mnt/cephfs/fscrypt-test-3/area_decrypted.tar (7) Issue has been triggered [ 408.072247] ------------[ cut here ]------------ [ 408.072251] WARNING: CPU: 1 PID: 392 at net/ceph/messenger_v2.c:865 ceph_con_v2_try_read+0x4b39/0x72f0 [ 408.072267] Modules linked in: intel_rapl_msr intel_rapl_common intel_uncore_fre...

EPSS: Низкий
github логотип

GHSA-xqfj-35wv-m3cr

около 5 лет назад

Null pointer dereference in `StringNGrams`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xqfh-qj3w-mr75

8 дней назад

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqfh-gx6q-m574

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xqfg-p7f2-6w5f

почти 3 года назад

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqff-x4hf-x674

больше 4 лет назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

EPSS: Низкий
github логотип

GHSA-xqff-gxc3-2x4v

больше 2 лет назад

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqfc-fqm7-gx4x

около 4 лет назад

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqfc-cx8v-9v3h

около 4 лет назад

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-xqfc-ch67-qwvg

около 3 лет назад

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqf9-v7ff-rf4x

около 4 лет назад

Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.

EPSS: Низкий
github логотип

GHSA-xqf9-qrgq-fxfv

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xqf9-q644-qr8q

больше 4 лет назад

HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.

EPSS: Низкий
github логотип

GHSA-xqf7-wh6f-f6jh

больше 1 года назад

The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xqf7-frvw-5523

больше 3 лет назад

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqf6-p37p-9cxg

около 4 лет назад

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqf6-m6vx-v7jx

около 4 лет назад

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqf6-9hf7-323f

9 месяцев назад

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqf6-5grh-6223

около 4 лет назад

Passwords transmitted in plain text by Jenkins Artifactory Plugin

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xqf5-6fm4-qwhv

около 4 лет назад

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqfj-57hg-6v8m

In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash in process_v2_sparse_read() for encrypted directories The crash in process_v2_sparse_read() for fscrypt-encrypted directories has been reported. Issue takes place for Ceph msgr2 protocol in secure mode. It can be reproduced by the steps: sudo mount -t ceph :/ /mnt/cephfs/ -o name=admin,fs=cephfs,ms_mode=secure (1) mkdir /mnt/cephfs/fscrypt-test-3 (2) cp area_decrypted.tar /mnt/cephfs/fscrypt-test-3 (3) fscrypt encrypt --source=raw_key --key=./my.key /mnt/cephfs/fscrypt-test-3 (4) fscrypt lock /mnt/cephfs/fscrypt-test-3 (5) fscrypt unlock --key=my.key /mnt/cephfs/fscrypt-test-3 (6) cat /mnt/cephfs/fscrypt-test-3/area_decrypted.tar (7) Issue has been triggered [ 408.072247] ------------[ cut here ]------------ [ 408.072251] WARNING: CPU: 1 PID: 392 at net/ceph/messenger_v2.c:865 ceph_con_v2_try_read+0x4b39/0x72f0 [ 408.072267] Modules linked in: intel_rapl_msr intel_rapl_common intel_uncore_fre...

0%
Низкий
8 месяцев назад
github логотип
GHSA-xqfj-35wv-m3cr

Null pointer dereference in `StringNGrams`

CVSS3: 2.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-xqfh-qj3w-mr75

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.

CVSS3: 7.5
0%
Низкий
8 дней назад
github логотип
GHSA-xqfh-gx6q-m574

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-xqfg-p7f2-6w5f

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xqff-x4hf-x674

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqff-gxc3-2x4v

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqfc-fqm7-gx4x

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xqfc-cx8v-9v3h

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675.

CVSS3: 7.8
18%
Средний
около 4 лет назад
github логотип
GHSA-xqfc-ch67-qwvg

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xqf9-v7ff-rf4x

Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqf9-qrgq-fxfv

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqf9-q644-qr8q

HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqf7-wh6f-f6jh

The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqf7-frvw-5523

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqf6-p37p-9cxg

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xqf6-m6vx-v7jx

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqf6-9hf7-323f

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xqf6-5grh-6223

Passwords transmitted in plain text by Jenkins Artifactory Plugin

CVSS3: 3.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqf5-6fm4-qwhv

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу