Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq39-3m9q-6r9j

больше 4 лет назад

Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.

EPSS: Низкий
github логотип

GHSA-xq38-gh8w-xv34

больше 4 лет назад

A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.

EPSS: Низкий
github логотип

GHSA-xq38-4286-vwhm

3 месяца назад

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-xq37-cpxh-7m6j

больше 4 лет назад

Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq37-89vc-hv3q

больше 4 лет назад

Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.

EPSS: Низкий
github логотип

GHSA-xq36-jhc6-fxw2

больше 2 лет назад

The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq34-8pwm-wv56

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the zone parameter in a del action to services_captiveportal_zones.php.

EPSS: Средний
github логотип

GHSA-xq34-4qgv-ggmc

25 дней назад

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq33-vcxx-f474

больше 4 лет назад

Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

EPSS: Низкий
github логотип

GHSA-xq33-fr9f-6p9r

10 месяцев назад

Redis Enterprise Elevation of Privilege Vulnerability

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xq32-9g7q-7297

3 месяца назад

FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq32-4fhv-g5h5

около 4 лет назад

Raw Image Extension Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-28466.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq2x-m5mh-fh59

больше 4 лет назад

PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.

EPSS: Средний
github логотип

GHSA-xq2x-gx2h-74r3

около 4 лет назад

src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary file, a different vector than CVE-2008-4959 and CVE-2008-5380.

EPSS: Низкий
github логотип

GHSA-xq2x-f6m4-2hrp

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache after doing PARTIAL_VALID1 zeroout When splitting an unwritten extent in the middle and converting it to initialized in ext4_split_extent() with the EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_DATA_VALID2 flags set, it could leave a stale unwritten extent. Assume we have an unwritten file and buffered write in the middle of it without dioread_nolock enabled, it will allocate blocks as written extent. 0 A B N [UUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDD--] D: valid data |<- ->| ----> this range needs to be initialized ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_PARTIAL_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and leave the entire extent as unwr...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq2x-8w8c-2hw4

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create new FTP users via a CreateFTP action in the ftp_management module to the default URI, (2) conduct cross-site scripting (XSS) attacks via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/, or (3) conduct SQL injection attacks via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.

EPSS: Низкий
github логотип

GHSA-xq2w-qxwp-qw9f

около 1 года назад

Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlocks For Elementor: from n/a through 1.3.16.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq2w-hqm3-v7fp

около 4 лет назад

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq2w-cvxp-qhgg

больше 1 года назад

In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xq2v-rr62-286c

12 месяцев назад

KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq39-3m9q-6r9j

Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq38-gh8w-xv34

A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq38-4286-vwhm

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 9.3
1%
Низкий
3 месяца назад
github логотип
GHSA-xq37-cpxh-7m6j

Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq37-89vc-hv3q

Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xq36-jhc6-fxw2

The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq34-8pwm-wv56

Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the zone parameter in a del action to services_captiveportal_zones.php.

20%
Средний
около 4 лет назад
github логотип
GHSA-xq34-4qgv-ggmc

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

CVSS3: 9.8
1%
Низкий
25 дней назад
github логотип
GHSA-xq33-vcxx-f474

Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq33-fr9f-6p9r

Redis Enterprise Elevation of Privilege Vulnerability

CVSS3: 8.7
1%
Низкий
10 месяцев назад
github логотип
GHSA-xq32-9g7q-7297

FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xq32-4fhv-g5h5

Raw Image Extension Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-28466.

CVSS3: 7.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xq2x-m5mh-fh59

PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.

64%
Средний
больше 4 лет назад
github логотип
GHSA-xq2x-gx2h-74r3

src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary file, a different vector than CVE-2008-4959 and CVE-2008-5380.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq2x-f6m4-2hrp

In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache after doing PARTIAL_VALID1 zeroout When splitting an unwritten extent in the middle and converting it to initialized in ext4_split_extent() with the EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_DATA_VALID2 flags set, it could leave a stale unwritten extent. Assume we have an unwritten file and buffered write in the middle of it without dioread_nolock enabled, it will allocate blocks as written extent. 0 A B N [UUUUUUUUUUUU] on-disk extent U: unwritten extent [UUUUUUUUUUUU] extent status tree [--DDDDDDDD--] D: valid data |<- ->| ----> this range needs to be initialized ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_PARTIAL_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and leave the entire extent as unwr...

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xq2x-8w8c-2hw4

Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create new FTP users via a CreateFTP action in the ftp_management module to the default URI, (2) conduct cross-site scripting (XSS) attacks via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/, or (3) conduct SQL injection attacks via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq2w-qxwp-qw9f

Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlocks For Elementor: from n/a through 1.3.16.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xq2w-hqm3-v7fp

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq2w-cvxp-qhgg

In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

CVSS3: 4.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-xq2v-rr62-286c

KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.

CVSS3: 7.5
0%
Низкий
12 месяцев назад

Уязвимостей на страницу