Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xpv8-fw7f-p7c6

около 4 лет назад

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

EPSS: Низкий
github логотип

GHSA-xpv8-33xp-mjf2

около 4 лет назад

Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpv7-vm32-p7wv

около 2 месяцев назад

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xpv7-p5h9-8rgm

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpv7-93cm-4mxv

около 4 лет назад

img_auth.php may leak private extension images into the public cache

EPSS: Низкий
github логотип

GHSA-xpv7-5pmx-7r5h

около 1 года назад

Missing Authorization vulnerability in Etsy360 Embed and Integrate Etsy Shop allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embed and Integrate Etsy Shop: from n/a through 1.0.4.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpv6-xwmp-4m43

3 месяца назад

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xpv6-mc85-j28m

больше 1 года назад

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpv6-88fr-wq7p

около 4 лет назад

An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpv5-92cc-8f65

больше 1 года назад

musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpv3-x3xh-h28r

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of symlink creations don't give more information than telling that something goes wrong, since the usual code path is a lregister callback from each control element creation. More badly, the use of WARN() rather confuses fuzzer as if it were serious issues. This patch downgrades the warning messages to use the normal dev_err() instead of WARN(). For making it clearer, add the function name to the prefix, too.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpv3-wh3r-49xg

около 4 лет назад

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpv2-wfwf-r6xf

11 месяцев назад

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the uss_setting_page function when processing the uss_set form type. This makes it possible for unauthenticated attackers to modify critical Upyun cloud storage settings including bucket name, operator credentials, upload paths, and image processing parameters via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpv2-c6wv-9xg2

больше 4 лет назад

AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.

EPSS: Низкий
github логотип

GHSA-xpv2-8ppj-79hh

почти 5 лет назад

Expression injection in AviatorScript

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xprx-7799-7m8j

около 4 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of Enhanced Metafile Format processing engine (within the image conversion module). A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xprx-5rcx-fjcv

около 4 лет назад

In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.

EPSS: Низкий
github логотип

GHSA-xprw-xvvm-vqmv

около 4 лет назад

Improper Access Control in Apache Derby

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xprw-r8hx-4rqm

больше 1 года назад

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xprw-mh67-9xf5

6 месяцев назад

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpv8-fw7f-p7c6

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xpv8-33xp-mjf2

Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xpv7-vm32-p7wv

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

CVSS3: 4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpv7-p5h9-8rgm

A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xpv7-93cm-4mxv

img_auth.php may leak private extension images into the public cache

1%
Низкий
около 4 лет назад
github логотип
GHSA-xpv7-5pmx-7r5h

Missing Authorization vulnerability in Etsy360 Embed and Integrate Etsy Shop allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embed and Integrate Etsy Shop: from n/a through 1.0.4.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xpv6-xwmp-4m43

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xpv6-mc85-j28m

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpv6-88fr-wq7p

An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpv5-92cc-8f65

musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpv3-x3xh-h28r

In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of symlink creations don't give more information than telling that something goes wrong, since the usual code path is a lregister callback from each control element creation. More badly, the use of WARN() rather confuses fuzzer as if it were serious issues. This patch downgrades the warning messages to use the normal dev_err() instead of WARN(). For making it clearer, add the function name to the prefix, too.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpv3-wh3r-49xg

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xpv2-wfwf-r6xf

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the uss_setting_page function when processing the uss_set form type. This makes it possible for unauthenticated attackers to modify critical Upyun cloud storage settings including bucket name, operator credentials, upload paths, and image processing parameters via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xpv2-c6wv-9xg2

AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xpv2-8ppj-79hh

Expression injection in AviatorScript

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
github логотип
GHSA-xprx-7799-7m8j

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of Enhanced Metafile Format processing engine (within the image conversion module). A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
11%
Средний
около 4 лет назад
github логотип
GHSA-xprx-5rcx-fjcv

In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xprw-xvvm-vqmv

Improper Access Control in Apache Derby

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xprw-r8hx-4rqm

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xprw-mh67-9xf5

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

CVSS3: 8.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу