Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xppr-6c99-hp78

около 2 лет назад

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xppr-5m7f-5626

больше 4 лет назад

SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.

EPSS: Низкий
github логотип

GHSA-xppp-92mj-4gg6

около 4 лет назад

Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute arbitrary code via a crafted inf file.

EPSS: Низкий
github логотип

GHSA-xppm-x368-2qjm

почти 4 года назад

In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xppm-mp6m-c6fw

больше 4 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."

EPSS: Низкий
github логотип

GHSA-xppm-jmw6-fhmf

около 2 месяцев назад

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xppm-fxhj-x8p3

5 месяцев назад

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xppm-25h7-qf3q

10 месяцев назад

Missing Authorization vulnerability in Codeinwp Revive Old Posts tweet-old-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive Old Posts: from n/a through <= 9.3.3.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xppj-xjxm-v2wv

больше 4 лет назад

The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack.

EPSS: Низкий
github логотип

GHSA-xppj-mp47-h9fj

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xppj-j5qj-xhcx

около 4 лет назад

A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP addresses. This security update corrects how ADFS updates its list of banned IP addresses., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-1126.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpph-pf69-7f23

почти 3 года назад

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xpph-g64w-p4mm

около 4 лет назад

Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xppg-xx55-6rw5

12 месяцев назад

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xppg-r7h5-74wm

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: return -ENOMEM if dma_map_single fails The spi controller supports 44-bit address space on AXI in DMA mode, so set dma_addr_t width to 44-bit to avoid using a swiotlb mapping. In addition, if dma_map_single fails, it should return immediately instead of continuing doing the DMA operation which bases on invalid address. This fixes the following crash which occurs in reading a big block from flash: [ 123.633577] zynqmp-qspi ff0f0000.spi: swiotlb buffer is full (sz: 4194304 bytes), total 32768 (slots), used 0 (slots) [ 123.644230] zynqmp-qspi ff0f0000.spi: ERR:rxdma:memory not mapped [ 123.784625] Unable to handle kernel paging request at virtual address 00000000003fffc0 [ 123.792536] Mem abort info: [ 123.795313] ESR = 0x96000145 [ 123.798351] EC = 0x25: DABT (current EL), IL = 32 bits [ 123.803655] SET = 0, FnV = 0 [ 123.806693] EA = 0, S1PTW = 0 [ 123.809818] Data abort in...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xppf-v74q-p4r3

около 4 лет назад

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xppf-jw7p-wfmj

больше 4 лет назад

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

EPSS: Низкий
github логотип

GHSA-xppc-p674-7v8r

7 дней назад

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpp9-cvrv-9rvf

больше 4 лет назад

SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.

EPSS: Низкий
github логотип

GHSA-xpp9-6v93-3xvq

больше 4 лет назад

Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xppr-6c99-hp78

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xppr-5m7f-5626

SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xppp-92mj-4gg6

Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute arbitrary code via a crafted inf file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xppm-x368-2qjm

In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xppm-mp6m-c6fw

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xppm-jmw6-fhmf

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slots, such as route.query parameters, which execute in the document context when the noscript tag is implicitly closed by script tags.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xppm-fxhj-x8p3

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xppm-25h7-qf3q

Missing Authorization vulnerability in Codeinwp Revive Old Posts tweet-old-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive Old Posts: from n/a through <= 9.3.3.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xppj-xjxm-v2wv

The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xppj-mp47-h9fj

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-xppj-j5qj-xhcx

A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP addresses. This security update corrects how ADFS updates its list of banned IP addresses., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-1126.

CVSS3: 6.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-xpph-pf69-7f23

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVSS3: 9.8
19%
Средний
почти 3 года назад
github логотип
GHSA-xpph-g64w-p4mm

Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xppg-xx55-6rw5

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-xppg-r7h5-74wm

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: return -ENOMEM if dma_map_single fails The spi controller supports 44-bit address space on AXI in DMA mode, so set dma_addr_t width to 44-bit to avoid using a swiotlb mapping. In addition, if dma_map_single fails, it should return immediately instead of continuing doing the DMA operation which bases on invalid address. This fixes the following crash which occurs in reading a big block from flash: [ 123.633577] zynqmp-qspi ff0f0000.spi: swiotlb buffer is full (sz: 4194304 bytes), total 32768 (slots), used 0 (slots) [ 123.644230] zynqmp-qspi ff0f0000.spi: ERR:rxdma:memory not mapped [ 123.784625] Unable to handle kernel paging request at virtual address 00000000003fffc0 [ 123.792536] Mem abort info: [ 123.795313] ESR = 0x96000145 [ 123.798351] EC = 0x25: DABT (current EL), IL = 32 bits [ 123.803655] SET = 0, FnV = 0 [ 123.806693] EA = 0, S1PTW = 0 [ 123.809818] Data abort in...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xppf-v74q-p4r3

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

16%
Средний
около 4 лет назад
github логотип
GHSA-xppf-jw7p-wfmj

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xppc-p674-7v8r

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-xpp9-cvrv-9rvf

SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpp9-6v93-3xvq

Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу