Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xp28-3fv9-33c6

больше 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp27-mhxx-q8mf

около 4 лет назад

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.

EPSS: Низкий
github логотип

GHSA-xp27-gwqx-8qx4

почти 3 года назад

Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp27-8r9x-g424

около 2 лет назад

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp27-622h-2g9p

почти 4 года назад

In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-189574230

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp26-p53h-6h2p

около 4 лет назад

Improper Neutralization of Input During Web Page Generation in LXML

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp26-jqrv-cc5r

около 4 лет назад

Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp26-fwf6-j3gx

около 4 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp24-4hc5-r39q

4 месяца назад

A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The manipulation of the argument fname/lname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xp23-pr4w-q7fx

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themeqx LetterPress plugin <= 1.1.2 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xp23-94cq-8m5g

около 1 года назад

A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of incoming packets. This could allow an unauthenticated remote attacker to create a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp23-6mrm-wqh3

около 2 месяцев назад

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp23-4cw6-346h

около 4 лет назад

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xp22-xvph-8m82

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere Lite allows Stored XSS. This issue affects WPShapere Lite: from n/a through 1.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xmxx-qpv3-jjw8

около 2 месяцев назад

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmxx-m7q8-x9xj

около 4 лет назад

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

EPSS: Низкий
github логотип

GHSA-xmxx-8mch-q276

около 4 лет назад

The mintToken function of a smart contract implementation for Bitstarti, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmxx-7p24-h892

4 месяца назад

OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xmxx-577p-gqgc

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmxw-rhxj-cxcc

около 4 лет назад

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp28-3fv9-33c6

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xp27-mhxx-q8mf

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xp27-gwqx-8qx4

Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xp27-8r9x-g424

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp27-622h-2g9p

In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-189574230

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp26-p53h-6h2p

Improper Neutralization of Input During Web Page Generation in LXML

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xp26-jqrv-cc5r

Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

CVSS3: 7.2
5%
Низкий
около 4 лет назад
github логотип
GHSA-xp26-fwf6-j3gx

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xp24-4hc5-r39q

A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The manipulation of the argument fname/lname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xp23-pr4w-q7fx

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themeqx LetterPress plugin <= 1.1.2 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-xp23-94cq-8m5g

A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of incoming packets. This could allow an unauthenticated remote attacker to create a denial of service condition.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-xp23-6mrm-wqh3

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xp23-4cw6-346h

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782.

CVSS3: 4.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp22-xvph-8m82

Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere Lite allows Stored XSS. This issue affects WPShapere Lite: from n/a through 1.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xmxx-qpv3-jjw8

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xmxx-m7q8-x9xj

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xmxx-8mch-q276

The mintToken function of a smart contract implementation for Bitstarti, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmxx-7p24-h892

OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

CVSS3: 8.1
1%
Низкий
4 месяца назад
github логотип
GHSA-xmxx-577p-gqgc

In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xmxw-rhxj-cxcc

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.

CVSS3: 5.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу