Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xm28-33cw-qw8x

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xm27-gqxx-cpcx

больше 4 лет назад

Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."

EPSS: Низкий
github логотип

GHSA-xm26-26vh-5phq

больше 4 лет назад

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

EPSS: Низкий
github логотип

GHSA-xm25-hh96-p9xh

около 4 лет назад

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186424.

EPSS: Низкий
github логотип

GHSA-xm25-5jmx-4mjc

около 4 лет назад

Mitigation bypass in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to execute arbitrary code by crafting a malicious message.

EPSS: Низкий
github логотип

GHSA-xm25-4mwc-qhx5

больше 4 лет назад

Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."

EPSS: Средний
github логотип

GHSA-xm24-rmjg-m943

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Robin Phillips Mobile Banner plugin <= 1.5 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xm24-7c3w-pfc7

почти 4 года назад

In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-234441463

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm24-7446-mqm4

больше 4 лет назад

Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.

EPSS: Низкий
github логотип

GHSA-xm23-f7v4-5j82

4 месяца назад

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium). This issue was fixed in version 4.0.260204.2 of the runZero Platform.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm22-8c3w-j34x

больше 3 лет назад

A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225943.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjxx-r5cf-4p2h

больше 4 лет назад

Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.

EPSS: Низкий
github логотип

GHSA-xjxx-h5w2-fphm

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.

EPSS: Низкий
github логотип

GHSA-xjxx-grm6-73vf

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: block: fix wrong mode for blkdev_put() from disk_scan_partitions() If disk_scan_partitions() is called with 'FMODE_EXCL', blkdev_get_by_dev() will be called without 'FMODE_EXCL', however, follow blkdev_put() is still called with 'FMODE_EXCL', which will cause 'bd_holders' counter to leak. Fix the problem by using the right mode for blkdev_put().

EPSS: Низкий
github логотип

GHSA-xjxx-8f45-6p6w

больше 4 лет назад

Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xjxr-x4h8-946x

около 4 лет назад

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xjxr-9f3w-9hc2

около 4 лет назад

Prima Systems FlexAir devices allow Unauthenticated Command Injection resulting in Root Remote Code Execution.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xjxq-vf9p-rf53

почти 3 года назад

Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjxq-r86x-5mrv

больше 2 лет назад

In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a different issue than CVE-2023-50428. NOTE: some parties oppose this new limit check (for example, because they agree with the objective but disagree with the technical mechanism, or because they have a different objective).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xjxq-r4rh-23g9

больше 4 лет назад

Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm28-33cw-qw8x

Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xm27-gqxx-cpcx

Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xm26-26vh-5phq

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm25-hh96-p9xh

IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186424.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm25-5jmx-4mjc

Mitigation bypass in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to execute arbitrary code by crafting a malicious message.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xm25-4mwc-qhx5

Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."

59%
Средний
больше 4 лет назад
github логотип
GHSA-xm24-rmjg-m943

Cross-Site Request Forgery (CSRF) vulnerability in Robin Phillips Mobile Banner plugin <= 1.5 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xm24-7c3w-pfc7

In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-234441463

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xm24-7446-mqm4

Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xm23-f7v4-5j82

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium). This issue was fixed in version 4.0.260204.2 of the runZero Platform.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xm22-8c3w-j34x

A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225943.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xjxx-r5cf-4p2h

Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjxx-h5w2-fphm

Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjxx-grm6-73vf

In the Linux kernel, the following vulnerability has been resolved: block: fix wrong mode for blkdev_put() from disk_scan_partitions() If disk_scan_partitions() is called with 'FMODE_EXCL', blkdev_get_by_dev() will be called without 'FMODE_EXCL', however, follow blkdev_put() is still called with 'FMODE_EXCL', which will cause 'bd_holders' counter to leak. Fix the problem by using the right mode for blkdev_put().

больше 1 года назад
github логотип
GHSA-xjxx-8f45-6p6w

Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjxr-x4h8-946x

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).

CVSS3: 9.8
96%
Критический
около 4 лет назад
github логотип
GHSA-xjxr-9f3w-9hc2

Prima Systems FlexAir devices allow Unauthenticated Command Injection resulting in Root Remote Code Execution.

CVSS3: 8.8
31%
Средний
около 4 лет назад
github логотип
GHSA-xjxq-vf9p-rf53

Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xjxq-r86x-5mrv

In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a different issue than CVE-2023-50428. NOTE: some parties oppose this new limit check (for example, because they agree with the objective but disagree with the technical mechanism, or because they have a different objective).

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjxq-r4rh-23g9

Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу