Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjmq-x923-hrwq

около 4 лет назад

A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjmj-w54m-v5gr

больше 3 лет назад

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjmj-p278-4jp5

больше 4 лет назад

OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability

EPSS: Низкий
github логотип

GHSA-xjmj-jj97-789f

около 4 лет назад

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.

EPSS: Низкий
github логотип

GHSA-xjmj-77vh-qf7w

около 4 лет назад

An arbitrary file deletion vulnerability exists within Maccms10.

EPSS: Низкий
github логотип

GHSA-xjmh-6wp6-74q8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: idpf: avoid vport access in idpf_get_link_ksettings When the device control plane is removed or the platform running device control plane is rebooted, a reset is detected on the driver. On driver reset, it releases the resources and waits for the reset to complete. If the reset fails, it takes the error path and releases the vport lock. At this time if the monitoring tools tries to access link settings, it call traces for accessing released vport pointer. To avoid it, move link_speed_mbps to netdev_priv structure which removes the dependency on vport pointer and the vport lock in idpf_get_link_ksettings. Also use netif_carrier_ok() to check the link status and adjust the offsetof to use link_up instead of link_speed_mbps.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjmg-vpvm-gr84

больше 4 лет назад

Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xjmg-ppqq-vfgg

больше 1 года назад

The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjmf-xr2j-gfx7

больше 4 лет назад

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xjmf-cg3p-vmcm

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic allows SQL Injection. This issue affects Local Magic: from n/a through 2.6.0.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-xjmc-6x2g-58qh

больше 2 лет назад

An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjmc-37gv-8mrp

около 4 лет назад

An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1324.

EPSS: Низкий
github логотип

GHSA-xjm9-rr2c-vpq2

16 дней назад

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjm9-9gr6-gcpx

около 4 лет назад

A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xjm8-v6p6-5c3j

больше 1 года назад

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjm8-9w9g-9h2f

около 3 лет назад

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xjm8-5h8c-cc2g

около 4 лет назад

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xjm6-pf3c-5gjq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.

EPSS: Низкий
github логотип

GHSA-xjm6-m6g9-99gh

около 4 лет назад

Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.

EPSS: Низкий
github логотип

GHSA-xjm6-jfmg-qc6p

около 2 лет назад

Aimeos denial of service vulnerability in SaaS and marketplace setups

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjmq-x923-hrwq

A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xjmj-w54m-v5gr

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xjmj-p278-4jp5

OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmj-jj97-789f

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjmj-77vh-qf7w

An arbitrary file deletion vulnerability exists within Maccms10.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjmh-6wp6-74q8

In the Linux kernel, the following vulnerability has been resolved: idpf: avoid vport access in idpf_get_link_ksettings When the device control plane is removed or the platform running device control plane is rebooted, a reset is detected on the driver. On driver reset, it releases the resources and waits for the reset to complete. If the reset fails, it takes the error path and releases the vport lock. At this time if the monitoring tools tries to access link settings, it call traces for accessing released vport pointer. To avoid it, move link_speed_mbps to netdev_priv structure which removes the dependency on vport pointer and the vport lock in idpf_get_link_ksettings. Also use netif_carrier_ok() to check the link status and adjust the offsetof to use link_up instead of link_speed_mbps.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjmg-vpvm-gr84

Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmg-ppqq-vfgg

The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjmf-xr2j-gfx7

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.

CVSS3: 7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjmf-cg3p-vmcm

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic allows SQL Injection. This issue affects Local Magic: from n/a through 2.6.0.

CVSS3: 9.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjmc-6x2g-58qh

An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjmc-37gv-8mrp

An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1324.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjm9-rr2c-vpq2

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

CVSS3: 9.8
0%
Низкий
16 дней назад
github логотип
GHSA-xjm9-9gr6-gcpx

A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.

CVSS3: 3.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjm8-v6p6-5c3j

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjm8-9w9g-9h2f

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xjm8-5h8c-cc2g

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjm6-pf3c-5gjq

Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjm6-m6g9-99gh

Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjm6-jfmg-qc6p

Aimeos denial of service vulnerability in SaaS and marketplace setups

CVSS3: 5.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу