Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xjc7-gh59-3hp4

около 2 лет назад

In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xjc6-w655-p4pc

3 месяца назад

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to extract sensitive database information including version details and other data.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xjc5-mpgm-fw42

больше 4 лет назад

PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.

EPSS: Низкий
github логотип

GHSA-xjc5-m98p-6f2c

больше 2 лет назад

Improperly calculated effective permissions in M-Files Server versions 23.9 and 23.10 and 23.11 before 23.11.13168.7 could produce a faulty result if an object used a specific configuration of metadata-driven permissions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjc4-4m54-94xr

больше 3 лет назад

Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjc3-vjh6-m283

больше 1 года назад

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjc3-4jp4-q9c6

около 2 лет назад

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the content in the 'send_pdf' and the 'send_pdf_front' functions which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xjc2-482p-w8xr

8 месяцев назад

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjc2-47vq-w6wg

больше 4 лет назад

A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.

EPSS: Низкий
github логотип

GHSA-xjc2-37xp-26m5

около 4 лет назад

The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). NOTE: bad0a746e9f4cf260dedba5828d9645d50176aac is cited in the OSV "fixed" field but does not have a code change.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xj9x-9j3p-fff9

9 дней назад

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj9x-95w7-mx93

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects Pandora FMS: from 700 through 773.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xj9w-qxv5-jhjg

больше 4 лет назад

An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. This allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via crafted perf_event_open and mmap system calls.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj9w-h48f-jf9m

около 4 лет назад

Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.

EPSS: Низкий
github логотип

GHSA-xj9w-cgqg-q897

около 2 месяцев назад

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can submit private keys, ciphertext, and passphrases to perform server-side decryption without credentials, exposing key material to logs and enabling resource exhaustion attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj9w-76w3-9v9v

больше 4 лет назад

A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj9w-5r6q-x6v4

4 месяца назад

OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj9v-6q2f-vqhx

больше 3 лет назад

wifey vulnerable to Command Injection due to improper input sanitization

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj9r-hfwq-rpc7

больше 2 лет назад

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Acroforms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22704.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj9r-6r7r-x7p5

больше 4 лет назад

PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjc7-gh59-3hp4

In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xjc6-w655-p4pc

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to extract sensitive database information including version details and other data.

CVSS3: 8.2
0%
Низкий
3 месяца назад
github логотип
GHSA-xjc5-mpgm-fw42

PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xjc5-m98p-6f2c

Improperly calculated effective permissions in M-Files Server versions 23.9 and 23.10 and 23.11 before 23.11.13168.7 could produce a faulty result if an object used a specific configuration of metadata-driven permissions.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xjc4-4m54-94xr

Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xjc3-vjh6-m283

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjc3-4jp4-q9c6

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the content in the 'send_pdf' and the 'send_pdf_front' functions which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS3: 5.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xjc2-482p-w8xr

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xjc2-47vq-w6wg

A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjc2-37xp-26m5

The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). NOTE: bad0a746e9f4cf260dedba5828d9645d50176aac is cited in the OSV "fixed" field but does not have a code change.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xj9x-9j3p-fff9

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.

CVSS3: 9.8
1%
Низкий
9 дней назад
github логотип
GHSA-xj9x-95w7-mx93

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects Pandora FMS: from 700 through 773.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xj9w-qxv5-jhjg

An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. This allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via crafted perf_event_open and mmap system calls.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-xj9w-h48f-jf9m

Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj9w-cgqg-q897

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can submit private keys, ciphertext, and passphrases to perform server-side decryption without credentials, exposing key material to logs and enabling resource exhaustion attacks.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xj9w-76w3-9v9v

A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj9w-5r6q-x6v4

OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md

CVSS3: 8.8
1%
Низкий
4 месяца назад
github логотип
GHSA-xj9v-6q2f-vqhx

wifey vulnerable to Command Injection due to improper input sanitization

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xj9r-hfwq-rpc7

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Acroforms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22704.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xj9r-6r7r-x7p5

PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.

4%
Низкий
больше 4 лет назад

Уязвимостей на страницу