Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj3x-5wmj-qmh3

больше 4 лет назад

SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.

EPSS: Низкий
github логотип

GHSA-xj3x-55gf-j7q8

больше 4 лет назад

admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.

EPSS: Низкий
github логотип

GHSA-xj3x-3vfq-979h

8 месяцев назад

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xj3w-mwcp-xp5m

больше 4 лет назад

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002005.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj3w-m54w-h7p9

10 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj3v-mc9q-x9hh

больше 4 лет назад

SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.

EPSS: Низкий
github логотип

GHSA-xj3v-fcjw-gv7p

больше 2 лет назад

An issue was discovered in the default configurations of ROS2 Iron Irwini ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to authenticate using default credentials.

EPSS: Низкий
github логотип

GHSA-xj3v-8p9p-j8q5

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ip: Fix a data-race around sysctl_fwmark_reflect. While reading sysctl_fwmark_reflect, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xj3r-qq7w-cg2x

больше 1 года назад

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xj3r-h978-v848

больше 4 лет назад

Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj3r-45pc-vrfq

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: locking/ww_mutex/test: Fix potential workqueue corruption In some cases running with the test-ww_mutex code, I was seeing odd behavior where sometimes it seemed flush_workqueue was returning before all the work threads were finished. Often this would cause strange crashes as the mutexes would be freed while they were being used. Looking at the code, there is a lifetime problem as the controlling thread that spawns the work allocates the "struct stress" structures that are passed to the workqueue threads. Then when the workqueue threads are finished, they free the stress struct that was passed to them. Unfortunately the workqueue work_struct node is in the stress struct. Which means the work_struct is freed before the work thread returns and while flush_workqueue is waiting. It seems like a better idea to have the controlling thread both allocate and free the stress structures, so that we can be sure we don't c...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj3q-64v9-867h

около 4 лет назад

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xj3q-3fqm-9f4h

больше 4 лет назад

PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xj3p-jj6q-38cj

около 4 лет назад

JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

EPSS: Низкий
github логотип

GHSA-xj3m-j93c-rfwv

больше 4 лет назад

Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."

EPSS: Низкий
github логотип

GHSA-xj3m-fx7f-hqmh

4 месяца назад

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj3j-28fv-mq6v

11 месяцев назад

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind server-side request forgery (SSRF) vulnerability reachable via the /var/www/app/console_release/hp/log_off_single_sign_on.php script that can be exploited by an unauthenticated user. When a printer is registered, the software stores the printer’s host name in the variable $printer_vo->str_host_address. The code later builds a URL like 'http://<host‑address>:80/DevMgmt/DiscoveryTree.xml' and sends the request with curl. No validation, whitelist, or private‑network filtering is performed before the request is made. Because the request is blind, an attacker cannot see the data directly, but can still: probe internal services, trigger internal actions, or gather other intelligence. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xj3h-vc9j-j823

около 8 лет назад

Directory Traversal in nodeaaaaa

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj3h-ghff-wj93

больше 3 лет назад

The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xj3h-gcxj-7pw6

больше 4 лет назад

Teardrop IP denial of service.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj3x-5wmj-qmh3

SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3x-55gf-j7q8

admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3x-3vfq-979h

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 3.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xj3w-mwcp-xp5m

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002005.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3w-m54w-h7p9

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

CVSS3: 6.5
0%
Низкий
10 дней назад
github логотип
GHSA-xj3v-mc9q-x9hh

SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3v-fcjw-gv7p

An issue was discovered in the default configurations of ROS2 Iron Irwini ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to authenticate using default credentials.

больше 2 лет назад
github логотип
GHSA-xj3v-8p9p-j8q5

In the Linux kernel, the following vulnerability has been resolved: ip: Fix a data-race around sysctl_fwmark_reflect. While reading sysctl_fwmark_reflect, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xj3r-qq7w-cg2x

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xj3r-h978-v848

Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3r-45pc-vrfq

In the Linux kernel, the following vulnerability has been resolved: locking/ww_mutex/test: Fix potential workqueue corruption In some cases running with the test-ww_mutex code, I was seeing odd behavior where sometimes it seemed flush_workqueue was returning before all the work threads were finished. Often this would cause strange crashes as the mutexes would be freed while they were being used. Looking at the code, there is a lifetime problem as the controlling thread that spawns the work allocates the "struct stress" structures that are passed to the workqueue threads. Then when the workqueue threads are finished, they free the stress struct that was passed to them. Unfortunately the workqueue work_struct node is in the stress struct. Which means the work_struct is freed before the work thread returns and while flush_workqueue is waiting. It seems like a better idea to have the controlling thread both allocate and free the stress structures, so that we can be sure we don't c...

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xj3q-64v9-867h

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj3q-3fqm-9f4h

PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3p-jj6q-38cj

JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj3m-j93c-rfwv

Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xj3m-fx7f-hqmh

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xj3j-28fv-mq6v

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind server-side request forgery (SSRF) vulnerability reachable via the /var/www/app/console_release/hp/log_off_single_sign_on.php script that can be exploited by an unauthenticated user. When a printer is registered, the software stores the printer’s host name in the variable $printer_vo->str_host_address. The code later builds a URL like 'http://<host‑address>:80/DevMgmt/DiscoveryTree.xml' and sends the request with curl. No validation, whitelist, or private‑network filtering is performed before the request is made. Because the request is blind, an attacker cannot see the data directly, but can still: probe internal services, trigger internal actions, or gather other intelligence. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

CVSS3: 5.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xj3h-vc9j-j823

Directory Traversal in nodeaaaaa

CVSS3: 7.5
2%
Низкий
около 8 лет назад
github логотип
GHSA-xj3h-ghff-wj93

The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xj3h-gcxj-7pw6

Teardrop IP denial of service.

36%
Средний
больше 4 лет назад

Уязвимостей на страницу