Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xhw9-4wqq-x67v

почти 4 года назад

rdiffweb vulnerable to potential DoS via memory consumption

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhw8-g8mh-rxvw

около 4 лет назад

An issue was discovered in Corel PaintShop Pro 2019 21.0.0.119. An integer overflow in the jp2 parsing library allows an attacker to overwrite memory and to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xhw8-cw4m-2j3c

больше 3 лет назад

An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xhw8-7rfw-2fg2

больше 3 лет назад

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhw8-68ww-6958

около 4 лет назад

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhw8-46vj-3gq5

больше 1 года назад

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xhw7-r59x-5m6x

около 1 года назад

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

EPSS: Средний
github логотип

GHSA-xhw7-jhmp-j62j

5 месяцев назад

`dnp3times` was removed from crates.io due to malicious code

EPSS: Низкий
github логотип

GHSA-xhw7-j96h-c3g5

3 месяца назад

YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhw7-9wqv-ffm2

около 4 лет назад

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.

EPSS: Низкий
github логотип

GHSA-xhw7-5gmc-634h

больше 4 лет назад

Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhw6-hjc9-679m

больше 4 лет назад

Pac4j token validation bypass if OpenID Connect provider supports none algorithm

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhw6-399x-xj62

около 4 лет назад

The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value within JSON data.

EPSS: Низкий
github логотип

GHSA-xhw5-gfmh-rhfw

около 4 лет назад

IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhw5-6m93-pmpj

около 4 лет назад

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.

EPSS: Низкий
github логотип

GHSA-xhw4-f4c3-7c2f

28 дней назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() Clear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link routine.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhw4-5qgr-c2w2

около 4 лет назад

Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

EPSS: Низкий
github логотип

GHSA-xhw3-wmx2-76wf

около 4 лет назад

Buffer overflow in Jenkins WMI Windows Agents plugin

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-xhw3-h8gq-2w23

почти 2 года назад

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhw3-4j3m-hq53

больше 1 года назад

Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhw9-4wqq-x67v

rdiffweb vulnerable to potential DoS via memory consumption

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xhw8-g8mh-rxvw

An issue was discovered in Corel PaintShop Pro 2019 21.0.0.119. An integer overflow in the jp2 parsing library allows an attacker to overwrite memory and to execute arbitrary code.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xhw8-cw4m-2j3c

An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xhw8-7rfw-2fg2

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xhw8-68ww-6958

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xhw8-46vj-3gq5

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhw7-r59x-5m6x

An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

14%
Средний
около 1 года назад
github логотип
GHSA-xhw7-jhmp-j62j

`dnp3times` was removed from crates.io due to malicious code

5 месяцев назад
github логотип
GHSA-xhw7-j96h-c3g5

YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xhw7-9wqv-ffm2

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xhw7-5gmc-634h

Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhw6-hjc9-679m

Pac4j token validation bypass if OpenID Connect provider supports none algorithm

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhw6-399x-xj62

The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value within JSON data.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhw5-gfmh-rhfw

IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhw5-6m93-pmpj

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhw4-f4c3-7c2f

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() Clear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link routine.

CVSS3: 8.8
0%
Низкий
28 дней назад
github логотип
GHSA-xhw4-5qgr-c2w2

Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

9%
Низкий
около 4 лет назад
github логотип
GHSA-xhw3-wmx2-76wf

Buffer overflow in Jenkins WMI Windows Agents plugin

CVSS3: 4.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhw3-h8gq-2w23

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xhw3-4j3m-hq53

Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion

CVSS3: 8.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу