Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh73-mcmv-h45w

больше 4 лет назад

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh73-4jm2-j7c9

больше 4 лет назад

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh72-v6v9-mwhc

4 месяца назад

OpenClaw: Feishu webhook and card-action validation now fail closed

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh72-gqgw-x486

больше 4 лет назад

An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh72-9gpx-w4cx

больше 2 лет назад

A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh72-8hx6-6qv9

больше 4 лет назад

A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xh6x-jf3c-2xmf

почти 4 года назад

Windows Workstation Service Elevation of Privilege Vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh6w-jrm8-9v99

больше 4 лет назад

The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implementation."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh6v-cv6c-vgp6

около 4 лет назад

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

EPSS: Низкий
github логотип

GHSA-xh6r-vr44-6r8x

почти 2 года назад

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website certificates. Specifically, if a site certificate lacks the "Server Authentication" specification in the Extended Key Usage extension, the product does not verify the certificate's compliance with the site, deeming such certificates as valid. This flaw could allow an attacker to perform a Man-in-the-Middle (MITM) attack, intercepting and potentially altering communications between the user and the website.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xh6r-5wcf-38f6

2 месяца назад

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This makes it possible for unauthenticated attackers to overwrite existing media attachments with attacker-supplied file content by supplying a forged multipart POST request targeting any attachment the victim has edit_post capability over via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The forged request requires a victim with at least Author-level privileges, as the handler enforces a current_user_can('edit_post', $id) check; tricking an Author-level or higher user into clicking a crafted link is sufficient to trigger the overwrite against attachments that user can edit.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh6p-mmwp-c9gh

больше 4 лет назад

SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.

EPSS: Низкий
github логотип

GHSA-xh6p-h9xv-5c64

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out When both the RHBA and RPA FDMI requests time out, fnic reuses a frame to send ABTS for each of them. On send completion, this causes an attempt to free the same frame twice that leads to a crash. Fix crash by allocating separate frames for RHBA and RPA, and modify ABTS logic accordingly. Tested by checking MDS for FDMI information. Tested by using instrumented driver to: - Drop PLOGI response - Drop RHBA response - Drop RPA response - Drop RHBA and RPA response - Drop PLOGI response + ABTS response - Drop RHBA response + ABTS response - Drop RPA response + ABTS response - Drop RHBA and RPA response + ABTS response for both of them

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh6p-7c6x-4vjr

около 2 лет назад

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the mode_url=exec&command= substring. This affects EG-2000SE EG_RGOS 11.9 B11P1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh6m-gfx7-237c

больше 3 лет назад

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh6m-fr4r-mqj3

больше 1 года назад

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iPadOS 17.7.4, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3. An app may be able to fingerprint the user.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh6m-92pm-858v

больше 4 лет назад

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

EPSS: Низкий
github логотип

GHSA-xh6m-7cr7-xx66

больше 2 лет назад

Missing permission checks on Hazelcast client protocol

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xh6m-2h5x-55mh

больше 2 лет назад

An issue was discovered in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xh6j-v8vp-q869

больше 2 лет назад

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that the patch in 2.6.4 allows SVG uploads but the uploaded SVG files are sanitized.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh73-mcmv-h45w

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh73-4jm2-j7c9

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh72-v6v9-mwhc

OpenClaw: Feishu webhook and card-action validation now fail closed

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-xh72-gqgw-x486

An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh72-9gpx-w4cx

A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh72-8hx6-6qv9

A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh6x-jf3c-2xmf

Windows Workstation Service Elevation of Privilege Vulnerability.

CVSS3: 4.3
3%
Низкий
почти 4 года назад
github логотип
GHSA-xh6w-jrm8-9v99

The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a "page lock order bug in the XFS seek hole/data implementation."

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh6v-cv6c-vgp6

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

0%
Низкий
около 4 лет назад
github логотип
GHSA-xh6r-vr44-6r8x

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website certificates. Specifically, if a site certificate lacks the "Server Authentication" specification in the Extended Key Usage extension, the product does not verify the certificate's compliance with the site, deeming such certificates as valid. This flaw could allow an attacker to perform a Man-in-the-Middle (MITM) attack, intercepting and potentially altering communications between the user and the website.

CVSS3: 7.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xh6r-5wcf-38f6

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This makes it possible for unauthenticated attackers to overwrite existing media attachments with attacker-supplied file content by supplying a forged multipart POST request targeting any attachment the victim has edit_post capability over via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The forged request requires a victim with at least Author-level privileges, as the handler enforces a current_user_can('edit_post', $id) check; tricking an Author-level or higher user into clicking a crafted link is sufficient to trigger the overwrite against attachments that user can edit.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xh6p-mmwp-c9gh

SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh6p-h9xv-5c64

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out When both the RHBA and RPA FDMI requests time out, fnic reuses a frame to send ABTS for each of them. On send completion, this causes an attempt to free the same frame twice that leads to a crash. Fix crash by allocating separate frames for RHBA and RPA, and modify ABTS logic accordingly. Tested by checking MDS for FDMI information. Tested by using instrumented driver to: - Drop PLOGI response - Drop RHBA response - Drop RPA response - Drop RHBA and RPA response - Drop PLOGI response + ABTS response - Drop RHBA response + ABTS response - Drop RPA response + ABTS response - Drop RHBA and RPA response + ABTS response for both of them

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xh6p-7c6x-4vjr

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the mode_url=exec&command= substring. This affects EG-2000SE EG_RGOS 11.9 B11P1.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xh6m-gfx7-237c

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xh6m-fr4r-mqj3

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iPadOS 17.7.4, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3. An app may be able to fingerprint the user.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh6m-92pm-858v

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh6m-7cr7-xx66

Missing permission checks on Hazelcast client protocol

CVSS3: 7.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh6m-2h5x-55mh

An issue was discovered in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

CVSS3: 8.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xh6j-v8vp-q869

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that the patch in 2.6.4 allows SVG uploads but the uploaded SVG files are sanitized.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу