Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh2m-55cw-vq57

больше 4 лет назад

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xh2j-q4mc-v522

больше 4 лет назад

Moodle calculated question type allows remote code execution by Question authors

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xh2h-xr83-rv32

10 месяцев назад

An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh2h-f6rw-xfqx

около 4 лет назад

Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.

EPSS: Низкий
github логотип

GHSA-xh2h-cw6h-x9h5

около 4 лет назад

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-xh2g-m2wv-2336

больше 2 лет назад

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of the argument currency leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-255502 is the identifier assigned to this vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xh2g-2958-rp54

больше 4 лет назад

BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh2f-mpwc-mhh4

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh2f-j4vc-q8qj

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Add missing check and free for ida_alloc Add the check for the return value of the ida_alloc in order to avoid NULL pointer dereference. Moreover, free allocated "ctx->id" if mdp_m2m_open fails later in order to avoid memory leak.

EPSS: Низкий
github логотип

GHSA-xh2f-h76w-4qqc

больше 4 лет назад

The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.

EPSS: Средний
github логотип

GHSA-xh2c-vxrg-5c77

около 4 лет назад

JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh2c-m49q-f2gf

больше 2 лет назад

Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh2c-fh83-6hgx

почти 4 года назад

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh2c-5r7j-3g84

около 1 года назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xh29-wvh5-6vww

больше 4 лет назад

RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.

EPSS: Средний
github логотип

GHSA-xh29-r392-48pf

больше 1 года назад

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-xh29-r2w5-wx8m

около 4 лет назад

Nokogiri Improperly Handles Unexpected Data Type

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xh29-jpw9-pv7c

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger() If iio_trigger_register() returns error, it should call iio_trigger_free() to give up the reference that hold in iio_trigger_alloc(), so that it can call iio_trig_release() to free memory when the refcount hit to 0.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh29-778x-wq63

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters.

EPSS: Низкий
github логотип

GHSA-xh28-r3j4-439x

9 месяцев назад

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh2m-55cw-vq57

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh2j-q4mc-v522

Moodle calculated question type allows remote code execution by Question authors

CVSS3: 8.8
32%
Средний
больше 4 лет назад
github логотип
GHSA-xh2h-xr83-rv32

An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xh2h-f6rw-xfqx

Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xh2h-cw6h-x9h5

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

CVSS3: 7.5
95%
Критический
около 4 лет назад
github логотип
GHSA-xh2g-m2wv-2336

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of the argument currency leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-255502 is the identifier assigned to this vulnerability.

CVSS3: 4.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh2g-2958-rp54

BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh2f-mpwc-mhh4

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh2f-j4vc-q8qj

In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Add missing check and free for ida_alloc Add the check for the return value of the ida_alloc in order to avoid NULL pointer dereference. Moreover, free allocated "ctx->id" if mdp_m2m_open fails later in order to avoid memory leak.

0%
Низкий
8 месяцев назад
github логотип
GHSA-xh2f-h76w-4qqc

The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.

11%
Средний
больше 4 лет назад
github логотип
GHSA-xh2c-vxrg-5c77

JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xh2c-m49q-f2gf

Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xh2c-fh83-6hgx

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xh2c-5r7j-3g84

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 1 года назад
github логотип
GHSA-xh29-wvh5-6vww

RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.

22%
Средний
больше 4 лет назад
github логотип
GHSA-xh29-r392-48pf

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.

CVSS3: 4.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh29-r2w5-wx8m

Nokogiri Improperly Handles Unexpected Data Type

CVSS3: 8.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-xh29-jpw9-pv7c

In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger() If iio_trigger_register() returns error, it should call iio_trigger_free() to give up the reference that hold in iio_trigger_alloc(), so that it can call iio_trig_release() to free memory when the refcount hit to 0.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh29-778x-wq63

Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh28-r3j4-439x

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.

CVSS3: 5.3
0%
Низкий
9 месяцев назад

Уязвимостей на страницу