Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-xx52-g2px-mxcx

больше 4 лет назад

BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise through 5.0.4 MR6 log cleartext credentials during exception handling, which might allow context-dependent attackers to obtain sensitive information by reading a log file.

EPSS: Низкий
github логотип

GHSA-xx52-9m5j-pp7h

больше 2 лет назад

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx52-6w26-g473

больше 4 лет назад

SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.

EPSS: Низкий
github логотип

GHSA-xx52-3mch-r5wp

больше 4 лет назад

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx4x-7c38-rpq3

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not check the return values of clk_get(). This could lead to a kernel crash when the invalid pointers are later dereferenced by clock core functions. Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding IS_ERR() checks immediately after each clock acquisition.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx4w-vp73-2842

больше 4 лет назад

A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to elevate their privileges. A successful exploit could allow an attacker to execute arbitrary code with SYSTEM level privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx4w-8h42-jm57

около 1 года назад

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to cause unexpected system termination.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xx4v-prfh-6cgc

больше 1 года назад

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx4v-fp2m-hmpv

больше 4 лет назад

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.

EPSS: Низкий
github логотип

GHSA-xx4r-v983-p5jq

больше 4 лет назад

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xx4r-5265-48j6

больше 2 лет назад

silverstripe/framework SQL injection in full text search

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx4q-xvq8-pqjv

около 1 года назад

A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xx4q-9h3q-wpv9

больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx4p-cqfx-r6v6

около 3 лет назад

In initiateTdlsTeardownInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235951

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xx4p-56g4-h2m8

16 дней назад

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx4m-rfhv-5rx3

больше 4 лет назад

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to complete a transition from Low Integrity to Medium Integrity by leveraging incorrect permissions.

EPSS: Низкий
github логотип

GHSA-xx4m-fcjj-4mc6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.

EPSS: Низкий
github логотип

GHSA-xx4m-763q-h8x3

больше 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xx4j-w367-7247

24 дня назад

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xx4j-rvcc-2vhr

больше 4 лет назад

Capstone SEGV caused by a read memory access

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx52-g2px-mxcx

BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise through 5.0.4 MR6 log cleartext credentials during exception handling, which might allow context-dependent attackers to obtain sensitive information by reading a log file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx52-9m5j-pp7h

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xx52-6w26-g473

SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx52-3mch-r5wp

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx4x-7c38-rpq3

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not check the return values of clk_get(). This could lead to a kernel crash when the invalid pointers are later dereferenced by clock core functions. Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding IS_ERR() checks immediately after each clock acquisition.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xx4w-vp73-2842

A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to elevate their privileges. A successful exploit could allow an attacker to execute arbitrary code with SYSTEM level privileges.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xx4w-8h42-jm57

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to cause unexpected system termination.

CVSS3: 3.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xx4v-prfh-6cgc

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xx4v-fp2m-hmpv

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals the installation path in an error message, a different vulnerability than CVE-2011-2488.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx4r-v983-p5jq

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

CVSS3: 9.8
22%
Средний
больше 4 лет назад
github логотип
GHSA-xx4r-5265-48j6

silverstripe/framework SQL injection in full text search

CVSS3: 8.8
больше 2 лет назад
github логотип
GHSA-xx4q-xvq8-pqjv

A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
около 1 года назад
github логотип
GHSA-xx4q-9h3q-wpv9

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx4p-cqfx-r6v6

In initiateTdlsTeardownInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235951

CVSS3: 4.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx4p-56g4-h2m8

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

CVSS3: 5.3
0%
Низкий
16 дней назад
github логотип
GHSA-xx4m-rfhv-5rx3

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to complete a transition from Low Integrity to Medium Integrity by leveraging incorrect permissions.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xx4m-fcjj-4mc6

Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx4m-763q-h8x3

Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.

CVSS3: 9.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xx4j-w367-7247

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

CVSS3: 8.2
0%
Низкий
24 дня назад
github логотип
GHSA-xx4j-rvcc-2vhr

Capstone SEGV caused by a read memory access

CVSS3: 5.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу