Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg7j-75jq-gm7f

больше 4 лет назад

An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will cause a use-after-free.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg7j-42pr-9v55

больше 2 лет назад

A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects the function delete_ltype of the file delete_ltype.php of the component Loan Type Page. The manipulation of the argument ltype_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246137 was assigned to this vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xg7h-qf8j-p98r

больше 4 лет назад

An elevation of privilege vulnerability exists when Windows fails a check, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2008 R2, Windows 10. This CVE ID is unique from CVE-2018-8313.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xg7g-jmmf-pmrh

2 месяца назад

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg7f-gpc9-59gg

больше 1 года назад

Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId parameter manipulation in a form sent to endpoints "/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx" and "/TotalAgility/Kofax/BrowserDevice/ScanFrontDebug.aspx" This allows for injection of a malicious JavaScript code, leading to a possible information leak.  Exploitation is possible only while using POST requests and also requires retrieving/generating a proper VIEWSTATE parameter, which limits the risk of a successful attack.

EPSS: Низкий
github логотип

GHSA-xg7f-9m4r-jh69

больше 4 лет назад

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg7c-hpj9-r697

больше 4 лет назад

Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.

EPSS: Низкий
github логотип

GHSA-xg7c-7v8p-8ww8

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core Features designthemes-core-features allows Reflected XSS.This issue affects DesignThemes Core Features: from n/a through <= 2.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xg7c-263c-79vp

почти 4 года назад

IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xg79-vpm4-cg56

около 3 лет назад

PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xg78-wwf5-gc23

больше 4 лет назад

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using the web UI of the affected software. An attacker could exploit this vulnerability by using the web UI of the affected software to create a new user and then logging into the web UI as the newly created user. A successful exploit could allow the attacker to elevate their privileges on the affected device. This vulnerability affects Cisco devices that are running a vulnerable release Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuy83062.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg77-xqhq-crpr

около 4 лет назад

Stored XSS vulnerability in Code Coverage API Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg77-wrvc-q75c

около 2 лет назад

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg77-wqrq-9jqj

почти 3 года назад

Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg77-mvwp-crp2

около 4 лет назад

In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.

EPSS: Низкий
github логотип

GHSA-xg77-fgx3-94j3

больше 4 лет назад

PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.

EPSS: Низкий
github логотип

GHSA-xg77-2m7h-4885

около 1 года назад

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg76-5qj2-2hhv

3 месяца назад

Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg76-3pjj-pf64

больше 4 лет назад

The br_mdb_ip_get function in net/bridge/br_multicast.c in the Linux kernel before 2.6.35-rc5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an IGMP packet, related to lack of a multicast table.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg75-q3q5-cqmv

больше 4 лет назад

Denial of Service in http-swagger

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg7j-75jq-gm7f

An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will cause a use-after-free.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7j-42pr-9v55

A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects the function delete_ltype of the file delete_ltype.php of the component Loan Type Page. The manipulation of the argument ltype_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246137 was assigned to this vulnerability.

CVSS3: 4.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xg7h-qf8j-p98r

An elevation of privilege vulnerability exists when Windows fails a check, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2008 R2, Windows 10. This CVE ID is unique from CVE-2018-8313.

CVSS3: 4.7
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7g-jmmf-pmrh

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xg7f-gpc9-59gg

Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId parameter manipulation in a form sent to endpoints "/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx" and "/TotalAgility/Kofax/BrowserDevice/ScanFrontDebug.aspx" This allows for injection of a malicious JavaScript code, leading to a possible information leak.  Exploitation is possible only while using POST requests and also requires retrieving/generating a proper VIEWSTATE parameter, which limits the risk of a successful attack.

1%
Низкий
больше 1 года назад
github логотип
GHSA-xg7f-9m4r-jh69

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7c-hpj9-r697

Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7c-7v8p-8ww8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core Features designthemes-core-features allows Reflected XSS.This issue affects DesignThemes Core Features: from n/a through <= 2.3.

CVSS3: 7.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xg7c-263c-79vp

IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.

CVSS3: 7.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xg79-vpm4-cg56

PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xg78-wwf5-gc23

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using the web UI of the affected software. An attacker could exploit this vulnerability by using the web UI of the affected software to create a new user and then logging into the web UI as the newly created user. A successful exploit could allow the attacker to elevate their privileges on the affected device. This vulnerability affects Cisco devices that are running a vulnerable release Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuy83062.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg77-xqhq-crpr

Stored XSS vulnerability in Code Coverage API Plugin

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xg77-wrvc-q75c

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xg77-wqrq-9jqj

Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xg77-mvwp-crp2

In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.

7%
Низкий
около 4 лет назад
github логотип
GHSA-xg77-fgx3-94j3

PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg77-2m7h-4885

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xg76-5qj2-2hhv

Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-xg76-3pjj-pf64

The br_mdb_ip_get function in net/bridge/br_multicast.c in the Linux kernel before 2.6.35-rc5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an IGMP packet, related to lack of a multicast table.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xg75-q3q5-cqmv

Denial of Service in http-swagger

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу