Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-xg4x-w83h-xxj6

9 месяцев назад

The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the __kds_flag functionality that imports featured images. This makes it possible for authenticated attackers, with Adminstrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xg4x-w2j3-57h6

7 месяцев назад

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xg4x-jpjh-84hv

11 месяцев назад

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xg4x-58xv-5259

больше 4 лет назад

SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.

EPSS: Низкий
github логотип

GHSA-xg4x-2cmm-rgc9

4 месяца назад

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg4w-2qmm-9pfm

больше 2 лет назад

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xg4v-qw5v-j6h2

больше 3 лет назад

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg4v-h682-43v2

9 месяцев назад

Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg4r-c4j2-fcj4

больше 4 лет назад

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xg4r-75h7-2cgv

больше 4 лет назад

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg4q-hj2g-49gr

больше 2 лет назад

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for 'abc@gmail.com' and 'Abc@gmail.com' can both be created, leading to potential impersonation and confusion among users.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg4q-g85w-x6x5

7 месяцев назад

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

EPSS: Низкий
github логотип

GHSA-xg4p-hrwg-fqj6

больше 4 лет назад

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg4j-9fq9-qmm5

30 дней назад

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/U...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xg4h-q3qm-pp3c

больше 4 лет назад

thttpd has a local DoS vulnerability via specially-crafted .htpasswd files

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg4h-6gfc-h4m8

27 дней назад

etcd: Watch API authorization bypass via open-ended range requests

EPSS: Низкий
github логотип

GHSA-xg4h-4wcx-6x7v

больше 4 лет назад

Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.

EPSS: Низкий
github логотип

GHSA-xg4g-j93q-xpmh

почти 3 года назад

Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xg4f-mwxf-g67f

5 дней назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: reject stream disable with no active interface handle_uaudio_stream_req() resolves an interface index with info_idx_from_ifnum(), which returns -EINVAL when no interface matches. The enable branch and the response: cleanup label both guard against a negative index, but the disable branch does not: it forms info = &uadev[pcm_card_num].info[info_idx] and dereferences it. uadev[].info is a pointer allocated only when a stream is first enabled, so a negative info_idx on the disable path is unsafe in two ways: - If the card was never enabled, .info is NULL and &info[-EINVAL] is a wild pointer; reading info->data_ep_pipe faults (kernel oops). - If the card was enabled at least once (.info allocated) and the disable names an interface that does not match, &info[-EINVAL] points before the allocation; info->data_ep_pipe / info->sync_ep_pipe are an out-of-bounds slab read and, when no...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg49-wcx3-x7r3

около 4 лет назад

The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg4x-w83h-xxj6

The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the __kds_flag functionality that imports featured images. This makes it possible for authenticated attackers, with Adminstrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 4.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-xg4x-w2j3-57h6

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

CVSS3: 5.9
0%
Низкий
7 месяцев назад
github логотип
GHSA-xg4x-jpjh-84hv

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xg4x-58xv-5259

SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg4x-2cmm-rgc9

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.

CVSS3: 6.5
1%
Низкий
4 месяца назад
github логотип
GHSA-xg4w-2qmm-9pfm

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CVSS3: 8.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xg4v-qw5v-j6h2

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xg4v-h682-43v2

Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xg4r-c4j2-fcj4

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg4r-75h7-2cgv

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg4q-hj2g-49gr

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for 'abc@gmail.com' and 'Abc@gmail.com' can both be created, leading to potential impersonation and confusion among users.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xg4q-g85w-x6x5

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

0%
Низкий
7 месяцев назад
github логотип
GHSA-xg4p-hrwg-fqj6

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg4j-9fq9-qmm5

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/U...

CVSS3: 3.1
0%
Низкий
30 дней назад
github логотип
GHSA-xg4h-q3qm-pp3c

thttpd has a local DoS vulnerability via specially-crafted .htpasswd files

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg4h-6gfc-h4m8

etcd: Watch API authorization bypass via open-ended range requests

0%
Низкий
27 дней назад
github логотип
GHSA-xg4h-4wcx-6x7v

Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg4g-j93q-xpmh

Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xg4f-mwxf-g67f

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: reject stream disable with no active interface handle_uaudio_stream_req() resolves an interface index with info_idx_from_ifnum(), which returns -EINVAL when no interface matches. The enable branch and the response: cleanup label both guard against a negative index, but the disable branch does not: it forms info = &uadev[pcm_card_num].info[info_idx] and dereferences it. uadev[].info is a pointer allocated only when a stream is first enabled, so a negative info_idx on the disable path is unsafe in two ways: - If the card was never enabled, .info is NULL and &info[-EINVAL] is a wild pointer; reading info->data_ep_pipe faults (kernel oops). - If the card was enabled at least once (.info allocated) and the disable names an interface that does not match, &info[-EINVAL] points before the allocation; info->data_ep_pipe / info->sync_ep_pipe are an out-of-bounds slab read and, when no...

CVSS3: 7.8
0%
Низкий
5 дней назад
github логотип
GHSA-xg49-wcx3-x7r3

The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу