Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-xfv3-rrfm-f2rv

около 6 лет назад

Information Exposure in Netty

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xfv3-pv72-95q6

7 месяцев назад

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and last names. Other information such as social profile links and enrollment are also included.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xfv3-jp8h-q7v6

больше 3 лет назад

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xfv3-c2fr-gqcq

около 3 лет назад

A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file ex_catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236291.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xfrx-mv2w-4mhc

больше 4 лет назад

drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.

EPSS: Низкий
github логотип

GHSA-xfrx-g64h-2x84

10 дней назад

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: cap received transmit credits The interrupt-status packet reports transmit credits returned by the device. edge_interrupt_callback() adds the 16-bit value to txCredits without checking maxTxCredits. edge_write() uses txCredits minus the software FIFO count as the amount of data that fits. Since the FIFO is allocated with maxTxCredits bytes, txCredits exceeding maxTxCredits can cause OOB write in ring buffer. Cap accumulated credits at maxTxCredits. Conforming devices should never hit the cap.

EPSS: Низкий
github логотип

GHSA-xfrx-cmv6-fgvj

больше 3 лет назад

A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerability is the function override_content_width/register_settings of the file custom-content-width.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is e05e0104fc42ad13b57e2b2cb2d1857432624d39. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220219. NOTE: This attack is not very likely.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xfrw-pcmc-r2p3

около 4 лет назад

Missing permission checks in Jenkins OWASP Dependency-Track Plugin allow capturing credentials

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xfrw-hxr5-ghqf

около 5 лет назад

Cross-site Scripting in wagtail

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xfrw-g4q5-m2f8

11 месяцев назад

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xfrv-5h7j-4qvx

больше 4 лет назад

A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xfrr-v952-v375

11 месяцев назад

Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xfrr-fwx4-vqh9

больше 2 лет назад

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xfrr-5gq4-4j32

около 2 лет назад

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xfrr-5gjq-c74j

29 дней назад

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xfrq-p2m8-qpvm

около 1 месяца назад

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xfrq-jq75-3wqw

11 месяцев назад

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xfrq-7xgg-w3v5

больше 4 лет назад

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xfrq-44jr-w2f3

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xfrq-3339-mcj4

23 дня назад

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xfv3-rrfm-f2rv

Information Exposure in Netty

CVSS3: 7.5
5%
Низкий
около 6 лет назад
github логотип
GHSA-xfv3-pv72-95q6

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and last names. Other information such as social profile links and enrollment are also included.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xfv3-jp8h-q7v6

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xfv3-c2fr-gqcq

A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file ex_catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236291.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-xfrx-mv2w-4mhc

drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xfrx-g64h-2x84

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: cap received transmit credits The interrupt-status packet reports transmit credits returned by the device. edge_interrupt_callback() adds the 16-bit value to txCredits without checking maxTxCredits. edge_write() uses txCredits minus the software FIFO count as the amount of data that fits. Since the FIFO is allocated with maxTxCredits bytes, txCredits exceeding maxTxCredits can cause OOB write in ring buffer. Cap accumulated credits at maxTxCredits. Conforming devices should never hit the cap.

0%
Низкий
10 дней назад
github логотип
GHSA-xfrx-cmv6-fgvj

A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerability is the function override_content_width/register_settings of the file custom-content-width.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is e05e0104fc42ad13b57e2b2cb2d1857432624d39. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220219. NOTE: This attack is not very likely.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xfrw-pcmc-r2p3

Missing permission checks in Jenkins OWASP Dependency-Track Plugin allow capturing credentials

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xfrw-hxr5-ghqf

Cross-site Scripting in wagtail

CVSS3: 5.4
1%
Низкий
около 5 лет назад
github логотип
GHSA-xfrw-g4q5-m2f8

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-xfrv-5h7j-4qvx

A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xfrr-v952-v375

Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-xfrr-fwx4-vqh9

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xfrr-5gq4-4j32

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xfrr-5gjq-c74j

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

CVSS3: 6.6
0%
Низкий
29 дней назад
github логотип
GHSA-xfrq-p2m8-qpvm

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xfrq-jq75-3wqw

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-xfrq-7xgg-w3v5

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xfrq-44jr-w2f3

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-xfrq-3339-mcj4

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.

0%
Низкий
23 дня назад

Уязвимостей на страницу