Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-xvwq-6652-7rm2

почти 4 года назад

Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvwp-q2w5-88cf

около 2 лет назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xvwp-h6jv-7472

около 3 лет назад

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvwm-fhx3-vrj9

больше 3 лет назад

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xvwj-v9pv-cwjj

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvwh-qhvg-2jjx

больше 3 лет назад

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwg-32hp-p5p5

почти 4 года назад

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

EPSS: Низкий
github логотип

GHSA-xvwf-ffg2-9c6p

больше 3 лет назад

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwf-58fx-rg4f

около 1 года назад

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwc-mxm8-8hqg

больше 1 года назад

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvwc-m4qj-9wr9

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvw9-48jx-4p2f

9 месяцев назад

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xvw9-3mhm-xjqq

больше 2 лет назад

Apache Airflow information disclosure vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvw8-w3w2-qpgq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

EPSS: Низкий
github логотип

GHSA-xvw8-mqg6-cchx

11 месяцев назад

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvw8-h732-w84c

9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-xvw6-gw98-7w9w

около 2 лет назад

The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvw6-2phf-v6gr

8 месяцев назад

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through 1.0.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvw5-r9xw-9jjv

больше 3 лет назад

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

EPSS: Низкий
github логотип

GHSA-xvw5-c4h4-r2rh

больше 3 лет назад

Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvwq-6652-7rm2

Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwp-q2w5-88cf

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

CVSS3: 3.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvwp-h6jv-7472

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVSS3: 7.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-xvwm-fhx3-vrj9

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvwj-v9pv-cwjj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xvwh-qhvg-2jjx

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvwg-32hp-p5p5

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwf-ffg2-9c6p

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvwf-58fx-rg4f

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xvwc-mxm8-8hqg

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvwc-m4qj-9wr9

Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvw9-48jx-4p2f

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-xvw9-3mhm-xjqq

Apache Airflow information disclosure vulnerability

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvw8-w3w2-qpgq

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvw8-mqg6-cchx

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-xvw8-h732-w84c

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

9 месяцев назад
github логотип
GHSA-xvw6-gw98-7w9w

The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvw6-2phf-v6gr

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through 1.0.9.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xvw5-r9xw-9jjv

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvw5-c4h4-r2rh

Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

CVSS3: 7.5
9%
Низкий
больше 3 лет назад

Уязвимостей на страницу