Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42q7-95j7-w62m

больше 1 года назад

Mautic is vulnerable to XSS vulnerability

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-42q6-q2fj-4rjg

больше 3 лет назад

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42q6-p5h5-993x

почти 4 года назад

Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.

EPSS: Средний
github логотип

GHSA-42q5-gvj7-g3c2

больше 3 лет назад

There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

EPSS: Низкий
github логотип

GHSA-42q5-3w9f-c6pw

7 месяцев назад

Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42q4-wr7h-j9qx

больше 3 лет назад

The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42q4-9xf9-f67x

больше 3 лет назад

Apache Superset allowed for database connections password leak for authenticated users

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42q3-f5fp-gpxr

почти 4 года назад

** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value.

EPSS: Низкий
github логотип

GHSA-42q2-w7pp-mx38

почти 4 года назад

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.

EPSS: Низкий
github логотип

GHSA-42q2-m54f-jh95

около 3 лет назад

sememos/memos vulnerable to Improper Handling of Values

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42px-vp8x-r9wx

больше 3 лет назад

The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42pv-rvjf-mxph

больше 3 лет назад

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42pr-hpj6-p97q

больше 3 лет назад

The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42pq-hf34-5c7v

больше 3 лет назад

cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-42pq-h6rj-6c6q

около 3 лет назад

Memory corruption in Core due to stack-based buffer overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42pq-634r-jghr

больше 2 лет назад

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-42pp-ccmj-xrg8

больше 3 лет назад

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

EPSS: Низкий
github логотип

GHSA-42pm-gg43-38gr

больше 3 лет назад

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42pj-96jc-q58w

около 4 лет назад

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.

EPSS: Низкий
github логотип

GHSA-42pj-35w6-4jwg

почти 2 года назад

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42q7-95j7-w62m

Mautic is vulnerable to XSS vulnerability

CVSS3: 9.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-42q6-q2fj-4rjg

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42q6-p5h5-993x

Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.

23%
Средний
почти 4 года назад
github логотип
GHSA-42q5-gvj7-g3c2

There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42q5-3w9f-c6pw

Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-42q4-wr7h-j9qx

The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42q4-9xf9-f67x

Apache Superset allowed for database connections password leak for authenticated users

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42q3-f5fp-gpxr

** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value.

1%
Низкий
почти 4 года назад
github логотип
GHSA-42q2-w7pp-mx38

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-42q2-m54f-jh95

sememos/memos vulnerable to Improper Handling of Values

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-42px-vp8x-r9wx

The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-42pv-rvjf-mxph

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42pr-hpj6-p97q

The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42pq-hf34-5c7v

cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42pq-h6rj-6c6q

Memory corruption in Core due to stack-based buffer overflow.

CVSS3: 7.8
4%
Низкий
около 3 лет назад
github логотип
GHSA-42pq-634r-jghr

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVSS3: 9.8
33%
Средний
больше 2 лет назад
github логотип
GHSA-42pp-ccmj-xrg8

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42pm-gg43-38gr

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42pj-96jc-q58w

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.

0%
Низкий
около 4 лет назад
github логотип
GHSA-42pj-35w6-4jwg

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7
0%
Низкий
почти 2 года назад

Уязвимостей на страницу