Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3hwc-4pxw-w633

больше 3 лет назад

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.

EPSS: Низкий
github логотип

GHSA-3hw8-vgvf-843g

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Intro.JS allows Reflected XSS. This issue affects WP Intro.JS: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hw8-h4fg-g6wr

больше 3 лет назад

An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.

EPSS: Низкий
github логотип

GHSA-3hw8-52j6-h699

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Peake Responsive Flickr Slideshow allows Stored XSS.This issue affects Responsive Flickr Slideshow: from n/a through 2.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hw7-qj9h-r835

9 месяцев назад

Gardener allows bypassing project secret validation which can lead to privilege escalation

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3hw7-239v-hfv6

8 месяцев назад

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hw6-gc8h-9243

больше 3 лет назад

Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3hw5-q855-g6cw

почти 6 лет назад

Prototype Pollution in Dojox

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3hw5-m8jj-m9vv

больше 3 лет назад

Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3hw5-fffc-qrg4

больше 3 лет назад

phpMyAdmin Denial of Service (DoS)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3hw4-pvhh-9qcq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer() commit 6f755e85c332 ("coresight: Add helper for inserting synchronization packets") removed trailing '\0' from barrier_pkt array and updated the call sites like etb_update_buffer() to have proper checks for barrier_pkt size before read but missed updating tmc_update_etf_buffer() which still reads barrier_pkt past the array size resulting in KASAN out-of-bounds bug. Fix this by adding a check for barrier_pkt size before accessing like it is done in etb_update_buffer(). BUG: KASAN: global-out-of-bounds in tmc_update_etf_buffer+0x4b8/0x698 Read of size 4 at addr ffffffd05b7d1030 by task perf/2629 Call trace: dump_backtrace+0x0/0x27c show_stack+0x20/0x2c dump_stack+0x11c/0x188 print_address_description+0x3c/0x4a4 __kasan_report+0x140/0x164 kasan_report+0x10/0x18 __asan_report_load4_noabort+0x1c/0x24 tmc_update_etf_buffer+0x4b8...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hw4-hh3h-jx7q

больше 3 лет назад

libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hw3-mqwc-2cjg

почти 4 года назад

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.

EPSS: Высокий
github логотип

GHSA-3hw3-mqpp-fqg6

почти 4 года назад

Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.

EPSS: Низкий
github логотип

GHSA-3hw3-cr75-52m9

почти 4 года назад

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

EPSS: Низкий
github логотип

GHSA-3hw3-6562-638v

почти 2 года назад

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263310 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hw2-h67c-wq66

больше 3 лет назад

Uncontrolled Recursion in Akka HTTP

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3hw2-5vm9-c366

больше 3 лет назад

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.

EPSS: Низкий
github логотип

GHSA-3hvx-pxjp-5p5j

почти 4 года назад

Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters.

EPSS: Низкий
github логотип

GHSA-3hvv-xgr4-fr7x

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to allocated size for such cases.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hwc-4pxw-w633

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw8-vgvf-843g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Intro.JS allows Reflected XSS. This issue affects WP Intro.JS: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3hw8-h4fg-g6wr

An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw8-52j6-h699

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Peake Responsive Flickr Slideshow allows Stored XSS.This issue affects Responsive Flickr Slideshow: from n/a through 2.6.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3hw7-qj9h-r835

Gardener allows bypassing project secret validation which can lead to privilege escalation

CVSS3: 9.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-3hw7-239v-hfv6

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-3hw6-gc8h-9243

Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw5-q855-g6cw

Prototype Pollution in Dojox

CVSS3: 7.7
0%
Низкий
почти 6 лет назад
github логотип
GHSA-3hw5-m8jj-m9vv

Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw5-fffc-qrg4

phpMyAdmin Denial of Service (DoS)

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw4-pvhh-9qcq

In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer() commit 6f755e85c332 ("coresight: Add helper for inserting synchronization packets") removed trailing '\0' from barrier_pkt array and updated the call sites like etb_update_buffer() to have proper checks for barrier_pkt size before read but missed updating tmc_update_etf_buffer() which still reads barrier_pkt past the array size resulting in KASAN out-of-bounds bug. Fix this by adding a check for barrier_pkt size before accessing like it is done in etb_update_buffer(). BUG: KASAN: global-out-of-bounds in tmc_update_etf_buffer+0x4b8/0x698 Read of size 4 at addr ffffffd05b7d1030 by task perf/2629 Call trace: dump_backtrace+0x0/0x27c show_stack+0x20/0x2c dump_stack+0x11c/0x188 print_address_description+0x3c/0x4a4 __kasan_report+0x140/0x164 kasan_report+0x10/0x18 __asan_report_load4_noabort+0x1c/0x24 tmc_update_etf_buffer+0x4b8...

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hw4-hh3h-jx7q

libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw3-mqwc-2cjg

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.

86%
Высокий
почти 4 года назад
github логотип
GHSA-3hw3-mqpp-fqg6

Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hw3-cr75-52m9

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3hw3-6562-638v

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263310 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hw2-h67c-wq66

Uncontrolled Recursion in Akka HTTP

CVSS3: 7.5
76%
Высокий
больше 3 лет назад
github логотип
GHSA-3hw2-5vm9-c366

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hvx-pxjp-5p5j

Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3hvv-xgr4-fr7x

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to allocated size for such cases.

CVSS3: 5.5
0%
Низкий
9 месяцев назад

Уязвимостей на страницу