Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38vw-2crj-2w79

больше 3 лет назад

Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.

EPSS: Низкий
github логотип

GHSA-38vv-qgw3-86p8

больше 1 года назад

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38vr-vph7-hmrx

больше 3 лет назад

The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38vr-r7mr-r99m

больше 3 лет назад

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38vr-8qrj-3x4h

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: xhci: Handle TD clearing for multiple streams case When multiple streams are in use, multiple TDs might be in flight when an endpoint is stopped. We need to issue a Set TR Dequeue Pointer for each, to ensure everything is reset properly and the caches cleared. Change the logic so that any N>1 TDs found active for different streams are deferred until after the first one is processed, calling xhci_invalidate_cancelled_tds() again from xhci_handle_cmd_set_deq() to queue another command until we are done with all of them. Also change the error/"should never happen" paths to ensure we at least clear any affected TDs, even if we can't issue a command to clear the hardware cache, and complain loudly with an xhci_warn() if this ever happens. This problem case dates back to commit e9df17eb1408 ("USB: xhci: Correct assumptions about number of rings per endpoint.") early on in the XHCI driver's life, when stream support was...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38vr-4p57-8h9g

больше 3 лет назад

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-38vq-m27v-m4wq

больше 3 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper controls in MSM CORE leads to use memory after it is freed in msm_core_ioctl().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38vq-hh87-cj57

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters.

EPSS: Низкий
github логотип

GHSA-38vq-g6vr-w8wf

17 дней назад

Sentencepiece has a a heap overflow issue

EPSS: Низкий
github логотип

GHSA-38vq-cjh5-vw7x

больше 5 лет назад

Malicious Package in nodes.js

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38vq-9wrc-xxh4

около 1 месяца назад

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38vp-pppf-865m

почти 4 года назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Низкий
github логотип

GHSA-38vj-q4h7-q9qr

почти 4 года назад

Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.

EPSS: Низкий
github логотип

GHSA-38vh-mhxc-849f

больше 3 лет назад

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local users to obtain sensitive information by reading a file.

EPSS: Низкий
github логотип

GHSA-38vh-jg38-2rqp

больше 3 лет назад

Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38vh-68q7-274w

больше 3 лет назад

The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module.

EPSS: Низкий
github логотип

GHSA-38vg-j2xv-fm9g

около 2 лет назад

Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38vf-g5j6-x7wv

23 дня назад

StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-38vf-35cg-m73w

больше 2 лет назад

Cockpit CMS arbitrary file upload vulnerability

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-38v9-j34p-hprg

больше 3 лет назад

MatrikonOPC SCADA DNP3 OPC Server 1.2.0 allows remote attackers to cause a denial of service (master-station daemon crash) via a malformed DNP3 TCP packet from the IP address of an outstation.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38vw-2crj-2w79

Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38vv-qgw3-86p8

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-38vr-vph7-hmrx

The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38vr-r7mr-r99m

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38vr-8qrj-3x4h

In the Linux kernel, the following vulnerability has been resolved: xhci: Handle TD clearing for multiple streams case When multiple streams are in use, multiple TDs might be in flight when an endpoint is stopped. We need to issue a Set TR Dequeue Pointer for each, to ensure everything is reset properly and the caches cleared. Change the logic so that any N>1 TDs found active for different streams are deferred until after the first one is processed, calling xhci_invalidate_cancelled_tds() again from xhci_handle_cmd_set_deq() to queue another command until we are done with all of them. Also change the error/"should never happen" paths to ensure we at least clear any affected TDs, even if we can't issue a command to clear the hardware cache, and complain loudly with an xhci_warn() if this ever happens. This problem case dates back to commit e9df17eb1408 ("USB: xhci: Correct assumptions about number of rings per endpoint.") early on in the XHCI driver's life, when stream support was...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-38vr-4p57-8h9g

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38vq-m27v-m4wq

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper controls in MSM CORE leads to use memory after it is freed in msm_core_ioctl().

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38vq-hh87-cj57

Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38vq-g6vr-w8wf

Sentencepiece has a a heap overflow issue

0%
Низкий
17 дней назад
github логотип
GHSA-38vq-cjh5-vw7x

Malicious Package in nodes.js

CVSS3: 9.8
больше 5 лет назад
github логотип
GHSA-38vq-9wrc-xxh4

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-38vp-pppf-865m

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

1%
Низкий
почти 4 года назад
github логотип
GHSA-38vj-q4h7-q9qr

Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38vh-mhxc-849f

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local users to obtain sensitive information by reading a file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38vh-jg38-2rqp

Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-38vh-68q7-274w

The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38vg-j2xv-fm9g

Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-38vf-g5j6-x7wv

StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVSS3: 7.2
0%
Низкий
23 дня назад
github логотип
GHSA-38vf-35cg-m73w

Cockpit CMS arbitrary file upload vulnerability

CVSS3: 6.1
20%
Средний
больше 2 лет назад
github логотип
GHSA-38v9-j34p-hprg

MatrikonOPC SCADA DNP3 OPC Server 1.2.0 allows remote attackers to cause a denial of service (master-station daemon crash) via a malformed DNP3 TCP packet from the IP address of an outstation.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу