Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2rhx-8hc8-f268

больше 3 лет назад

profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

EPSS: Низкий
github логотип

GHSA-2rhx-838f-x5jw

больше 1 года назад

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2rhw-5pj3-hhx2

больше 3 лет назад

SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2rhv-qrh4-ppvg

больше 3 лет назад

Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2rhr-9v3p-vv9j

почти 2 года назад

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2rhr-5rr8-pf6q

больше 3 лет назад

An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. An attacker with physical access to the UART interface could access additional diagnostic and configuration functionalities as well as the camera's bootloader. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system. It could even render the device inoperable.

EPSS: Низкий
github логотип

GHSA-2rhr-29cm-5chf

почти 2 года назад

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rhq-96q8-4vjq

7 месяцев назад

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rhp-j953-ghxr

11 месяцев назад

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Iframe OVE-20230524-0012.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhp-94gv-g4xm

больше 3 лет назад

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhm-rw5w-h5p8

больше 3 лет назад

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

EPSS: Низкий
github логотип

GHSA-2rhm-r3jf-ph2q

7 месяцев назад

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2rhm-fq9f-r29w

около 2 лет назад

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rhh-j8hg-6qg4

6 месяцев назад

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhh-63xh-7gv7

больше 1 года назад

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2rhg-qq9v-fjp8

больше 3 лет назад

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhg-hqq9-8xjh

больше 2 лет назад

TeamPass information exposure vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rhg-4865-8qfj

больше 1 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2rhf-mvhm-8hfp

около 3 лет назад

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rhc-gc9x-8vvf

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through 1.0.2.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rhx-8hc8-f268

profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhx-838f-x5jw

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhw-5pj3-hhx2

SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhv-qrh4-ppvg

Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730.

CVSS3: 6.5
18%
Средний
больше 3 лет назад
github логотип
GHSA-2rhr-9v3p-vv9j

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rhr-5rr8-pf6q

An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. An attacker with physical access to the UART interface could access additional diagnostic and configuration functionalities as well as the camera's bootloader. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system. It could even render the device inoperable.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhr-29cm-5chf

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rhq-96q8-4vjq

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2rhp-j953-ghxr

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Iframe OVE-20230524-0012.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2rhp-94gv-g4xm

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhm-rw5w-h5p8

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhm-r3jf-ph2q

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2rhm-fq9f-r29w

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rhh-j8hg-6qg4

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2rhh-63xh-7gv7

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhg-qq9v-fjp8

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhg-hqq9-8xjh

TeamPass information exposure vulnerability

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rhg-4865-8qfj

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhf-mvhm-8hfp

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2rhc-gc9x-8vvf

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through 1.0.2.

CVSS3: 7.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу