Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rhp-94gv-g4xm

больше 3 лет назад

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhm-rw5w-h5p8

больше 3 лет назад

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

EPSS: Низкий
github логотип

GHSA-2rhm-r3jf-ph2q

7 месяцев назад

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2rhm-fq9f-r29w

около 2 лет назад

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rhh-j8hg-6qg4

6 месяцев назад

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhh-63xh-7gv7

больше 1 года назад

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2rhg-qq9v-fjp8

больше 3 лет назад

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rhg-hqq9-8xjh

больше 2 лет назад

TeamPass information exposure vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rhg-4865-8qfj

больше 1 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2rhf-mvhm-8hfp

около 3 лет назад

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rhc-gc9x-8vvf

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through 1.0.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2rhc-f5j3-jr26

больше 3 лет назад

SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must use a Parameter Pollution approach against goform/formSetDiagnosticToolsFmPing by providing the vlu_diagnostic_tools__ping_address parameter twice: once with a shell metacharacter and a command name, and once with a command argument.

EPSS: Низкий
github логотип

GHSA-2rh9-r44r-2xv6

больше 2 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2rh9-mcg8-96mq

почти 4 года назад

Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.

EPSS: Средний
github логотип

GHSA-2rh9-h56r-vv84

почти 4 года назад

Directory traversal vulnerability in the session mechanism of the web interface for Network Administration Visualized (NAV) before 3.1.1 allows attackers with filesystem write access to have an unknown impact via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2rh8-cp97-xxp6

больше 3 лет назад

The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers to bypass intended access restrictions by leveraging a screen-sharing connection.

EPSS: Низкий
github логотип

GHSA-2rh7-xqm7-m994

2 месяца назад

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2rh7-qf6c-x6ww

около 1 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through 1.24.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rh7-mhq6-qpjv

почти 4 года назад

Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.

EPSS: Низкий
github логотип

GHSA-2rh7-fjx8-h7jp

около 3 лет назад

The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rhp-94gv-g4xm

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhm-rw5w-h5p8

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhm-r3jf-ph2q

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2rhm-fq9f-r29w

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rhh-j8hg-6qg4

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2rhh-63xh-7gv7

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhg-qq9v-fjp8

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhg-hqq9-8xjh

TeamPass information exposure vulnerability

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rhg-4865-8qfj

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhf-mvhm-8hfp

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2rhc-gc9x-8vvf

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through 1.0.2.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2rhc-f5j3-jr26

SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must use a Parameter Pollution approach against goform/formSetDiagnosticToolsFmPing by providing the vlu_diagnostic_tools__ping_address parameter twice: once with a shell metacharacter and a command name, and once with a command argument.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2rh9-r44r-2xv6

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rh9-mcg8-96mq

Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.

21%
Средний
почти 4 года назад
github логотип
GHSA-2rh9-h56r-vv84

Directory traversal vulnerability in the session mechanism of the web interface for Network Administration Visualized (NAV) before 3.1.1 allows attackers with filesystem write access to have an unknown impact via unknown attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rh8-cp97-xxp6

The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers to bypass intended access restrictions by leveraging a screen-sharing connection.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rh7-xqm7-m994

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
2 месяца назад
github логотип
GHSA-2rh7-qf6c-x6ww

Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through 1.24.1.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2rh7-mhq6-qpjv

Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rh7-fjx8-h7jp

The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection

CVSS3: 9.8
4%
Низкий
около 3 лет назад

Уязвимостей на страницу