Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-27vh-h6mc-q6g8

больше 1 года назад

btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-27vh-g9xh-6mc8

больше 3 лет назад

In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts server-side connections and may result in a man-in-the-middle attack on the connections.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-27vh-g29g-4cf7

7 месяцев назад

The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27vg-xj68-r4p8

больше 3 лет назад

An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27vg-v28w-gqgh

больше 3 лет назад

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-27vg-qjpq-w479

больше 1 года назад

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-27vg-mg2m-7qv2

больше 3 лет назад

In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27vf-v322-7qf5

почти 4 года назад

Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-27vf-8fw5-36p7

больше 3 лет назад

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.

EPSS: Низкий
github логотип

GHSA-27vf-3g4f-6jp7

около 1 года назад

LibreNMS Ports Stored Cross-site Scripting vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-27vc-vrhq-mf4c

почти 4 года назад

SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.

EPSS: Низкий
github логотип

GHSA-27vc-rww5-64v8

больше 1 года назад

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27v9-jf76-68p4

больше 2 лет назад

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239260.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27v9-6wwc-82r3

больше 3 лет назад

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-27v9-58mg-8v43

больше 3 лет назад

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

EPSS: Низкий
github логотип

GHSA-27v7-qhfv-rqq8

больше 6 лет назад

Insecure Credential Storage in web3

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-27v6-gp7m-8rxj

4 месяца назад

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-27v6-gmmm-5qf3

почти 4 года назад

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

EPSS: Низкий
github логотип

GHSA-27v6-4m9p-3qq4

больше 3 лет назад

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-27v5-v9w4-6pr5

больше 3 лет назад

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27vh-h6mc-q6g8

btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-27vh-g9xh-6mc8

In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts server-side connections and may result in a man-in-the-middle attack on the connections.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vh-g29g-4cf7

The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-27vg-xj68-r4p8

An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vg-v28w-gqgh

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vg-qjpq-w479

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-27vg-mg2m-7qv2

In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vf-v322-7qf5

Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-27vf-8fw5-36p7

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vf-3g4f-6jp7

LibreNMS Ports Stored Cross-site Scripting vulnerability

CVSS3: 4.6
0%
Низкий
около 1 года назад
github логотип
GHSA-27vc-vrhq-mf4c

SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27vc-rww5-64v8

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-27v9-jf76-68p4

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239260.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27v9-6wwc-82r3

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v9-58mg-8v43

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v7-qhfv-rqq8

Insecure Credential Storage in web3

CVSS3: 3.3
больше 6 лет назад
github логотип
GHSA-27v6-gp7m-8rxj

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVSS3: 4
0%
Низкий
4 месяца назад
github логотип
GHSA-27v6-gmmm-5qf3

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

4%
Низкий
почти 4 года назад
github логотип
GHSA-27v6-4m9p-3qq4

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS3: 7.2
6%
Низкий
больше 3 лет назад
github логотип
GHSA-27v5-v9w4-6pr5

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу