Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52v9-p5f4-vfvm

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

EPSS: Низкий
github логотип

GHSA-52v8-fjqp-h7pm

больше 4 лет назад

Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-52v7-3m2m-4m4v

около 1 месяца назад

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-52v6-wpr7-xp26

больше 4 лет назад

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-52v6-f4mm-ccqx

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-52v5-jr5w-gjxr

3 месяца назад

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52v5-4c5v-67f2

больше 4 лет назад

Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lead to use after free issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MDM9607, MDM9640, MSM8909W, MSM8917, MSM8953, Nicobar, QCS605, QM215, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130

EPSS: Низкий
github логотип

GHSA-52v4-wxrx-gjjm

около 4 лет назад

Jenkins Apprenda Plugin has Missing Authorization vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-52v4-p4vv-8fxm

больше 4 лет назад

Multiple unspecified vulnerabilities in Local Media Browser before 0.1 have unknown impact and attack vectors related to "Security holes."

EPSS: Низкий
github логотип

GHSA-52v3-pgpf-rp65

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bernd Altmeier Google Maps GPX Viewer allows Reflected XSS. This issue affects Google Maps GPX Viewer: from n/a through 3.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-52v3-p44c-8m9p

10 месяцев назад

Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact + WooCommerce: from n/a through <= 2.4.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-52v3-7697-2rvx

около 1 года назад

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulnerability may lead to information disclosure, denial of service, and data tampering.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-52v2-8xvg-r55r

больше 4 лет назад

There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-52rx-xv44-hxmv

больше 4 лет назад

Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.

EPSS: Низкий
github логотип

GHSA-52rx-xq3x-2994

25 дней назад

Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID.

EPSS: Низкий
github логотип

GHSA-52rx-8x3w-4qr2

около 2 лет назад

A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52rw-wpq3-w67j

больше 4 лет назад

A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is due to the affected software not validating and calculating certain numerical values in IPv4 packets that are sent to an affected device. An attacker could exploit this vulnerability by sending malformed IPv4 traffic to an affected device. A successful exploit could allow the attacker to disrupt the flow of certain IPv4 traffic passing through an affected device, which could result in a DoS condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52rw-vfrw-g6pp

11 месяцев назад

A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-52rw-98p2-v2g3

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52rv-hwx6-25rg

больше 4 лет назад

Format string vulnerability in ui.c in Textbased MSN Client (TMSNC) before 0.2.5 allows attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors that cause format strings to be injected into the wprintw function.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52v9-p5f4-vfvm

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-52v8-fjqp-h7pm

Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52v7-3m2m-4m4v

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-52v6-wpr7-xp26

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-52v6-f4mm-ccqx

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-52v5-jr5w-gjxr

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-52v5-4c5v-67f2

Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lead to use after free issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MDM9607, MDM9640, MSM8909W, MSM8917, MSM8953, Nicobar, QCS605, QM215, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM8150, SM8250, SXR1130, SXR2130

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52v4-wxrx-gjjm

Jenkins Apprenda Plugin has Missing Authorization vulnerability

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-52v4-p4vv-8fxm

Multiple unspecified vulnerabilities in Local Media Browser before 0.1 have unknown impact and attack vectors related to "Security holes."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52v3-pgpf-rp65

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bernd Altmeier Google Maps GPX Viewer allows Reflected XSS. This issue affects Google Maps GPX Viewer: from n/a through 3.6.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-52v3-p44c-8m9p

Missing Authorization vulnerability in Constant Contact Constant Contact + WooCommerce constant-contact-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact + WooCommerce: from n/a through <= 2.4.1.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-52v3-7697-2rvx

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulnerability may lead to information disclosure, denial of service, and data tampering.

CVSS3: 7.6
1%
Низкий
около 1 года назад
github логотип
GHSA-52v2-8xvg-r55r

There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-52rx-xv44-hxmv

Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52rx-xq3x-2994

Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID.

25 дней назад
github логотип
GHSA-52rx-8x3w-4qr2

A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-52rw-wpq3-w67j

A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is due to the affected software not validating and calculating certain numerical values in IPv4 packets that are sent to an affected device. An attacker could exploit this vulnerability by sending malformed IPv4 traffic to an affected device. A successful exploit could allow the attacker to disrupt the flow of certain IPv4 traffic passing through an affected device, which could result in a DoS condition.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52rw-vfrw-g6pp

A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.

CVSS3: 3.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-52rw-98p2-v2g3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-52rv-hwx6-25rg

Format string vulnerability in ui.c in Textbased MSN Client (TMSNC) before 0.2.5 allows attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors that cause format strings to be injected into the wprintw function.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу