Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w49-cxr2-29fp

около 4 лет назад

The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w49-3hrr-cx3j

больше 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4w48-6p23-843q

3 месяца назад

Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access and undo_revoke_access actions without seller ownership validation. Attackers can modify the is_access_revoked status on arbitrary purchases to unauthorized revoke or restore buyer access to products they do not own.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w48-3xmg-2w3m

больше 4 лет назад

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4w46-w44m-3jq3

больше 5 лет назад

Parse Server stores password in plain text

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4w46-vcfx-xvfg

больше 4 лет назад

The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

EPSS: Низкий
github логотип

GHSA-4w46-qc42-6vpq

почти 2 года назад

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4w46-7mrq-64vx

больше 1 года назад

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4w45-xx62-4547

больше 4 лет назад

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

EPSS: Низкий
github логотип

GHSA-4w44-prwr-955f

больше 4 лет назад

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4w44-j4vc-r3rp

больше 1 года назад

A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit this vulnerability by intercepting the websocket request during file upload and replacing the file path with the path of the file they wish to read. The server then copies the file to the `private_upload` folder and provides the path to the copied file, which can be accessed via a GET request. This vulnerability can lead to the exposure of sensitive system files, potentially including credentials, configuration files, or sensitive user data.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w44-487m-rjmx

больше 2 лет назад

The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4w43-v393-px48

около 1 года назад

A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.

EPSS: Низкий
github логотип

GHSA-4w43-h2cj-3qvc

больше 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Kernel.

EPSS: Низкий
github логотип

GHSA-4w42-hx2p-m2jw

больше 2 лет назад

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4w42-h73x-mj6m

3 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4w3x-69m8-478c

2 месяца назад

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w3w-pf2j-j82f

больше 2 лет назад

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4w3w-2rp5-g8jm

15 дней назад

xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

EPSS: Низкий
github логотип

GHSA-4w3v-xg6m-mghp

больше 4 лет назад

Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w49-cxr2-29fp

The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-4w49-3hrr-cx3j

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w48-6p23-843q

Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access and undo_revoke_access actions without seller ownership validation. Attackers can modify the is_access_revoked status on arbitrary purchases to unauthorized revoke or restore buyer access to products they do not own.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4w48-3xmg-2w3m

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w46-w44m-3jq3

Parse Server stores password in plain text

CVSS3: 7.7
1%
Низкий
больше 5 лет назад
github логотип
GHSA-4w46-vcfx-xvfg

The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w46-qc42-6vpq

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-4w46-7mrq-64vx

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4w45-xx62-4547

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w44-prwr-955f

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w44-j4vc-r3rp

A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit this vulnerability by intercepting the websocket request during file upload and replacing the file path with the path of the file they wish to read. The server then copies the file to the `private_upload` folder and provides the path to the copied file, which can be accessed via a GET request. This vulnerability can lead to the exposure of sensitive system files, potentially including credentials, configuration files, or sensitive user data.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4w44-487m-rjmx

The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4w43-v393-px48

A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.

2%
Низкий
около 1 года назад
github логотип
GHSA-4w43-h2cj-3qvc

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Kernel.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w42-hx2p-m2jw

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4w42-h73x-mj6m

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.1
1%
Низкий
3 месяца назад
github логотип
GHSA-4w3x-69m8-478c

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4w3w-pf2j-j82f

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4w3w-2rp5-g8jm

xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

0%
Низкий
15 дней назад
github логотип
GHSA-4w3v-xg6m-mghp

Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.

19%
Средний
больше 4 лет назад

Уязвимостей на страницу