Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4vvp-x9h2-x2vf

около 6 лет назад

Path Traversal in public

EPSS: Низкий
github логотип

GHSA-4vvp-mmqw-cp8p

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Visualware MyConnection Server 8.2b allow remote attackers to inject arbitrary web script or HTML via the (1) bt, (2) variable, or (3) et parameter to myspeed/db/historyitem.

EPSS: Низкий
github логотип

GHSA-4vvp-2h3v-73fw

14 дней назад

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or submit duplicate checkout requests to inflate the counter, misrepresenting pending demand in the admin queue.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4vvm-5cw4-4q22

почти 2 года назад

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4vvm-4w3v-6mr8

около 3 лет назад

pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4vvj-4cpr-p986

около 2 лет назад

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4vvh-qc7h-f4ch

4 месяца назад

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4vvh-93ff-2f2v

3 месяца назад

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4vvh-32p4-7wgp

больше 1 года назад

A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4vvg-x86p-mvqc

больше 4 лет назад

Leaking of user information on Cross-Domain communication in sysend

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vvg-jx6g-7m2m

около 4 лет назад

In gcc, an internal compiler error in match_reload function at lra-constraints.c may cause a crash through a crafted input file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4vvg-656r-c25j

больше 4 лет назад

Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vvg-48v9-mm83

больше 4 лет назад

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.

EPSS: Средний
github логотип

GHSA-4vvf-q5vq-fm6w

больше 1 года назад

NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4vvf-gm8q-cf8p

28 дней назад

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4vvf-498m-f8p7

11 месяцев назад

Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4vvc-r4p4-qgrr

почти 3 года назад

Apache DolphinScheduler sensitive information disclosure

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vvc-hp8x-p32m

больше 4 лет назад

Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS. A stack-based overflow is present in the handling of environment variables when connecting via the telnet client to remote telnet servers. This issue only affects the telnet client ? accessible from the CLI or shell ? in Junos OS. Inbound telnet services are not affected by this issue. This issue affects: Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S13; 12.3X48 versions prior to 12.3X48-D80; 14.1X53 versions prior to 14.1X53-D130, 14.1X53-D49; 15.1 versions prior to 15.1F6-S12, 15.1R7-S4; 15.1X49 versions prior to 15.1X49-D170; 15.1X53 versions prior to 15.1X53-D237, 15.1X53-D496, 15.1X53-D591, 15.1X53-D69; 16.1 versions prior to 16.1R3-S11, 16.1R7-S4; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R2-S7, 17.2R3-S1; ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4vvc-6vxf-vxg4

больше 4 лет назад

Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.

EPSS: Низкий
github логотип

GHSA-4vvc-4999-7hh6

12 месяцев назад

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vvp-x9h2-x2vf

Path Traversal in public

около 6 лет назад
github логотип
GHSA-4vvp-mmqw-cp8p

Multiple cross-site scripting (XSS) vulnerabilities in Visualware MyConnection Server 8.2b allow remote attackers to inject arbitrary web script or HTML via the (1) bt, (2) variable, or (3) et parameter to myspeed/db/historyitem.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvp-2h3v-73fw

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or submit duplicate checkout requests to inflate the counter, misrepresenting pending demand in the admin queue.

CVSS3: 4.3
0%
Низкий
14 дней назад
github логотип
GHSA-4vvm-5cw4-4q22

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-4vvm-4w3v-6mr8

pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character

CVSS3: 6.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-4vvj-4cpr-p986

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

CVSS3: 6.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-4vvh-qc7h-f4ch

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-4vvh-93ff-2f2v

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4vvh-32p4-7wgp

A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4vvg-x86p-mvqc

Leaking of user information on Cross-Domain communication in sysend

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvg-jx6g-7m2m

In gcc, an internal compiler error in match_reload function at lra-constraints.c may cause a crash through a crafted input file.

CVSS3: 5.5
около 4 лет назад
github логотип
GHSA-4vvg-656r-c25j

Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvg-48v9-mm83

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.

55%
Средний
больше 4 лет назад
github логотип
GHSA-4vvf-q5vq-fm6w

NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

CVSS3: 7.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-4vvf-gm8q-cf8p

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.

CVSS3: 7.8
0%
Низкий
28 дней назад
github логотип
GHSA-4vvf-498m-f8p7

Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-4vvc-r4p4-qgrr

Apache DolphinScheduler sensitive information disclosure

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4vvc-hp8x-p32m

Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS. A stack-based overflow is present in the handling of environment variables when connecting via the telnet client to remote telnet servers. This issue only affects the telnet client ? accessible from the CLI or shell ? in Junos OS. Inbound telnet services are not affected by this issue. This issue affects: Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S13; 12.3X48 versions prior to 12.3X48-D80; 14.1X53 versions prior to 14.1X53-D130, 14.1X53-D49; 15.1 versions prior to 15.1F6-S12, 15.1R7-S4; 15.1X49 versions prior to 15.1X49-D170; 15.1X53 versions prior to 15.1X53-D237, 15.1X53-D496, 15.1X53-D591, 15.1X53-D69; 16.1 versions prior to 16.1R3-S11, 16.1R7-S4; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R2-S7, 17.2R3-S1; ...

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvc-6vxf-vxg4

Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvc-4999-7hh6

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
8%
Низкий
12 месяцев назад

Уязвимостей на страницу