Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v2q-r7pp-6g8x

больше 4 лет назад

The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4v2q-hjx3-c4vr

больше 4 лет назад

Magento remote code execution vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v2m-wc8x-hcjv

9 месяцев назад

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4v2m-666w-ffm3

больше 2 лет назад

Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules). The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.   This issue affects Automation Runtime: from 14.0 before 14.93.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4v2j-rfvp-fcjg

7 месяцев назад

Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v2j-q3rr-8qmg

больше 4 лет назад

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Низкий
github логотип

GHSA-4v2j-gjc9-p494

больше 1 года назад

Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4v2g-g3j4-2gg5

12 месяцев назад

A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v2g-fxcq-4j44

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7091r: Allow users to configure device events AD7091R-5 devices are supported by the ad7091r-5 driver together with the ad7091r-base driver. Those drivers declared iio events for notifying user space when ADC readings fall bellow the thresholds of low limit registers or above the values set in high limit registers. However, to configure iio events and their thresholds, a set of callback functions must be implemented and those were not present until now. The consequence of trying to configure ad7091r-5 events without the proper callback functions was a null pointer dereference in the kernel because the pointers to the callback functions were not set. Implement event configuration callbacks allowing users to read/write event thresholds and enable/disable event generation. Since the event spec structs are generic to AD7091R devices, also move those from the ad7091r-5 driver the base driver so they can b...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v2g-76qr-8gvj

4 месяца назад

There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView project.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4v2f-5xhv-8ff4

больше 4 лет назад

In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.

EPSS: Низкий
github логотип

GHSA-4v2c-h5r2-9g7x

больше 1 года назад

The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4v2c-g2xc-47fv

больше 7 лет назад

Downloads Resources over HTTP in massif

EPSS: Низкий
github логотип

GHSA-4v29-x97x-vq7r

больше 4 лет назад

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-4v29-vc65-87m4

около 3 лет назад

Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v29-qmg8-wv42

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: protect locator_addr with the main mutex If the service locator server is restarted fast enough, the PDR can rewrite locator_addr fields concurrently. Protect them by placing modification of those fields under the main pdr->lock.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v29-63c9-ww7w

больше 3 лет назад

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v28-j6q3-5m4r

12 дней назад

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4v28-8jj3-x7g5

больше 4 лет назад

Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4v27-p5q9-2gvg

больше 4 лет назад

The Point Inside Shopping & Travel (aka com.pointinside.android.app) application 3.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v2q-r7pp-6g8x

The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4v2q-hjx3-c4vr

Magento remote code execution vulnerability

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v2m-wc8x-hcjv

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-4v2m-666w-ffm3

Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules). The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.   This issue affects Automation Runtime: from 14.0 before 14.93.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v2j-rfvp-fcjg

Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-4v2j-q3rr-8qmg

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4v2j-gjc9-p494

Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v2g-g3j4-2gg5

A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-4v2g-fxcq-4j44

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7091r: Allow users to configure device events AD7091R-5 devices are supported by the ad7091r-5 driver together with the ad7091r-base driver. Those drivers declared iio events for notifying user space when ADC readings fall bellow the thresholds of low limit registers or above the values set in high limit registers. However, to configure iio events and their thresholds, a set of callback functions must be implemented and those were not present until now. The consequence of trying to configure ad7091r-5 events without the proper callback functions was a null pointer dereference in the kernel because the pointers to the callback functions were not set. Implement event configuration callbacks allowing users to read/write event thresholds and enable/disable event generation. Since the event spec structs are generic to AD7091R devices, also move those from the ad7091r-5 driver the base driver so they can b...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v2g-76qr-8gvj

There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView project.

CVSS3: 9.8
4 месяца назад
github логотип
GHSA-4v2f-5xhv-8ff4

In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v2c-h5r2-9g7x

The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v2c-g2xc-47fv

Downloads Resources over HTTP in massif

2%
Низкий
больше 7 лет назад
github логотип
GHSA-4v29-x97x-vq7r

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v29-vc65-87m4

Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4v29-qmg8-wv42

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: protect locator_addr with the main mutex If the service locator server is restarted fast enough, the PDR can rewrite locator_addr fields concurrently. Protect them by placing modification of those fields under the main pdr->lock.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4v29-63c9-ww7w

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4v28-j6q3-5m4r

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

CVSS3: 7.7
0%
Низкий
12 дней назад
github логотип
GHSA-4v28-8jj3-x7g5

Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.

CVSS3: 7.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v27-p5q9-2gvg

The Point Inside Shopping & Travel (aka com.pointinside.android.app) application 3.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу