Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pmv-mf66-4v3h

около 2 месяцев назад

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.

EPSS: Низкий
github логотип

GHSA-4pmv-jg56-hh93

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Envato Template Kit – Export allows Stored XSS.This issue affects Template Kit – Export: from n/a through 1.0.22.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4pmv-cr3m-c6qv

больше 4 лет назад

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pmv-5pj5-58xg

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kolja Nolte Flexible Blogtitle allows Reflected XSS. This issue affects Flexible Blogtitle: from n/a through 0.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4pmr-jmj5-4gwv

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4pmr-98gg-9wvp

больше 4 лет назад

IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4pmr-4q2r-c836

почти 2 года назад

Missing Authorization vulnerability in mg12 WP-RecentComments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-RecentComments: from n/a through 2.2.7.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4pmq-77vh-vh7v

больше 4 лет назад

A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pmq-325h-rx32

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Free rwi on reset success Free the rwi structure in the event that the last rwi in the list processed successfully. The logic in commit 4f408e1fa6e1 ("ibmvnic: retry reset if there are no other resets") introduces an issue that results in a 32 byte memory leak whenever the last rwi in the list gets processed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pmp-cjqc-whw3

около 4 лет назад

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4pmp-8rgh-2hrv

больше 4 лет назад

Denial of service in talk program allows remote attackers to disrupt a user's display.

EPSS: Низкий
github логотип

GHSA-4pmp-38hf-rmwj

больше 4 лет назад

OpenStack Neutron allows remote authenticated users to cause a denial of service

EPSS: Низкий
github логотип

GHSA-4pmm-c3gr-wwj8

около 4 лет назад

Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4pmm-77fx-g9g6

больше 4 лет назад

Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4pmm-4ff4-v6hc

3 месяца назад

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pmm-428p-r3fp

больше 4 лет назад

gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4pmj-rrfm-63h4

больше 4 лет назад

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4pmj-qpm8-x7gv

больше 1 года назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pmj-f9rj-vppc

больше 1 года назад

A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000 Beryl AX, GL-MT6000 Flint 2, GL-SFT1200 Opal, GL-X300B Collie, GL-X750 Spitz, GL-X3000 Spitz AX, GL-XE300 Puli and GL-XE3000 Puli AX 4.x. Affected is an unknown function of the file plugins.so of the component RPC Handler. The manipulation leads to buffer overflow. It is recommended to upgrade the affected component.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4pmh-h6pj-3wh3

около 1 месяца назад

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pmv-mf66-4v3h

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application. Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4pmv-jg56-hh93

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Envato Template Kit – Export allows Stored XSS.This issue affects Template Kit – Export: from n/a through 1.0.22.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-4pmv-cr3m-c6qv

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmv-5pj5-58xg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kolja Nolte Flexible Blogtitle allows Reflected XSS. This issue affects Flexible Blogtitle: from n/a through 0.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4pmr-jmj5-4gwv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-4pmr-98gg-9wvp

IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmr-4q2r-c836

Missing Authorization vulnerability in mg12 WP-RecentComments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-RecentComments: from n/a through 2.2.7.

CVSS3: 5.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-4pmq-77vh-vh7v

A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmq-325h-rx32

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Free rwi on reset success Free the rwi structure in the event that the last rwi in the list processed successfully. The logic in commit 4f408e1fa6e1 ("ibmvnic: retry reset if there are no other resets") introduces an issue that results in a 32 byte memory leak whenever the last rwi in the list gets processed.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4pmp-cjqc-whw3

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-4pmp-8rgh-2hrv

Denial of service in talk program allows remote attackers to disrupt a user's display.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmp-38hf-rmwj

OpenStack Neutron allows remote authenticated users to cause a denial of service

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmm-c3gr-wwj8

Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulnerability, leading to information disclosure.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-4pmm-77fx-g9g6

Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmm-4ff4-v6hc

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4pmm-428p-r3fp

gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmj-rrfm-63h4

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmj-qpm8-x7gv

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4pmj-f9rj-vppc

A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000 Beryl AX, GL-MT6000 Flint 2, GL-SFT1200 Opal, GL-X300B Collie, GL-X750 Spitz, GL-X3000 Spitz AX, GL-XE300 Puli and GL-XE3000 Puli AX 4.x. Affected is an unknown function of the file plugins.so of the component RPC Handler. The manipulation leads to buffer overflow. It is recommended to upgrade the affected component.

CVSS3: 8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4pmh-h6pj-3wh3

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу