Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g7j-2h92-xxp4

больше 4 лет назад

Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

EPSS: Низкий
github логотип

GHSA-4g7h-rf8x-fpv7

больше 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g7h-ghm5-8qmm

больше 4 лет назад

LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g7h-2qwj-w6hw

9 месяцев назад

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-4g7h-2356-gxxf

больше 2 лет назад

The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in class-sbmm-list-table.php. This makes it possible for unauthenticated attackers to bulk delete messages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4g7g-hm6x-hp5r

больше 4 лет назад

Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.

EPSS: Низкий
github логотип

GHSA-4g7f-972r-hmcv

больше 2 лет назад

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4g7f-7g83-8g6g

около 2 лет назад

The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, including comments containing cross-site scripting as detailed in CVE-2023-1602, granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4g7c-wgc5-7vr9

почти 2 года назад

Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4g7c-qjqw-rvrq

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g7c-75vj-hqfj

больше 3 лет назад

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4g79-wxj6-3p5w

около 1 месяца назад

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4g79-g5hq-5j9f

около 2 месяцев назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4g79-99f9-qx3x

больше 4 лет назад

Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Files method. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4g79-8pmr-hjx2

больше 4 лет назад

Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."

EPSS: Низкий
github логотип

GHSA-4g78-w5pc-hhq5

больше 4 лет назад

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4g78-vc7q-c4j6

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Add checks for devm_kcalloc As the devm_kcalloc may return NULL, the return value needs to be checked to avoid NULL poineter dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4g78-j29g-3rrf

11 месяцев назад

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4g77-whxw-4h2h

около 1 года назад

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g77-cvgw-grvw

больше 4 лет назад

Prototype Pollution in putil-merge

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g7j-2h92-xxp4

Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7h-rf8x-fpv7

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4g7h-ghm5-8qmm

LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7h-2qwj-w6hw

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

CVSS3: 4.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-4g7h-2356-gxxf

The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in class-sbmm-list-table.php. This makes it possible for unauthenticated attackers to bulk delete messages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g7g-hm6x-hp5r

Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7f-972r-hmcv

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g7f-7g83-8g6g

The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, including comments containing cross-site scripting as detailed in CVE-2023-1602, granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-4g7c-wgc5-7vr9

Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4g7c-qjqw-rvrq

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4g7c-75vj-hqfj

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4g79-wxj6-3p5w

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4g79-g5hq-5j9f

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4g79-99f9-qx3x

Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Files method. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g79-8pmr-hjx2

Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g78-w5pc-hhq5

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 9.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g78-vc7q-c4j6

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Add checks for devm_kcalloc As the devm_kcalloc may return NULL, the return value needs to be checked to avoid NULL poineter dereference.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4g78-j29g-3rrf

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-4g77-whxw-4h2h

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-4g77-cvgw-grvw

Prototype Pollution in putil-merge

CVSS3: 8.2
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу