Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-3vh5-vw4x-2894

больше 4 лет назад

A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vh5-r744-3j37

17 дней назад

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3vh5-qrqh-8pj5

больше 4 лет назад

The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3vh5-9778-57cq

около 4 лет назад

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vh5-5fv5-286r

больше 4 лет назад

Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

EPSS: Низкий
github логотип

GHSA-3vh3-xm22-984m

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webcreations907 WBC907 Core allows Stored XSS.This issue affects WBC907 Core: from n/a through 3.4.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vh3-mqwm-fjh6

больше 2 лет назад

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3vh3-h94g-wh9r

больше 4 лет назад

UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.

EPSS: Низкий
github логотип

GHSA-3vh2-xgxr-xw99

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.

EPSS: Низкий
github логотип

GHSA-3vh2-mmqw-p57m

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.

EPSS: Низкий
github логотип

GHSA-3vh2-7wc2-pg3v

больше 4 лет назад

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256.

EPSS: Низкий
github логотип

GHSA-3vgx-qgcc-j6g8

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.

EPSS: Низкий
github логотип

GHSA-3vgw-p3fg-cj52

больше 4 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while processing vsprintf in camera jpeg driver.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vgw-chq8-wqp9

больше 4 лет назад

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 180167.

EPSS: Низкий
github логотип

GHSA-3vgw-967p-w66j

больше 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vgw-93xw-5c6g

больше 1 года назад

A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vgw-585j-4m45

2 месяца назад

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3vgv-wch2-3cmp

больше 4 лет назад

The IMPI Mobile Security (aka com.impi) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3vgv-pgwc-8f57

больше 4 лет назад

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vgv-cg7r-qgvj

больше 4 лет назад

procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vh5-vw4x-2894

A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh5-r744-3j37

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

CVSS3: 7.1
0%
Низкий
17 дней назад
github логотип
GHSA-3vh5-qrqh-8pj5

The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh5-9778-57cq

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3vh5-5fv5-286r

Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh3-xm22-984m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webcreations907 WBC907 Core allows Stored XSS.This issue affects WBC907 Core: from n/a through 3.4.1.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3vh3-mqwm-fjh6

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

CVSS3: 2.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3vh3-h94g-wh9r

UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh2-xgxr-xw99

Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh2-mmqw-p57m

Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh2-7wc2-pg3v

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgx-qgcc-j6g8

Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgw-p3fg-cj52

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while processing vsprintf in camera jpeg driver.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgw-chq8-wqp9

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 180167.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgw-967p-w66j

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgw-93xw-5c6g

A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vgw-585j-4m45

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3vgv-wch2-3cmp

The IMPI Mobile Security (aka com.impi) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgv-pgwc-8f57

Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

CVSS3: 9.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3vgv-cg7r-qgvj

procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).

CVSS3: 7.5
9%
Низкий
больше 4 лет назад

Уязвимостей на страницу