Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-3v9m-736c-4x7x

больше 3 лет назад

In PVRSRVBridgeRGXKickTA3D of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-270396792

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v9m-2r3c-48wc

почти 3 года назад

The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3v9h-v2jm-73mm

около 2 лет назад

is_closing_session() allows users to fill up apport.log

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v9g-j2wr-qjhh

больше 4 лет назад

SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public.

EPSS: Низкий
github логотип

GHSA-3v9f-4vff-rx42

больше 4 лет назад

Jenkins Static Analysis Utilities Plugin is vulnerable to Cross-site request forgery vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3v9c-8rh8-vmj3

больше 4 лет назад

Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, QCS405, Rennell, Saipan, SC8180X, SDX55, SM8150, SM8250, SXR2130

EPSS: Низкий
github логотип

GHSA-3v99-rpgw-rrch

больше 4 лет назад

Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-service (DoS) or execute arbitrary code via unspecified vectors.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3v99-qgp9-2hp7

больше 4 лет назад

An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01c224 the value for the s_vol_play key is copied using strcpy to the buffer at 0xa0000418. This buffer is maximum 8 bytes large (this is the maximum size it could be, it is possible other global variables are stored between this variable and the next one that we could identify), sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3v99-jwxg-37h6

больше 4 лет назад

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3v99-hpv7-9hh9

больше 4 лет назад

Capstone Integer overflow

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v99-gw88-f2cw

около 2 месяцев назад

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v99-8xc4-9rvx

около 4 лет назад

A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v98-q7qw-m4cr

3 месяца назад

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3v98-74p6-c9g6

больше 4 лет назад

Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Performance Schema.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3v98-72qw-v7r9

больше 4 лет назад

XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v97-26cx-c3v7

около 1 года назад

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v95-qw2c-cq5p

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Post List allows Stored XSS.This issue affects Advanced Post List: from n/a through 0.5.6.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3v94-pmvx-x3wh

8 месяцев назад

A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3v94-mw7p-v465

4 месяца назад

hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses

EPSS: Низкий
github логотип

GHSA-3v94-cf5v-6c3j

больше 4 лет назад

sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v9m-736c-4x7x

In PVRSRVBridgeRGXKickTA3D of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-270396792

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v9m-2r3c-48wc

The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-3v9h-v2jm-73mm

is_closing_session() allows users to fill up apport.log

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3v9g-j2wr-qjhh

SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3v9f-4vff-rx42

Jenkins Static Analysis Utilities Plugin is vulnerable to Cross-site request forgery vulnerability

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v9c-8rh8-vmj3

Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, QCS405, Rennell, Saipan, SC8180X, SDX55, SM8150, SM8250, SXR2130

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v99-rpgw-rrch

Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-service (DoS) or execute arbitrary code via unspecified vectors.

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3v99-qgp9-2hp7

An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01c224 the value for the s_vol_play key is copied using strcpy to the buffer at 0xa0000418. This buffer is maximum 8 bytes large (this is the maximum size it could be, it is possible other global variables are stored between this variable and the next one that we could identify), sending anything longer will cause a buffer overflow.

CVSS3: 9.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v99-jwxg-37h6

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v99-hpv7-9hh9

Capstone Integer overflow

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v99-gw88-f2cw

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-3v99-8xc4-9rvx

A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVSS3: 7.5
7%
Низкий
около 4 лет назад
github логотип
GHSA-3v98-q7qw-m4cr

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

CVSS3: 5
0%
Низкий
3 месяца назад
github логотип
GHSA-3v98-74p6-c9g6

Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Performance Schema.

CVSS3: 4.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v98-72qw-v7r9

XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v97-26cx-c3v7

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-3v95-qw2c-cq5p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Post List allows Stored XSS.This issue affects Advanced Post List: from n/a through 0.5.6.1.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v94-pmvx-x3wh

A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 7.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-3v94-mw7p-v465

hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses

4 месяца назад
github логотип
GHSA-3v94-cf5v-6c3j

sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.

8%
Низкий
больше 4 лет назад

Уязвимостей на страницу