Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 342 247

Количество 342 247

github логотип

GHSA-2gwf-h3h6-j5rq

больше 4 лет назад

PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter.

EPSS: Низкий
github логотип

GHSA-2gwf-8wvr-vhx8

больше 3 лет назад

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gwc-rv3v-q9qp

больше 4 лет назад

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.

EPSS: Низкий
github логотип

GHSA-2gwc-3c7p-cjfq

около 3 лет назад

Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2gw9-xrfp-7749

больше 4 лет назад

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

EPSS: Высокий
github логотип

GHSA-2gw9-pm3q-q2fq

больше 4 лет назад

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."

EPSS: Средний
github логотип

GHSA-2gw9-fcg7-wj2g

больше 4 лет назад

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

EPSS: Низкий
github логотип

GHSA-2gw9-c2r2-f5qf

4 месяца назад

Neko has a Self-service Privilege Escalation for Authenticated Users

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gw8-x645-qvjj

9 месяцев назад

Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gw8-rmq5-c5gv

больше 4 лет назад

Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2gw8-m96h-qw78

больше 4 лет назад

Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-2gw8-8q9v-75m8

больше 2 лет назад

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2gw7-672m-m38x

больше 4 лет назад

The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gw6-v2h7-g6vm

больше 4 лет назад

A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

EPSS: Низкий
github логотип

GHSA-2gw6-73wc-x88f

больше 4 лет назад

Apache Geode information disclosure vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gw5-9px7-vp56

почти 3 года назад

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2gw3-mxrj-jwhh

больше 4 лет назад

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gw2-qgjg-xh6p

больше 1 года назад

Namada-apps allows Post-Genesis Validator Bypass

EPSS: Низкий
github логотип

GHSA-2gw2-8q9w-cw8p

почти 8 лет назад

Ruby-ffi has a DLL loading issue

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gvx-rx63-w97c

больше 4 лет назад

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gwf-h3h6-j5rq

PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2gwf-8wvr-vhx8

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gwc-rv3v-q9qp

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2gwc-3c7p-cjfq

Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22.

CVSS3: 6.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2gw9-xrfp-7749

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

88%
Высокий
больше 4 лет назад
github логотип
GHSA-2gw9-pm3q-q2fq

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."

30%
Средний
больше 4 лет назад
github логотип
GHSA-2gw9-fcg7-wj2g

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw9-c2r2-f5qf

Neko has a Self-service Privilege Escalation for Authenticated Users

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2gw8-x645-qvjj

Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-2gw8-rmq5-c5gv

Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

CVSS3: 4.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw8-m96h-qw78

Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw8-8q9v-75m8

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2gw7-672m-m38x

The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw6-v2h7-g6vm

A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw6-73wc-x88f

Apache Geode information disclosure vulnerability

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw5-9px7-vp56

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS3: 7.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-2gw3-mxrj-jwhh

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2gw2-qgjg-xh6p

Namada-apps allows Post-Genesis Validator Bypass

больше 1 года назад
github логотип
GHSA-2gw2-8q9w-cw8p

Ruby-ffi has a DLL loading issue

CVSS3: 7.8
1%
Низкий
почти 8 лет назад
github логотип
GHSA-2gvx-rx63-w97c

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу