Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hwc-4pxw-w633

больше 4 лет назад

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.

EPSS: Низкий
github логотип

GHSA-3hw8-vgvf-843g

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Intro.JS allows Reflected XSS. This issue affects WP Intro.JS: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hw8-h4fg-g6wr

больше 4 лет назад

An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.

EPSS: Низкий
github логотип

GHSA-3hw8-52j6-h699

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Peake Responsive Flickr Slideshow allows Stored XSS.This issue affects Responsive Flickr Slideshow: from n/a through 2.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hw7-qj9h-r835

больше 1 года назад

Gardener allows bypassing project secret validation which can lead to privilege escalation

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3hw7-239v-hfv6

около 1 года назад

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hw6-vmjp-6cj5

4 месяца назад

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hw6-gc8h-9243

больше 4 лет назад

Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3hw6-fxjg-9c93

5 месяцев назад

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hw5-q855-g6cw

больше 6 лет назад

Prototype Pollution in Dojox

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3hw5-m8jj-m9vv

около 4 лет назад

Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3hw5-fffc-qrg4

больше 4 лет назад

phpMyAdmin Denial of Service (DoS)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3hw4-pvhh-9qcq

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer() commit 6f755e85c332 ("coresight: Add helper for inserting synchronization packets") removed trailing '\0' from barrier_pkt array and updated the call sites like etb_update_buffer() to have proper checks for barrier_pkt size before read but missed updating tmc_update_etf_buffer() which still reads barrier_pkt past the array size resulting in KASAN out-of-bounds bug. Fix this by adding a check for barrier_pkt size before accessing like it is done in etb_update_buffer(). BUG: KASAN: global-out-of-bounds in tmc_update_etf_buffer+0x4b8/0x698 Read of size 4 at addr ffffffd05b7d1030 by task perf/2629 Call trace: dump_backtrace+0x0/0x27c show_stack+0x20/0x2c dump_stack+0x11c/0x188 print_address_description+0x3c/0x4a4 __kasan_report+0x140/0x164 kasan_report+0x10/0x18 __asan_report_load4_noabort+0x1c/0x24 tmc_update_etf_buffer+0x4b8...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hw4-hh3h-jx7q

больше 4 лет назад

libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hw3-mqwc-2cjg

больше 4 лет назад

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.

EPSS: Высокий
github логотип

GHSA-3hw3-mqq8-mf6r

5 месяцев назад

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.63.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hw3-mqpp-fqg6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.

EPSS: Низкий
github логотип

GHSA-3hw3-cr75-52m9

больше 4 лет назад

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

EPSS: Низкий
github логотип

GHSA-3hw3-6562-638v

больше 2 лет назад

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263310 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hw2-h67c-wq66

больше 4 лет назад

Uncontrolled Recursion in Akka HTTP

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hwc-4pxw-w633

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw8-vgvf-843g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Intro.JS allows Reflected XSS. This issue affects WP Intro.JS: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hw8-h4fg-g6wr

An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw8-52j6-h699

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Peake Responsive Flickr Slideshow allows Stored XSS.This issue affects Responsive Flickr Slideshow: from n/a through 2.6.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hw7-qj9h-r835

Gardener allows bypassing project secret validation which can lead to privilege escalation

CVSS3: 9.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-3hw7-239v-hfv6

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3hw6-vmjp-6cj5

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-3hw6-gc8h-9243

Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key

CVSS3: 3.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw6-fxjg-9c93

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 8.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-3hw5-q855-g6cw

Prototype Pollution in Dojox

CVSS3: 7.7
2%
Низкий
больше 6 лет назад
github логотип
GHSA-3hw5-m8jj-m9vv

Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-3hw5-fffc-qrg4

phpMyAdmin Denial of Service (DoS)

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw4-pvhh-9qcq

In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer() commit 6f755e85c332 ("coresight: Add helper for inserting synchronization packets") removed trailing '\0' from barrier_pkt array and updated the call sites like etb_update_buffer() to have proper checks for barrier_pkt size before read but missed updating tmc_update_etf_buffer() which still reads barrier_pkt past the array size resulting in KASAN out-of-bounds bug. Fix this by adding a check for barrier_pkt size before accessing like it is done in etb_update_buffer(). BUG: KASAN: global-out-of-bounds in tmc_update_etf_buffer+0x4b8/0x698 Read of size 4 at addr ffffffd05b7d1030 by task perf/2629 Call trace: dump_backtrace+0x0/0x27c show_stack+0x20/0x2c dump_stack+0x11c/0x188 print_address_description+0x3c/0x4a4 __kasan_report+0x140/0x164 kasan_report+0x10/0x18 __asan_report_load4_noabort+0x1c/0x24 tmc_update_etf_buffer+0x4b8...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hw4-hh3h-jx7q

libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.

CVSS3: 4.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw3-mqwc-2cjg

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.

74%
Высокий
больше 4 лет назад
github логотип
GHSA-3hw3-mqq8-mf6r

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.63.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3hw3-mqpp-fqg6

Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw3-cr75-52m9

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3hw3-6562-638v

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263310 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hw2-h67c-wq66

Uncontrolled Recursion in Akka HTTP

CVSS3: 7.5
36%
Средний
больше 4 лет назад

Уязвимостей на страницу