Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hp3-2w64-w6h6

7 месяцев назад

NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hp3-228q-23gq

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3hp2-jg96-579w

почти 2 года назад

Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23530.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hp2-fjxj-6wj4

4 месяца назад

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3hmx-xfr5-8hq6

6 месяцев назад

The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute of the 'sb_ravelry_designs' shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3hmx-7w48-9wcc

почти 3 года назад

User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hmx-5jq6-252x

больше 4 лет назад

The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.

EPSS: Низкий
github логотип

GHSA-3hmw-h9hw-mx39

9 месяцев назад

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hmw-9rrw-4ppp

больше 4 лет назад

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516.

EPSS: Низкий
github логотип

GHSA-3hmw-8mw3-rmpj

7 месяцев назад

NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter

EPSS: Низкий
github логотип

GHSA-3hmv-xgq6-6pp3

3 месяца назад

Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hmv-gr4c-qpjc

больше 4 лет назад

Russcom PHPImages allows remote attackers to upload files of arbitrary types by uploading a file with a .gif extension. NOTE: due to lack of specific information about attack vectors do not depend on the existence of another vulnerability, it is not clear whether this is a vulnerability.

EPSS: Низкий
github логотип

GHSA-3hmr-jrgj-vchc

больше 4 лет назад

Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.

EPSS: Низкий
github логотип

GHSA-3hmr-hpmw-7p9r

больше 4 лет назад

The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hmr-crcq-hxcv

5 месяцев назад

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3hmr-948v-5qgq

больше 4 лет назад

Moodle Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hmq-wx9v-vfjw

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.

EPSS: Низкий
github логотип

GHSA-3hmq-m636-vcvh

больше 4 лет назад

In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

EPSS: Низкий
github логотип

GHSA-3hmq-7955-4976

больше 4 лет назад

IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3hmq-7764-wgw3

3 месяца назад

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hp3-2w64-w6h6

NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.

CVSS3: 7.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-3hp3-228q-23gq

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-3hp2-jg96-579w

Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23530.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hp2-fjxj-6wj4

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
4 месяца назад
github логотип
GHSA-3hmx-xfr5-8hq6

The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute of the 'sb_ravelry_designs' shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hmx-7w48-9wcc

User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3hmx-5jq6-252x

The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmw-h9hw-mx39

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.

CVSS3: 7.2
1%
Низкий
9 месяцев назад
github логотип
GHSA-3hmw-9rrw-4ppp

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmw-8mw3-rmpj

NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter

0%
Низкий
7 месяцев назад
github логотип
GHSA-3hmv-xgq6-6pp3

Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3hmv-gr4c-qpjc

Russcom PHPImages allows remote attackers to upload files of arbitrary types by uploading a file with a .gif extension. NOTE: due to lack of specific information about attack vectors do not depend on the existence of another vulnerability, it is not clear whether this is a vulnerability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmr-jrgj-vchc

Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmr-hpmw-7p9r

The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmr-crcq-hxcv

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

CVSS3: 7.3
1%
Низкий
5 месяцев назад
github логотип
GHSA-3hmr-948v-5qgq

Moodle Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmq-wx9v-vfjw

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmq-m636-vcvh

In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmq-7955-4976

IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmq-7764-wgw3

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу