Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hh6-685p-ww7j

около 1 месяца назад

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hh5-x5h6-6vjx

около 4 лет назад

The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3hh5-r56f-p66v

10 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Local File Inclusion.This issue affects Xcare: from n/a through < 6.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3hh5-r29m-w2h9

больше 4 лет назад

Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3hh5-h95j-2cw7

около 4 лет назад

In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hh5-h59p-5j29

больше 4 лет назад

Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.

EPSS: Низкий
github логотип

GHSA-3hh4-vmx3-9xp9

около 4 лет назад

In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934919

EPSS: Низкий
github логотип

GHSA-3hh3-xxq8-cffj

больше 4 лет назад

Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hh3-wrj3-mf78

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.

EPSS: Низкий
github логотип

GHSA-3hh3-mqp9-6pgg

6 месяцев назад

The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hh3-m5g3-6j82

больше 4 лет назад

Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3hh3-hx7r-ggc2

5 месяцев назад

Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3hh2-42f8-hvgp

около 1 года назад

A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url.go. The manipulation of the argument r leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3hgx-g23w-rr36

около 1 месяца назад

Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hgx-68q9-pcf8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in view_search.asp in ClickTech Click Gallery allows remote attackers to inject arbitrary web script or HTML via the txtKeyWord parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3hgw-g59r-6g4w

больше 4 лет назад

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hgw-75v6-8742

около 1 года назад

An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hgw-3p93-22w3

больше 4 лет назад

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hgv-jr5j-cg9x

5 дней назад

Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover

EPSS: Низкий
github логотип

GHSA-3hgv-99j2-fhvj

около 1 года назад

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hh6-685p-ww7j

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hh5-x5h6-6vjx

The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-3hh5-r56f-p66v

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Local File Inclusion.This issue affects Xcare: from n/a through < 6.5.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3hh5-r29m-w2h9

Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh5-h95j-2cw7

In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker

CVSS3: 7.5
6%
Низкий
около 4 лет назад
github логотип
GHSA-3hh5-h59p-5j29

Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh4-vmx3-9xp9

In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934919

0%
Низкий
около 4 лет назад
github логотип
GHSA-3hh3-xxq8-cffj

Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php copy_folder_file call (in inc/class.ftpfolder.php) to move a .php file from the FTP folder into a web folder.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh3-wrj3-mf78

Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh3-mqp9-6pgg

The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hh3-m5g3-6j82

Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hh3-hx7r-ggc2

Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

CVSS3: 9.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-3hh2-42f8-hvgp

A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url.go. The manipulation of the argument r leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3hgx-g23w-rr36

Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hgx-68q9-pcf8

Cross-site scripting (XSS) vulnerability in view_search.asp in ClickTech Click Gallery allows remote attackers to inject arbitrary web script or HTML via the txtKeyWord parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgw-g59r-6g4w

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgw-75v6-8742

An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-3hgw-3p93-22w3

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hgv-jr5j-cg9x

Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover

0%
Низкий
5 дней назад
github логотип
GHSA-3hgv-99j2-fhvj

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

CVSS3: 6.7
0%
Низкий
около 1 года назад

Уязвимостей на страницу