Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 328

Количество 362 328

github логотип

GHSA-3h54-6g9g-h4w7

больше 1 года назад

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-3h53-wqpp-2rw8

10 месяцев назад

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3h53-6977-c549

больше 4 лет назад

Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11832.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h52-vv68-p6m9

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3h52-r54r-fvgf

7 месяцев назад

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h52-fhpg-8fqw

около 4 лет назад

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.

EPSS: Низкий
github логотип

GHSA-3h52-cx59-c456

5 месяцев назад

OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

EPSS: Низкий
github логотип

GHSA-3h52-6v6j-6wwv

3 месяца назад

TYPO3 SQL Injection in extension "Address List" (tt_address)

EPSS: Низкий
github логотип

GHSA-3h52-269p-cp9r

около 1 года назад

Information exposure in Next.js dev server due to lack of origin verification

EPSS: Низкий
github логотип

GHSA-3h4x-jrvr-p38w

около 4 лет назад

An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

EPSS: Низкий
github логотип

GHSA-3h4w-ppp7-mr7f

2 месяца назад

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4v-p542-7xmc

больше 1 года назад

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3h4v-m4g6-c2v8

около 4 лет назад

Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h4v-5rmg-5m36

около 1 года назад

A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 1f30edac27f69f61cff50162e980fe58fdeb30ca. It is recommended to upgrade the affected component.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3h4r-x85w-hcrm

больше 4 лет назад

A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.

EPSS: Низкий
github логотип

GHSA-3h4r-pjv6-cph9

около 7 лет назад

RubyGems Escape sequence injection vulnerability in api response handling

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h4r-h95r-47jc

больше 4 лет назад

Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.

EPSS: Низкий
github логотип

GHSA-3h4r-2q6q-wfr8

около 2 лет назад

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3h4q-7386-ff6m

около 4 лет назад

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

EPSS: Низкий
github логотип

GHSA-3h4p-v99m-68x5

больше 4 лет назад

SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h54-6g9g-h4w7

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

больше 1 года назад
github логотип
GHSA-3h53-wqpp-2rw8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS3: 7.1
1%
Низкий
10 месяцев назад
github логотип
GHSA-3h53-6977-c549

Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11832.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h52-vv68-p6m9

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-3h52-r54r-fvgf

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-3h52-fhpg-8fqw

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h52-cx59-c456

OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

0%
Низкий
5 месяцев назад
github логотип
GHSA-3h52-6v6j-6wwv

TYPO3 SQL Injection in extension "Address List" (tt_address)

0%
Низкий
3 месяца назад
github логотип
GHSA-3h52-269p-cp9r

Information exposure in Next.js dev server due to lack of origin verification

0%
Низкий
около 1 года назад
github логотип
GHSA-3h4x-jrvr-p38w

An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h4w-ppp7-mr7f

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3h4v-p542-7xmc

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h4v-m4g6-c2v8

Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h4v-5rmg-5m36

A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 1f30edac27f69f61cff50162e980fe58fdeb30ca. It is recommended to upgrade the affected component.

CVSS3: 5.3
1%
Низкий
около 1 года назад
github логотип
GHSA-3h4r-x85w-hcrm

A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3h4r-pjv6-cph9

RubyGems Escape sequence injection vulnerability in api response handling

CVSS3: 7.5
3%
Низкий
около 7 лет назад
github логотип
GHSA-3h4r-h95r-47jc

Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3h4r-2q6q-wfr8

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h4q-7386-ff6m

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h4p-v99m-68x5

SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу