Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 895

Количество 361 895

github логотип

GHSA-3g4h-56c8-j5ff

больше 4 лет назад

Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g4g-934h-pjq7

около 4 лет назад

The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.

EPSS: Низкий
github логотип

GHSA-3g4c-hjhr-73rj

около 2 лет назад

CometVisu Backend for openHAB has a sensitive information disclosure vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g4c-gh47-jwj2

больше 4 лет назад

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3g4c-8p3f-xp53

около 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior and 5.7.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-3g48-cr7g-6ph4

около 4 лет назад

A flaw was found in Infinispan version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a user authenticated to the local machine to perform all operations on the caches, including the creation, update, deletion, and shutdown of the entire server.

EPSS: Низкий
github логотип

GHSA-3g48-4h8r-fg8c

больше 4 лет назад

Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.

EPSS: Низкий
github логотип

GHSA-3g46-58rq-xqf3

около 4 лет назад

The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation, allowing MITM attackers to cause a denial of service.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3g45-m7q2-c5g9

больше 1 года назад

Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The specific flaw exists within the saveFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE. Was ZDI-CAN-22548.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g45-cx6m-2pfc

около 4 лет назад

The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other application is able to load any website/web content into the application's context, which is shown as a full-screen overlay to the user.

EPSS: Низкий
github логотип

GHSA-3g45-cr6q-gf5g

около 2 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3g44-f63g-r9p7

почти 3 года назад

H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3g44-c4qc-cxm8

2 месяца назад

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3g44-8pvw-94rh

больше 3 лет назад

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g43-xfrw-pv5m

больше 2 лет назад

eZ Platform User data disclosure

EPSS: Низкий
github логотип

GHSA-3g43-x7qr-96ph

больше 3 лет назад

Possible CSRF token fixation

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3g43-vm9r-34g5

больше 4 лет назад

On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may constitute an extended denial of service condition for the device(s). If the device is configured in high-availability, the RG1+ (data-plane) will fail-over to the secondary node. If the device is configured in stand-alone, there will be temporary traffic interruption until the flowd process is restored automatically. Sustained crafted packets may cause the secondary failover node to fail back, or fail completely, potentially halting flowd on both nodes of the cluster or causing flip-flop failovers to occur. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67 on vSRX or SRX Series; 12.3X48 prior to 12.3X48-D50 on vSRX or SRX Series; 1...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g43-r9pg-jrj9

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, key material is not always cleared properly.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g43-6gmg-66jw

3 месяца назад

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3g42-9rvj-6j9x

около 1 года назад

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g4h-56c8-j5ff

Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4g-934h-pjq7

The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3g4c-hjhr-73rj

CometVisu Backend for openHAB has a sensitive information disclosure vulnerability

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3g4c-gh47-jwj2

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g4c-8p3f-xp53

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior and 5.7.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-3g48-cr7g-6ph4

A flaw was found in Infinispan version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a user authenticated to the local machine to perform all operations on the caches, including the creation, update, deletion, and shutdown of the entire server.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3g48-4h8r-fg8c

Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3g46-58rq-xqf3

The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation, allowing MITM attackers to cause a denial of service.

CVSS3: 5.9
0%
Низкий
около 4 лет назад
github логотип
GHSA-3g45-m7q2-c5g9

Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The specific flaw exists within the saveFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE. Was ZDI-CAN-22548.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-3g45-cx6m-2pfc

The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other application is able to load any website/web content into the application's context, which is shown as a full-screen overlay to the user.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3g45-cr6q-gf5g

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-3g44-f63g-r9p7

H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.

CVSS3: 9.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-3g44-c4qc-cxm8

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CVSS3: 8.5
1%
Низкий
2 месяца назад
github логотип
GHSA-3g44-8pvw-94rh

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3g43-xfrw-pv5m

eZ Platform User data disclosure

больше 2 лет назад
github логотип
GHSA-3g43-x7qr-96ph

Possible CSRF token fixation

CVSS3: 5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g43-vm9r-34g5

On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may constitute an extended denial of service condition for the device(s). If the device is configured in high-availability, the RG1+ (data-plane) will fail-over to the secondary node. If the device is configured in stand-alone, there will be temporary traffic interruption until the flowd process is restored automatically. Sustained crafted packets may cause the secondary failover node to fail back, or fail completely, potentially halting flowd on both nodes of the cluster or causing flip-flop failovers to occur. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67 on vSRX or SRX Series; 12.3X48 prior to 12.3X48-D50 on vSRX or SRX Series; 1...

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3g43-r9pg-jrj9

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, key material is not always cleared properly.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

CVSS3: 7
1%
Низкий
3 месяца назад
github логотип
GHSA-3g42-9rvj-6j9x

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.

CVSS3: 8.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу