Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-3f92-q4c5-7ppr

больше 4 лет назад

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3f92-pgj5-j64j

около 4 лет назад

Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

EPSS: Низкий
github логотип

GHSA-3f92-cwf9-rgvq

почти 2 года назад

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f92-7xfr-mgpx

около 1 года назад

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f92-4q6m-m3rv

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3f8w-p3m8-mpjx

больше 4 лет назад

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f8v-r6fv-2xv4

около 4 лет назад

The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f8r-x482-8qpg

больше 2 лет назад

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3f8r-8g29-hh32

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.

EPSS: Низкий
github логотип

GHSA-3f8r-4qwm-r7jf

больше 5 лет назад

Improper Authentication in Apache Traffic Control

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f8r-37x3-r4g8

больше 4 лет назад

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption.

EPSS: Низкий
github логотип

GHSA-3f8q-6q6f-h89r

больше 4 лет назад

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f8p-g8f8-x3r3

больше 4 лет назад

NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.

EPSS: Низкий
github логотип

GHSA-3f8p-77gw-5f5c

больше 4 лет назад

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.

EPSS: Низкий
github логотип

GHSA-3f8p-349v-j5h8

13 дней назад

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator's browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3f8m-mr6h-cch4

больше 2 лет назад

A vulnerability, which was classified as critical, was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. This affects an unknown part of the file home.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3f8j-mm92-hxrr

6 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3f8j-hxpw-f275

около 2 лет назад

The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f8j-c578-3q4f

больше 4 лет назад

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f8j-8ww3-q7v6

больше 4 лет назад

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f92-q4c5-7ppr

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f92-pgj5-j64j

Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

0%
Низкий
около 4 лет назад
github логотип
GHSA-3f92-cwf9-rgvq

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3f92-7xfr-mgpx

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3f92-4q6m-m3rv

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-3f8w-p3m8-mpjx

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8v-r6fv-2xv4

The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3f8r-x482-8qpg

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

CVSS3: 3.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3f8r-8g29-hh32

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8r-4qwm-r7jf

Improper Authentication in Apache Traffic Control

CVSS3: 9.8
3%
Низкий
больше 5 лет назад
github логотип
GHSA-3f8r-37x3-r4g8

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8q-6q6f-h89r

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8p-g8f8-x3r3

NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8p-77gw-5f5c

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8p-349v-j5h8

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator's browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover.

CVSS3: 4.4
0%
Низкий
13 дней назад
github логотип
GHSA-3f8m-mr6h-cch4

A vulnerability, which was classified as critical, was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. This affects an unknown part of the file home.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3f8j-mm92-hxrr

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

6 месяцев назад
github логотип
GHSA-3f8j-hxpw-f275

The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3f8j-c578-3q4f

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8j-8ww3-q7v6

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS3: 9.8
13%
Средний
больше 4 лет назад

Уязвимостей на страницу