Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35jw-3v94-g7gf

около 4 лет назад

Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Windows PDF Library handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8728.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-35jv-74f7-vj2m

больше 4 лет назад

In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619337.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35jv-46p3-x4g4

около 1 месяца назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set ...

EPSS: Низкий
github логотип

GHSA-35jr-5458-r65r

7 месяцев назад

IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35jr-36cj-2w6g

больше 4 лет назад

Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35jq-jf9g-9jg7

больше 1 года назад

Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-35jp-ww65-95wh

3 месяца назад

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-35jp-8cgg-p4wj

около 2 лет назад

Shopware vulnerable to Server Side Template Injection in Twig using Context functions

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-35jp-44cx-hw36

больше 4 лет назад

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35jm-rm2f-hpgj

около 21 часа назад

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-35jm-qwg4-c8wj

около 1 года назад

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35jj-wx47-4w8r

больше 2 лет назад

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-35jj-vqcf-f2jf

больше 3 лет назад

Hidden fields can be leaked on readable collections in Payload

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-35jj-h5xp-mhvc

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35jj-9635-2vjm

около 4 лет назад

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

EPSS: Низкий
github логотип

GHSA-35jh-r3h4-6jhm

больше 5 лет назад

Command Injection in lodash

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-35jh-p5wf-6gg4

больше 4 лет назад

Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

EPSS: Низкий
github логотип

GHSA-35jh-g8qg-jgf5

больше 4 лет назад

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

EPSS: Низкий
github логотип

GHSA-35jh-78c5-6rfj

около 4 лет назад

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35jh-65jp-wj73

около 4 лет назад

Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35jw-3v94-g7gf

Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Windows PDF Library handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8728.

CVSS3: 7.5
22%
Средний
около 4 лет назад
github логотип
GHSA-35jv-74f7-vj2m

In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619337.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35jv-46p3-x4g4

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set ...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-35jr-5458-r65r

IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-35jr-36cj-2w6g

Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35jq-jf9g-9jg7

Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

CVSS3: 8.7
1%
Низкий
3 месяца назад
github логотип
GHSA-35jp-8cgg-p4wj

Shopware vulnerable to Server Side Template Injection in Twig using Context functions

CVSS3: 8.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-35jp-44cx-hw36

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35jm-rm2f-hpgj

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.

CVSS3: 7.7
около 21 часа назад
github логотип
GHSA-35jm-qwg4-c8wj

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-35jj-wx47-4w8r

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

CVSS3: 7.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35jj-vqcf-f2jf

Hidden fields can be leaked on readable collections in Payload

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35jj-h5xp-mhvc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-35jj-9635-2vjm

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

6%
Низкий
около 4 лет назад
github логотип
GHSA-35jh-r3h4-6jhm

Command Injection in lodash

CVSS3: 7.2
21%
Средний
больше 5 лет назад
github логотип
GHSA-35jh-p5wf-6gg4

Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35jh-g8qg-jgf5

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-35jh-78c5-6rfj

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-35jh-65jp-wj73

Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

CVSS3: 9.8
4%
Низкий
около 4 лет назад

Уязвимостей на страницу