Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2wmq-wq3w-j93h

2 месяца назад

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no permissions checks beyond being able to see the artifacts in question.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wmq-9w92-6xx4

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ravi Singh Visitor Details allows Stored XSS. This issue affects Visitor Details: from n/a through 1.0.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2wmq-3m94-g4jr

около 2 месяцев назад

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2wmp-7qf6-49px

почти 3 года назад

Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wmp-6cvh-326h

больше 2 лет назад

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wmm-vrhw-cf55

больше 4 лет назад

Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.

EPSS: Низкий
github логотип

GHSA-2wmm-f268-hrpm

почти 4 года назад

The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2wmm-cc27-75cj

почти 2 года назад

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2wmm-3686-65hx

около 4 лет назад

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wmj-8mqg-r9q8

больше 3 лет назад

Moodle has Incorrect Default Permissions

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wmj-46rj-qm2w

больше 2 лет назад

ZITADEL Account Takeover via Malicious Host Header Injection

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2wmh-hj9f-qxhx

около 1 месяца назад

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2wmh-359c-rw99

около 4 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.

EPSS: Низкий
github логотип

GHSA-2wmh-22pv-vc2h

около 4 лет назад

browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2wmg-wcpx-h559

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through 1.4.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2wmg-qmv3-pmvc

около 4 лет назад

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.

EPSS: Низкий
github логотип

GHSA-2wmg-q3rm-p93r

3 месяца назад

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wmg-pcgw-7mxw

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block – Display your videos as a gallery in a professional way allows Stored XSS. This issue affects Video Gallery Block – Display your videos as a gallery in a professional way: from n/a through 1.1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wmg-hcwc-fx57

около 4 лет назад

The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can result in administrative user with privilege restrictions logging in as a more powerful administrator. This attack appear to be exploitable via Use user administration privilege to set the password of a more powerful administrator. This vulnerability appears to have been fixed in 5.4.7.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2wmg-9g29-r2rp

около 4 лет назад

The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wmq-wq3w-j93h

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no permissions checks beyond being able to see the artifacts in question.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2wmq-9w92-6xx4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ravi Singh Visitor Details allows Stored XSS. This issue affects Visitor Details: from n/a through 1.0.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wmq-3m94-g4jr

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2wmp-7qf6-49px

Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2wmp-6cvh-326h

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2wmm-vrhw-cf55

Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wmm-f268-hrpm

The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2wmm-cc27-75cj

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.

CVSS3: 9.6
1%
Низкий
почти 2 года назад
github логотип
GHSA-2wmm-3686-65hx

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wmj-8mqg-r9q8

Moodle has Incorrect Default Permissions

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wmj-46rj-qm2w

ZITADEL Account Takeover via Malicious Host Header Injection

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2wmh-hj9f-qxhx

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

CVSS3: 8.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2wmh-359c-rw99

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2wmh-22pv-vc2h

browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2wmg-wcpx-h559

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through 1.4.8.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2wmg-qmv3-pmvc

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.

8%
Низкий
около 4 лет назад
github логотип
GHSA-2wmg-q3rm-p93r

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2wmg-pcgw-7mxw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block – Display your videos as a gallery in a professional way allows Stored XSS. This issue affects Video Gallery Block – Display your videos as a gallery in a professional way: from n/a through 1.1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2wmg-hcwc-fx57

The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can result in administrative user with privilege restrictions logging in as a more powerful administrator. This attack appear to be exploitable via Use user administration privilege to set the password of a more powerful administrator. This vulnerability appears to have been fixed in 5.4.7.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wmg-9g29-r2rp

The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу