Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vfq-7gxj-92hg

почти 2 года назад

A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vfp-x8jm-58cj

около 4 лет назад

Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vfp-rfhc-3mm2

8 месяцев назад

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2vfp-cq97-7pq2

около 4 лет назад

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, and CVE-2014-2417.

EPSS: Низкий
github логотип

GHSA-2vfp-2qpf-jwrq

около 4 лет назад

A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vfm-wf45-cf66

около 4 лет назад

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

EPSS: Низкий
github логотип

GHSA-2vfm-v289-h559

24 дня назад

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2vfm-rw86-mwjv

больше 4 лет назад

David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vfm-65cj-5j48

больше 4 лет назад

Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2vfj-ww29-h4x2

больше 2 лет назад

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vfj-3h9f-v378

около 4 лет назад

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

EPSS: Низкий
github логотип

GHSA-2vfh-w2hp-mr2m

около 4 лет назад

eDeploy has RCE via cPickle deserialization of untrusted data

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vfh-6ppw-453g

около 2 лет назад

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2vfg-xrq7-ffvf

10 дней назад

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vfg-x9vh-wg4m

около 4 лет назад

Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.

EPSS: Низкий
github логотип

GHSA-2vfg-m6gf-wcr4

около 4 лет назад

An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.

EPSS: Низкий
github логотип

GHSA-2vff-hj5x-8gq7

около 2 месяцев назад

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vfc-ww3w-459q

около 4 лет назад

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vf9-33mf-fjw2

12 месяцев назад

A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2vf8-hmhp-gw9x

больше 2 лет назад

This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vfq-7gxj-92hg

A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2vfp-x8jm-58cj

Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2vfp-rfhc-3mm2

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2vfp-cq97-7pq2

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, and CVE-2014-2417.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfp-2qpf-jwrq

A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

CVSS3: 8.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-2vfm-wf45-cf66

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfm-v289-h559

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

CVSS3: 8.6
0%
Низкий
24 дня назад
github логотип
GHSA-2vfm-rw86-mwjv

David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vfm-65cj-5j48

Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

CVSS3: 4.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2vfj-ww29-h4x2

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vfj-3h9f-v378

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfh-w2hp-mr2m

eDeploy has RCE via cPickle deserialization of untrusted data

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vfh-6ppw-453g

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
1%
Низкий
около 2 лет назад
github логотип
GHSA-2vfg-xrq7-ffvf

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 7.5
0%
Низкий
10 дней назад
github логотип
GHSA-2vfg-x9vh-wg4m

Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vfg-m6gf-wcr4

An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vff-hj5x-8gq7

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2vfc-ww3w-459q

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2vf9-33mf-fjw2

A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
12 месяцев назад
github логотип
GHSA-2vf8-hmhp-gw9x

This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.

0%
Низкий
больше 2 лет назад

Уязвимостей на страницу