Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-2r8v-p65x-3663

около 1 месяца назад

QUIC has Broken TLS verification

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2r8v-9m34-p378

около 4 лет назад

LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2r8v-44qx-992x

6 месяцев назад

The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.

EPSS: Низкий
github логотип

GHSA-2r8v-24rx-6584

около 4 лет назад

The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.

EPSS: Низкий
github логотип

GHSA-2r8q-h42x-rjm5

около 4 лет назад

Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2r8q-2j9h-3chh

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: net: dpaa: Pad packets to ETH_ZLEN When sending packets under 60 bytes, up to three bytes of the buffer following the data may be leaked. Avoid this by extending all packets to ETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be reproduced by running $ ping -s 11 destination

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2r8p-fg3c-wcj4

почти 5 лет назад

Heap OOB and CHECK fail in `ResourceGather`

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2r8p-5hq4-h3r4

около 2 месяцев назад

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2r8p-4r3c-hw34

7 месяцев назад

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2r8j-rf53-9g72

около 2 лет назад

Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2r8h-ccmx-mmjc

больше 4 лет назад

Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2r8h-6hvp-jqwg

4 месяца назад

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2r8h-2rq3-qxmx

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= 1.2.17.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2r8f-cf6w-x5vq

6 месяцев назад

Duplicate Advisory: FUXA contains a hard-coded credential vulnerability

EPSS: Низкий
github логотип

GHSA-2r8f-2665-3gxq

почти 6 лет назад

Malicious Package in froever

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r89-wvrg-9qjh

почти 4 года назад

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2r89-3cpr-6vj2

около 4 лет назад

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r88-ww5g-vx3h

около 4 лет назад

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r87-96mr-fgv7

больше 4 лет назад

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."

EPSS: Высокий
github логотип

GHSA-2r87-8x7j-8ppq

около 2 месяцев назад

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r8v-p65x-3663

QUIC has Broken TLS verification

CVSS3: 9.1
около 1 месяца назад
github логотип
GHSA-2r8v-9m34-p378

LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.

CVSS3: 4.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-2r8v-44qx-992x

The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.

1%
Низкий
6 месяцев назад
github логотип
GHSA-2r8v-24rx-6584

The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2r8q-h42x-rjm5

Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2r8q-2j9h-3chh

In the Linux kernel, the following vulnerability has been resolved: net: dpaa: Pad packets to ETH_ZLEN When sending packets under 60 bytes, up to three bytes of the buffer following the data may be leaked. Avoid this by extending all packets to ETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be reproduced by running $ ping -s 11 destination

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2r8p-fg3c-wcj4

Heap OOB and CHECK fail in `ResourceGather`

CVSS3: 7.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-2r8p-5hq4-h3r4

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.

CVSS3: 5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2r8p-4r3c-hw34

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-2r8j-rf53-9g72

Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2r8h-ccmx-mmjc

Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2r8h-6hvp-jqwg

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2r8h-2rq3-qxmx

Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= 1.2.17.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2r8f-cf6w-x5vq

Duplicate Advisory: FUXA contains a hard-coded credential vulnerability

6 месяцев назад
github логотип
GHSA-2r8f-2665-3gxq

Malicious Package in froever

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-2r89-wvrg-9qjh

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2r89-3cpr-6vj2

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVSS3: 9.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-2r88-ww5g-vx3h

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2r87-96mr-fgv7

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."

76%
Высокий
больше 4 лет назад
github логотип
GHSA-2r87-8x7j-8ppq

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу