Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-2qv6-9wx5-cwv4

2 месяца назад

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2qv6-8qcf-2852

9 месяцев назад

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qv5-c5x6-3fqr

около 4 лет назад

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2qv5-7mw5-j3cg

больше 3 лет назад

spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisers

EPSS: Низкий
github логотип

GHSA-2qv4-c5gv-5f74

около 4 лет назад

Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2qv4-869g-77jr

около 4 лет назад

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.

EPSS: Низкий
github логотип

GHSA-2qv3-h9c7-9qcq

больше 1 года назад

Windows WLAN AutoConfig Service Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2qv3-7vvv-5c37

больше 1 года назад

In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2qv2-r6pr-h6qm

около 4 лет назад

XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2qv2-hwxw-9jhw

больше 4 лет назад

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qv2-gmpw-q53p

около 4 лет назад

While processing logs, data is copied into a buffer pointed to by an untrusted pointer in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2qv2-8rj8-m28p

больше 1 года назад

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qv2-52fw-4p3c

около 4 лет назад

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112204376

EPSS: Низкий
github логотип

GHSA-2qrx-vr2m-vjfp

около 4 лет назад

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input validation of CLI command user input. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a CLI command with crafted user input. A successful exploit could allow the attacker to execute arbitrary commands on the affected system that should be restricted. The attacker would need to have valid user credentials for the device. Cisco Bug IDs: CSCvf49844.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2qrx-mpvp-j33p

больше 3 лет назад

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qrx-m2qx-4wr4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2qrw-v6m9-cjjq

14 дней назад

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qrw-655g-f524

больше 2 лет назад

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qrv-v95f-h2jw

около 4 лет назад

ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

EPSS: Низкий
github логотип

GHSA-2qrv-rc5x-2g2h

4 месяца назад

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qv6-9wx5-cwv4

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-2qv6-8qcf-2852

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2qv5-c5x6-3fqr

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qv5-7mw5-j3cg

spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisers

больше 3 лет назад
github логотип
GHSA-2qv4-c5gv-5f74

Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qv4-869g-77jr

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qv3-h9c7-9qcq

Windows WLAN AutoConfig Service Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2qv3-7vvv-5c37

In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qv2-r6pr-h6qm

XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2qv2-hwxw-9jhw

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2qv2-gmpw-q53p

While processing logs, data is copied into a buffer pointed to by an untrusted pointer in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2qv2-8rj8-m28p

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2qv2-52fw-4p3c

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112204376

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qrx-vr2m-vjfp

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input validation of CLI command user input. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a CLI command with crafted user input. A successful exploit could allow the attacker to execute arbitrary commands on the affected system that should be restricted. The attacker would need to have valid user credentials for the device. Cisco Bug IDs: CSCvf49844.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qrx-mpvp-j33p

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qrx-m2qx-4wr4

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qrw-v6m9-cjjq

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

CVSS3: 8.8
0%
Низкий
14 дней назад
github логотип
GHSA-2qrw-655g-f524

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2qrv-v95f-h2jw

ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

0%
Низкий
4 месяца назад

Уязвимостей на страницу