Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3rwr-fq47-78qj

больше 1 года назад

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3rwq-vmr7-cggq

больше 2 лет назад

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rwq-pxmh-pw55

больше 2 лет назад

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3rwq-fg95-ffjf

7 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Side Request Forgery.This issue affects Okulistik: through 21102025.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rwq-2648-vg59

больше 3 лет назад

Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rwp-9p3r-82c4

больше 2 лет назад

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3rwm-jg87-jp7c

больше 4 лет назад

An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA8081, QCA9377, QCA9379, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM660, SDX20, SDX24

EPSS: Низкий
github логотип

GHSA-3rwj-vm9j-wg4r

больше 4 лет назад

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rwj-v7jp-w542

больше 4 лет назад

Pagekit Stored Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3rwj-9q84-fmqw

больше 1 года назад

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.

EPSS: Низкий
github логотип

GHSA-3rwj-4395-cj7h

около 2 месяцев назад

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rwj-253m-qrvm

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases we can trigger: xe 0000:03:00.0: [drm] Assertion `exec_queue_destroyed(q)` failed! .... WARNING: CPU: 18 PID: 2640 at drivers/gpu/drm/xe/xe_guc_submit.c:1826 xe_guc_sched_done_handler+0xa54/0xef0 [xe] xe 0000:03:00.0: [drm] *ERROR* GT1: DEREGISTER_DONE: Unexpected engine state 0x00a1, guc_id=57 Looking at a snippet of corresponding ftrace for this GuC id we can see: 162.673311: xe_sched_msg_add: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673317: xe_sched_msg_recv: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673319: xe_exec_queue_scheduling_disable: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674089: xe_exec_queue_kill: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674108: xe_exec_queue_close: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rwh-j2p9-wp9q

больше 4 лет назад

The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

EPSS: Низкий
github логотип

GHSA-3rwg-qhqc-m6rc

около 2 лет назад

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rwg-qf5g-xvjv

больше 4 лет назад

Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rwg-7w5w-62jx

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3rwf-9748-8cvv

3 месяца назад

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rwc-8hqh-2vxh

больше 2 лет назад

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rwc-35jw-8w8p

больше 4 лет назад

The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

EPSS: Низкий
github логотип

GHSA-3rw9-wmc8-8948

около 1 года назад

Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rwr-fq47-78qj

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rwq-vmr7-cggq

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3rwq-pxmh-pw55

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

CVSS3: 9.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3rwq-fg95-ffjf

Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Side Request Forgery.This issue affects Okulistik: through 21102025.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3rwq-2648-vg59

Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwp-9p3r-82c4

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3rwm-jg87-jp7c

An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA8081, QCA9377, QCA9379, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM660, SDX20, SDX24

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwj-vm9j-wg4r

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwj-v7jp-w542

Pagekit Stored Cross-site Scripting

CVSS3: 4.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwj-9q84-fmqw

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.

0%
Низкий
больше 1 года назад
github логотип
GHSA-3rwj-4395-cj7h

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3rwj-253m-qrvm

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases we can trigger: xe 0000:03:00.0: [drm] Assertion `exec_queue_destroyed(q)` failed! .... WARNING: CPU: 18 PID: 2640 at drivers/gpu/drm/xe/xe_guc_submit.c:1826 xe_guc_sched_done_handler+0xa54/0xef0 [xe] xe 0000:03:00.0: [drm] *ERROR* GT1: DEREGISTER_DONE: Unexpected engine state 0x00a1, guc_id=57 Looking at a snippet of corresponding ftrace for this GuC id we can see: 162.673311: xe_sched_msg_add: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673317: xe_sched_msg_recv: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673319: xe_exec_queue_scheduling_disable: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674089: xe_exec_queue_kill: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674108: xe_exec_queue_close: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc...

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rwh-j2p9-wp9q

The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwg-qhqc-m6rc

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3rwg-qf5g-xvjv

Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rwg-7w5w-62jx

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-3rwf-9748-8cvv

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3rwc-8hqh-2vxh

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3rwc-35jw-8w8p

The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3rw9-wmc8-8948

Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token

около 1 года назад

Уязвимостей на страницу