Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2p3w-56f5-gwxv

2 месяца назад

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p3v-w39c-p52w

8 месяцев назад

The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in the plugin's settings.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2p3v-427c-rpc7

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2p3r-9wcw-v845

3 месяца назад

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p3q-x3x4-ww4x

около 4 лет назад

In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-8982 and CVE-2020-8983 but has essentially the same risk.

EPSS: Средний
github логотип

GHSA-2p3q-h3hg-jcqq

13 дней назад

Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2p3q-c42r-jwmx

больше 3 лет назад

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function delete_order of the file /classes/master.php?f=delete_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225534 is the identifier assigned to this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2p3p-3j6c-h3fv

около 4 лет назад

An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Information Disclosure Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p3j-x2c8-h7qw

около 4 лет назад

360 Systems Maxx, Image Server Maxx, and Image Server 2000 have a hardcoded password for the root account, which makes it easier for remote attackers to execute arbitrary code, or modify video content or scheduling, via an SSH session.

EPSS: Низкий
github логотип

GHSA-2p3j-cmc3-j53x

около 4 лет назад

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2p3j-8j8p-99q8

около 4 лет назад

DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p3h-vm38-7wjp

около 4 лет назад

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-2p3h-m9wr-j5v9

больше 4 лет назад

A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p3h-3pmw-fjvx

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: regulator: core: Prevent integer underflow By using a ratio of delay to poll_enabled_time that is not integer time_remaining underflows and does not exit the loop as expected. As delay could be derived from DT and poll_enabled_time is defined in the driver this can easily happen. Use a signed iterator to make sure that the loop exits once the remaining time is negative.

EPSS: Низкий
github логотип

GHSA-2p3h-3pf2-9rg6

3 месяца назад

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 109.4 addresses this issue. This patch is called 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. Upgrading the affected component is advised. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2p3f-3cj6-r8vv

больше 3 лет назад

A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2p3c-p3qw-69r4

почти 4 года назад

The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations

EPSS: Низкий
github логотип

GHSA-2p3c-9cpr-r34w

5 месяцев назад

A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earlier allows remote attackers to execute arbitrary web script or HTML via a crafted payload in a filename parameter (e.g., to the FileRead function). This occurs because the error message is not properly sanitized before being output to the user. This vulnerability is fixed in version 2.18.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2p39-r99c-cqgg

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2p38-wq56-wg8h

больше 4 лет назад

The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p3w-56f5-gwxv

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2p3v-w39c-p52w

The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in the plugin's settings.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2p3v-427c-rpc7

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2p3r-9wcw-v845

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2p3q-x3x4-ww4x

In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-8982 and CVE-2020-8983 but has essentially the same risk.

14%
Средний
около 4 лет назад
github логотип
GHSA-2p3q-h3hg-jcqq

Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability

CVSS3: 8.8
1%
Низкий
13 дней назад
github логотип
GHSA-2p3q-c42r-jwmx

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function delete_order of the file /classes/master.php?f=delete_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225534 is the identifier assigned to this vulnerability.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p3p-3j6c-h3fv

An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Information Disclosure Vulnerability'.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2p3j-x2c8-h7qw

360 Systems Maxx, Image Server Maxx, and Image Server 2000 have a hardcoded password for the root account, which makes it easier for remote attackers to execute arbitrary code, or modify video content or scheduling, via an SSH session.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2p3j-cmc3-j53x

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p3j-8j8p-99q8

DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2p3h-vm38-7wjp

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p3h-m9wr-j5v9

A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2p3h-3pmw-fjvx

In the Linux kernel, the following vulnerability has been resolved: regulator: core: Prevent integer underflow By using a ratio of delay to poll_enabled_time that is not integer time_remaining underflows and does not exit the loop as expected. As delay could be derived from DT and poll_enabled_time is defined in the driver this can easily happen. Use a signed iterator to make sure that the loop exits once the remaining time is negative.

0%
Низкий
10 месяцев назад
github логотип
GHSA-2p3h-3pf2-9rg6

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 109.4 addresses this issue. This patch is called 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. Upgrading the affected component is advised. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

CVSS3: 2.4
0%
Низкий
3 месяца назад
github логотип
GHSA-2p3f-3cj6-r8vv

A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p3c-p3qw-69r4

The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations

почти 4 года назад
github логотип
GHSA-2p3c-9cpr-r34w

A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earlier allows remote attackers to execute arbitrary web script or HTML via a crafted payload in a filename parameter (e.g., to the FileRead function). This occurs because the error message is not properly sanitized before being output to the user. This vulnerability is fixed in version 2.18.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-2p39-r99c-cqgg

Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p38-wq56-wg8h

The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад

Уязвимостей на страницу