Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2hvm-7cm7-f4p9

около 4 лет назад

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hvj-wgq7-vx3c

около 4 лет назад

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

EPSS: Низкий
github логотип

GHSA-2hvj-p59v-p559

больше 1 года назад

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2hvj-57fv-jjcc

4 месяца назад

There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hvh-v6r6-v7r4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.

EPSS: Низкий
github логотип

GHSA-2hvh-cw5c-8q8q

9 месяцев назад

CKAN vulnerable to fixed session IDs

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hvh-c5c2-vj85

около 4 лет назад

Zend Framework SQL injection vector using null byte for PDO

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hvh-29rf-rgx7

около 4 лет назад

The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.

EPSS: Низкий
github логотип

GHSA-2hvg-x2p3-jfmj

около 4 лет назад

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.

EPSS: Низкий
github логотип

GHSA-2hvg-v2h5-m85r

около 4 лет назад

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

EPSS: Низкий
github логотип

GHSA-2hvg-pfw9-r56c

около 4 лет назад

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2hvg-8mmr-f5mc

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free in em28xx_v4l2_open() em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct and set dev->v4l2 to NULL under dev->lock. This race leads to two issues: - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler, since the video_device is embedded in the freed em28xx_v4l2 struct. - NULL pointer dereference in em28xx_resolution_set() when accessing v4l2->norm, since dev->v4l2 has been set to NULL. Fix this by moving the mutex_lock() before the dev->v4l2 read and adding a NULL check for dev->v4l2 under the lock.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hvf-6vwf-3fjq

3 месяца назад

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hvc-hwg3-hpvw

больше 3 лет назад

PaddlePaddle Out-of-bounds Read vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2hvc-5c6v-f533

2 месяца назад

Apache CXF: Untrusted JMS configuration can lead to RCE

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hv7-f89v-j5wh

больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to gain root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hv6-pqf3-c2j2

около 4 лет назад

Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

EPSS: Средний
github логотип

GHSA-2hv6-9hx6-7j2g

больше 1 года назад

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2hv6-78vc-qvw9

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

EPSS: Низкий
github логотип

GHSA-2hv6-3c5r-xmfv

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hvm-7cm7-f4p9

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2hvj-wgq7-vx3c

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hvj-p59v-p559

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hvj-57fv-jjcc

There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2hvh-v6r6-v7r4

Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hvh-cw5c-8q8q

CKAN vulnerable to fixed session IDs

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-2hvh-c5c2-vj85

Zend Framework SQL injection vector using null byte for PDO

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2hvh-29rf-rgx7

The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2hvg-x2p3-jfmj

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2hvg-v2h5-m85r

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hvg-pfw9-r56c

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVSS3: 9.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hvg-8mmr-f5mc

In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free in em28xx_v4l2_open() em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct and set dev->v4l2 to NULL under dev->lock. This race leads to two issues: - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler, since the video_device is embedded in the freed em28xx_v4l2 struct. - NULL pointer dereference in em28xx_resolution_set() when accessing v4l2->norm, since dev->v4l2 has been set to NULL. Fix this by moving the mutex_lock() before the dev->v4l2 read and adding a NULL check for dev->v4l2 under the lock.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2hvf-6vwf-3fjq

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

CVSS3: 6.3
5%
Низкий
3 месяца назад
github логотип
GHSA-2hvc-hwg3-hpvw

PaddlePaddle Out-of-bounds Read vulnerability

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvc-5c6v-f533

Apache CXF: Untrusted JMS configuration can lead to RCE

CVSS3: 7.5
1%
Низкий
2 месяца назад
github логотип
GHSA-2hv7-f89v-j5wh

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to gain root privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hv6-pqf3-c2j2

Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

51%
Средний
около 4 лет назад
github логотип
GHSA-2hv6-9hx6-7j2g

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hv6-78vc-qvw9

Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hv6-3c5r-xmfv

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу