Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-xr38-w5rc-h3q4

21 день назад

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr38-33h6-9m6r

около 4 лет назад

In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.

EPSS: Низкий
github логотип

GHSA-xr37-pjfh-qwwc

около 4 лет назад

Fortify Plugin stored credentials in plain text

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xr37-jcv5-cqxv

больше 2 лет назад

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xr37-95p8-x373

больше 4 лет назад

An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).

EPSS: Низкий
github логотип

GHSA-xr36-f3cm-q4rx

около 4 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-xr35-94xw-8gm8

5 месяцев назад

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xr34-pc3c-449f

8 месяцев назад

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr34-4j63-xfh6

около 1 месяца назад

Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xr32-vwr8-2rgc

около 4 лет назад

An information disclosure vulnerability in the NVIDIA libwilhelm. Product: Android. Versions: Android kernel. Android ID A-64339309. References: N-CVE-2017-13175.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr32-36pp-7rvg

10 месяцев назад

A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xr2w-pmx3-6j4j

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr2v-p69m-q5gx

около 4 лет назад

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.

EPSS: Низкий
github логотип

GHSA-xr2v-mvcq-w8hv

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xr2r-hj4r-gw3q

почти 2 года назад

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr2r-hh4x-gv58

около 4 лет назад

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr2r-4cvv-wp49

около 4 лет назад

parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.

EPSS: Низкий
github логотип

GHSA-xr2q-p6hj-37m3

около 4 лет назад

The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr2q-4fvx-23gr

около 4 лет назад

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr2p-f39w-cjpv

больше 3 лет назад

ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr38-w5rc-h3q4

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
0%
Низкий
21 день назад
github логотип
GHSA-xr38-33h6-9m6r

In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr37-pjfh-qwwc

Fortify Plugin stored credentials in plain text

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr37-jcv5-cqxv

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.

CVSS3: 2.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xr37-95p8-x373

An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr36-f3cm-q4rx

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr35-94xw-8gm8

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xr34-pc3c-449f

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xr34-4j63-xfh6

Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xr32-vwr8-2rgc

An information disclosure vulnerability in the NVIDIA libwilhelm. Product: Android. Versions: Android kernel. Android ID A-64339309. References: N-CVE-2017-13175.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr32-36pp-7rvg

A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.

CVSS3: 6
0%
Низкий
10 месяцев назад
github логотип
GHSA-xr2w-pmx3-6j4j

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xr2v-p69m-q5gx

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xr2v-mvcq-w8hv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr2r-hj4r-gw3q

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr2r-hh4x-gv58

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.

CVSS3: 7.5
6%
Низкий
около 4 лет назад
github логотип
GHSA-xr2r-4cvv-wp49

parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xr2q-p6hj-37m3

The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr2q-4fvx-23gr

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xr2p-f39w-cjpv

ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

CVSS3: 8.8
15%
Средний
больше 3 лет назад

Уязвимостей на страницу