Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2g2x-v3m2-fgmc

около 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via unknown vectors related to Kernel.

EPSS: Низкий
github логотип

GHSA-2g2x-6p8h-94w3

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.4.37651. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Document objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13741.

EPSS: Низкий
github логотип

GHSA-2g2x-4qqh-7m58

около 4 лет назад

Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

EPSS: Низкий
github логотип

GHSA-2g2v-w577-39wq

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g2v-r289-p3rh

около 4 лет назад

SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.

EPSS: Низкий
github логотип

GHSA-2g2v-h26j-4qfh

больше 1 года назад

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

EPSS: Низкий
github логотип

GHSA-2g2v-frmf-48r9

около 4 лет назад

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

EPSS: Низкий
github логотип

GHSA-2g2r-fqp8-fwpv

больше 4 лет назад

NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.

EPSS: Низкий
github логотип

GHSA-2g2r-3v4x-6xv3

почти 3 года назад

Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g2q-92qg-99wf

около 1 года назад

A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g2p-m572-cj69

около 2 лет назад

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g2p-3v97-37x7

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary web script or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP referer to pixel.php.

EPSS: Низкий
github логотип

GHSA-2g2m-jxx6-g9c9

около 4 лет назад

The GLOBAL MOVIE MAGAZINE (aka com.magzter.globalmoviemagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2g2m-8qqm-fqp4

больше 4 лет назад

Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2g2j-q43h-638m

около 4 лет назад

The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allow attackers to cause a denial of service (system crash) via a crafted application, which triggers an invalid memory access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g2j-fq65-5w72

3 дня назад

An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g2h-672j-8vfh

около 2 лет назад

Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g2g-m4v5-68cr

больше 1 года назад

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2g2g-8p8h-fgwm

около 2 месяцев назад

Twig: XSS in profiler HtmlDumper via unescaped template and profile names

EPSS: Низкий
github логотип

GHSA-2g2f-5373-6jjv

около 4 лет назад

Unspecified vulnerability in Oracle Solaris 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Print Filter Utility.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g2x-v3m2-fgmc

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via unknown vectors related to Kernel.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2g2x-6p8h-94w3

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.4.37651. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Document objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13741.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2g2x-4qqh-7m58

Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2g2v-w577-39wq

Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-2g2v-r289-p3rh

SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2g2v-h26j-4qfh

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

1%
Низкий
больше 1 года назад
github логотип
GHSA-2g2v-frmf-48r9

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

6%
Низкий
около 4 лет назад
github логотип
GHSA-2g2r-fqp8-fwpv

NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-2g2r-3v4x-6xv3

Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2g2q-92qg-99wf

A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
2%
Низкий
около 1 года назад
github логотип
GHSA-2g2p-m572-cj69

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g2p-3v97-37x7

Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary web script or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP referer to pixel.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2g2m-jxx6-g9c9

The GLOBAL MOVIE MAGAZINE (aka com.magzter.globalmoviemagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2g2m-8qqm-fqp4

Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2g2j-q43h-638m

The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allow attackers to cause a denial of service (system crash) via a crafted application, which triggers an invalid memory access.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2g2j-fq65-5w72

An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.

CVSS3: 6.5
0%
Низкий
3 дня назад
github логотип
GHSA-2g2h-672j-8vfh

Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g2g-m4v5-68cr

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g2g-8p8h-fgwm

Twig: XSS in profiler HtmlDumper via unescaped template and profile names

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2g2f-5373-6jjv

Unspecified vulnerability in Oracle Solaris 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Print Filter Utility.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу