Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-2fcr-jfvc-vgg2

10 дней назад

Gitea: Two SSRF findings

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fcq-6m38-v4mx

около 4 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.

EPSS: Низкий
github логотип

GHSA-2fcq-5g6c-rqrj

около 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2fcp-wr9w-5jjr

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fcj-xjq4-c3h8

11 месяцев назад

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

EPSS: Низкий
github логотип

GHSA-2fcj-pq3f-v8fp

5 месяцев назад

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fcj-g7j8-pg57

около 1 года назад

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fch-jvg5-crf6

больше 7 лет назад

Improper Input Validation python-gnupg

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fch-hv74-fgw9

больше 3 лет назад

Cross site scripting (XSS) in wwbn/avideo

EPSS: Низкий
github логотип

GHSA-2fch-5g6g-5j6q

около 2 месяцев назад

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fch-4j3w-44mf

около 4 лет назад

cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).

EPSS: Низкий
github логотип

GHSA-2fcg-hwv9-g767

почти 3 года назад

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fcg-5wrc-pm23

около 4 лет назад

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2fcg-48pf-99vm

больше 4 лет назад

Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.

EPSS: Низкий
github логотип

GHSA-2fcc-jc2g-q7h3

больше 1 года назад

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.&nbsp; This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fcc-j9wr-vcj4

около 1 года назад

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fcc-frh3-hm3c

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in origincode Video Gallery – Vimeo and YouTube Gallery allows Stored XSS. This issue affects Video Gallery – Vimeo and YouTube Gallery: from n/a through 1.1.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fcc-cgw7-6rrw

6 месяцев назад

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device().

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fc9-xpp8-2g9h

больше 2 лет назад

`@backstage/backend-common` vulnerable to path traversal through symlinks

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2fc8-wj99-h595

около 4 лет назад

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fcr-jfvc-vgg2

Gitea: Two SSRF findings

CVSS3: 7.7
10 дней назад
github логотип
GHSA-2fcq-6m38-v4mx

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2fcq-5g6c-rqrj

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2fcp-wr9w-5jjr

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2fcj-xjq4-c3h8

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

0%
Низкий
11 месяцев назад
github логотип
GHSA-2fcj-pq3f-v8fp

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2fcj-g7j8-pg57

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2fch-jvg5-crf6

Improper Input Validation python-gnupg

CVSS3: 7.5
9%
Низкий
больше 7 лет назад
github логотип
GHSA-2fch-hv74-fgw9

Cross site scripting (XSS) in wwbn/avideo

больше 3 лет назад
github логотип
GHSA-2fch-5g6g-5j6q

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2fch-4j3w-44mf

cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).

1%
Низкий
около 4 лет назад
github логотип
GHSA-2fcg-hwv9-g767

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2fcg-5wrc-pm23

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2fcg-48pf-99vm

Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2fcc-jc2g-q7h3

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.&nbsp; This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.

CVSS3: 7.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-2fcc-j9wr-vcj4

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2fcc-frh3-hm3c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in origincode Video Gallery – Vimeo and YouTube Gallery allows Stored XSS. This issue affects Video Gallery – Vimeo and YouTube Gallery: from n/a through 1.1.7.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2fcc-cgw7-6rrw

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device().

CVSS3: 5.4
1%
Низкий
6 месяцев назад
github логотип
GHSA-2fc9-xpp8-2g9h

`@backstage/backend-common` vulnerable to path traversal through symlinks

CVSS3: 8.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2fc8-wj99-h595

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу