Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-28r9-jxmr-8hgr

4 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through <= 2.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28r9-hhcv-7c73

около 4 лет назад

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.

EPSS: Низкий
github логотип

GHSA-28r9-967h-xvcv

около 4 лет назад

Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28r9-5f3v-j8fw

около 4 лет назад

When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28r9-4273-pm3w

около 4 лет назад

An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28r8-9g34-2x25

около 4 лет назад

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.

EPSS: Низкий
github логотип

GHSA-28r8-6q2m-x9g4

около 4 лет назад

The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-28r7-8r62-w9hj

10 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

EPSS: Низкий
github логотип

GHSA-28r6-jm5h-mrgg

больше 4 лет назад

Access control bypass in Beego

EPSS: Низкий
github логотип

GHSA-28r5-hvrv-cvq5

4 месяца назад

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28r4-58h5-m5rr

около 4 лет назад

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28r2-q6m8-9hpx

около 4 лет назад

HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-28qw-8jmg-32wx

больше 2 лет назад

Transient DOS when processing a NULL buffer while parsing WLAN vdev.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28qr-hqrv-mhvr

около 4 лет назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-28qq-773c-49rf

около 4 лет назад

SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-28qq-5f47-r5x2

6 месяцев назад

Duplicate Advisory: gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28qp-wgp5-fp7m

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

EPSS: Низкий
github логотип

GHSA-28qp-rcr7-xp4g

больше 1 года назад

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28qp-98vv-5xqx

около 4 лет назад

The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28qp-8c7m-wc33

около 4 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28r9-jxmr-8hgr

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through <= 2.1.

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-28r9-hhcv-7c73

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.

3%
Низкий
около 4 лет назад
github логотип
GHSA-28r9-967h-xvcv

Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-28r9-5f3v-j8fw

When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-28r9-4273-pm3w

An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-28r8-9g34-2x25

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28r8-6q2m-x9g4

The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-28r7-8r62-w9hj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

0%
Низкий
10 месяцев назад
github логотип
GHSA-28r6-jm5h-mrgg

Access control bypass in Beego

1%
Низкий
больше 4 лет назад
github логотип
GHSA-28r5-hvrv-cvq5

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-28r4-58h5-m5rr

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-28r2-q6m8-9hpx

HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion

CVSS3: 8.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-28qw-8jmg-32wx

Transient DOS when processing a NULL buffer while parsing WLAN vdev.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28qr-hqrv-mhvr

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-28qq-773c-49rf

SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28qq-5f47-r5x2

Duplicate Advisory: gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

CVSS3: 9.8
6 месяцев назад
github логотип
GHSA-28qp-wgp5-fp7m

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28qp-rcr7-xp4g

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-28qp-98vv-5xqx

The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-28qp-8c7m-wc33

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
14%
Средний
около 4 лет назад

Уязвимостей на страницу