Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-27vg-33gh-4hwg

5 месяцев назад

Actual Sync Server has an Authenticated Path Traversal

EPSS: Низкий
github логотип

GHSA-27vf-v322-7qf5

около 4 лет назад

Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-27vf-8fw5-36p7

около 4 лет назад

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.

EPSS: Низкий
github логотип

GHSA-27vf-3g4f-6jp7

больше 1 года назад

LibreNMS Ports Stored Cross-site Scripting vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-27vc-vrhq-mf4c

около 4 лет назад

SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.

EPSS: Низкий
github логотип

GHSA-27vc-rww5-64v8

почти 2 года назад

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27v9-jf76-68p4

почти 3 года назад

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239260.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27v9-6wwc-82r3

около 4 лет назад

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-27v9-58mg-8v43

около 4 лет назад

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

EPSS: Низкий
github логотип

GHSA-27v8-7qqq-m35q

3 месяца назад

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27v7-qhfv-rqq8

около 7 лет назад

Insecure Credential Storage in web3

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-27v6-gp7m-8rxj

10 месяцев назад

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-27v6-gmmm-5qf3

около 4 лет назад

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

EPSS: Низкий
github логотип

GHSA-27v6-4m9p-3qq4

почти 4 года назад

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-27v5-v9w4-6pr5

около 4 лет назад

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27v5-q384-ff55

больше 4 лет назад

find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.

EPSS: Низкий
github логотип

GHSA-27v5-mp7r-pc7w

10 месяцев назад

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27v5-c462-wpq7

4 месяца назад

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27v4-w7r4-68vg

больше 2 лет назад

Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-27v4-m256-2g57

почти 3 года назад

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27vg-33gh-4hwg

Actual Sync Server has an Authenticated Path Traversal

0%
Низкий
5 месяцев назад
github логотип
GHSA-27vf-v322-7qf5

Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27vf-8fw5-36p7

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27vf-3g4f-6jp7

LibreNMS Ports Stored Cross-site Scripting vulnerability

CVSS3: 4.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-27vc-vrhq-mf4c

SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27vc-rww5-64v8

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-27v9-jf76-68p4

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239260.

CVSS3: 6.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-27v9-6wwc-82r3

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-27v9-58mg-8v43

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27v8-7qqq-m35q

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-27v7-qhfv-rqq8

Insecure Credential Storage in web3

CVSS3: 3.3
около 7 лет назад
github логотип
GHSA-27v6-gp7m-8rxj

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVSS3: 4
0%
Низкий
10 месяцев назад
github логотип
GHSA-27v6-gmmm-5qf3

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-27v6-4m9p-3qq4

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-27v5-v9w4-6pr5

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-27v5-q384-ff55

find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-27v5-mp7r-pc7w

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-27v5-c462-wpq7

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-27v4-w7r4-68vg

Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.

CVSS3: 3.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-27v4-m256-2g57

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

CVSS3: 9.8
1%
Низкий
почти 3 года назад

Уязвимостей на страницу