Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-275h-jpxv-7884

около 2 месяцев назад

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-275h-9v8g-x3q8

около 4 лет назад

PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.

EPSS: Низкий
github логотип

GHSA-275g-g844-73jh

около 1 года назад

Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation

EPSS: Низкий
github логотип

GHSA-275g-39jx-pp75

почти 3 года назад

In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-275f-wc6q-wvqf

больше 4 лет назад

ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties of the file are viewed.

EPSS: Низкий
github логотип

GHSA-275f-jq4p-wxgw

около 4 лет назад

Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-275c-xpvc-jgfw

28 дней назад

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

EPSS: Низкий
github логотип

GHSA-275c-wjvg-g854

почти 4 года назад

Visual Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35777, CVE-2022-35825, CVE-2022-35827.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-275c-w5mq-v5m2

больше 2 лет назад

PaddlePaddle floating point exception in paddle.argmin and paddle.argmax

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-275c-v3rc-xghx

около 4 лет назад

Kirby XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-275c-875v-46qg

почти 2 года назад

The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-275c-83p3-m29v

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through <= 2.7.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-275c-3cvw-rvcg

больше 1 года назад

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2759-f2p3-358h

около 4 лет назад

SQL injection vulnerability in the Flash SlideShow (slideshow) extension 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2758-47r7-2729

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2758-3vp9-72c9

около 4 лет назад

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-2757-2xv4-prm9

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2757-2hpv-v482

11 месяцев назад

Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2756-g6w2-6hv2

около 2 месяцев назад

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2755-4mpr-8455

около 4 лет назад

IrfanView 4.53 allows a User Mode Write AV starting at DPX!ReadDPX_W+0x0000000000001203.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-275h-jpxv-7884

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-275h-9v8g-x3q8

PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.

5%
Низкий
около 4 лет назад
github логотип
GHSA-275g-g844-73jh

Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation

0%
Низкий
около 1 года назад
github логотип
GHSA-275g-39jx-pp75

In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-275f-wc6q-wvqf

ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties of the file are viewed.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-275f-jq4p-wxgw

Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on the server.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-275c-xpvc-jgfw

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

28 дней назад
github логотип
GHSA-275c-wjvg-g854

Visual Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35777, CVE-2022-35825, CVE-2022-35827.

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-275c-w5mq-v5m2

PaddlePaddle floating point exception in paddle.argmin and paddle.argmax

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-275c-v3rc-xghx

Kirby XSS Vulnerability

CVSS3: 5.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-275c-875v-46qg

The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-275c-83p3-m29v

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through <= 2.7.3.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-275c-3cvw-rvcg

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2759-f2p3-358h

SQL injection vulnerability in the Flash SlideShow (slideshow) extension 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2758-47r7-2729

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2758-3vp9-72c9

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2757-2xv4-prm9

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2757-2hpv-v482

Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-2756-g6w2-6hv2

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 7.3
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-2755-4mpr-8455

IrfanView 4.53 allows a User Mode Write AV starting at DPX!ReadDPX_W+0x0000000000001203.

CVSS3: 7.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу