Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-23w9-jw3m-h5hj

около 4 лет назад

The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

EPSS: Низкий
github логотип

GHSA-23w9-g78h-f93v

около 4 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23w8-x79h-65g9

больше 1 года назад

Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23w8-jvp8-xp5w

около 4 лет назад

An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. The server typically logs activity only when a client application specifies that logging is desired. This can be problematic for use cases in a regulated industry, where server-side logging is required in additional situations.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23w8-jcvm-j4jg

больше 4 лет назад

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

EPSS: Низкий
github логотип

GHSA-23w8-fw6w-p2gr

около 4 лет назад

An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23w7-h454-2fw3

около 4 лет назад

The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to execute code and gain privileges.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-23w7-3gw5-5jqr

около 1 года назад

GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-23w5-m3rw-wr6g

больше 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-23w5-4m68-gv63

около 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: PS). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23w4-rpc6-wpcc

11 месяцев назад

Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet

EPSS: Низкий
github логотип

GHSA-23w4-f563-4m2j

около 4 лет назад

A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

EPSS: Низкий
github логотип

GHSA-23w3-wj92-2gp6

больше 1 года назад

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24521)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23w3-pmw9-p5xf

около 4 лет назад

Possible buffer overflow while playing mkv clip due to lack of validation of atom size buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

EPSS: Низкий
github логотип

GHSA-23w3-3c8p-hvh3

около 1 года назад

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23w2-wmrg-qxqw

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded allows Reflected XSS. This issue affects Theme Switcher Reloaded: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23w2-5h7v-wppv

около 4 лет назад

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Graphics Component RCE Vulnerability."

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-23vx-xx4m-jf8w

около 1 года назад

A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-23vx-2j4v-jvhm

10 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-23vw-mhv5-grv5

почти 6 лет назад

Denial of Service in @hapi/hapi

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23w9-jw3m-h5hj

The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

1%
Низкий
около 4 лет назад
github логотип
GHSA-23w9-g78h-f93v

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
8%
Низкий
около 4 лет назад
github логотип
GHSA-23w8-x79h-65g9

Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23w8-jvp8-xp5w

An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. The server typically logs activity only when a client application specifies that logging is desired. This can be problematic for use cases in a regulated industry, where server-side logging is required in additional situations.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-23w8-jcvm-j4jg

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23w8-fw6w-p2gr

An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-23w7-h454-2fw3

The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to execute code and gain privileges.

CVSS3: 7
0%
Низкий
около 4 лет назад
github логотип
GHSA-23w7-3gw5-5jqr

GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.

CVSS3: 7.8
13%
Средний
около 1 года назад
github логотип
GHSA-23w5-m3rw-wr6g

Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0.

CVSS3: 9.9
16%
Средний
больше 1 года назад
github логотип
GHSA-23w5-4m68-gv63

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: PS). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-23w4-rpc6-wpcc

Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet

0%
Низкий
11 месяцев назад
github логотип
GHSA-23w4-f563-4m2j

A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

2%
Низкий
около 4 лет назад
github логотип
GHSA-23w3-wj92-2gp6

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24521)

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-23w3-pmw9-p5xf

Possible buffer overflow while playing mkv clip due to lack of validation of atom size buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

1%
Низкий
около 4 лет назад
github логотип
GHSA-23w3-3c8p-hvh3

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

CVSS3: 4.8
1%
Низкий
около 1 года назад
github логотип
GHSA-23w2-wmrg-qxqw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded allows Reflected XSS. This issue affects Theme Switcher Reloaded: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-23w2-5h7v-wppv

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Graphics Component RCE Vulnerability."

CVSS3: 8.8
49%
Средний
около 4 лет назад
github логотип
GHSA-23vx-xx4m-jf8w

A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-23vx-2j4v-jvhm

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

CVSS3: 8.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-23vw-mhv5-grv5

Denial of Service in @hapi/hapi

почти 6 лет назад

Уязвимостей на страницу