Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-378v-28hj-76wf

7 месяцев назад

bn.js affected by an infinite loop

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-378r-5qcc-x537

4 месяца назад

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-378r-2hmj-3r7x

больше 1 года назад

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-378r-2ff8-c4pr

15 дней назад

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-378q-m7x3-6f3j

больше 4 лет назад

Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-378q-gq6q-wjhh

почти 4 года назад

timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-378p-j64m-xgm4

больше 4 лет назад

Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-378p-hrq3-x4p3

больше 5 лет назад

Cross-site scripting in Shopizer

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-378p-935f-rmpw

больше 4 лет назад

Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.

EPSS: Средний
github логотип

GHSA-378p-2r6r-m338

больше 1 года назад

A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). The maintenance connection of affected devices fails to protect access to the device's control unit configuration. This could allow an attacker with physical access to the maintenance connection's door port to perform arbitrary configuration changes.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-378m-r762-v3g7

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.

EPSS: Низкий
github логотип

GHSA-378j-qh98-9px6

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-378j-3jfj-8r9f

6 месяцев назад

go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-378h-jm2h-7wrm

около 3 лет назад

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-378h-8fph-fgpg

больше 4 лет назад

IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.

EPSS: Низкий
github логотип

GHSA-378g-wwv2-rpm8

больше 4 лет назад

Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.

EPSS: Средний
github логотип

GHSA-378g-rr79-9cqw

3 месяца назад

Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-378f-jx5r-r547

больше 1 года назад

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions. This makes it possible for unauthenticated attackers to delete arbitrary files, update theme options, export widget options, import widget options, generate backups, restore backups, and reset theme options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-378f-8q54-3fqx

12 месяцев назад

Liferay Portal is vulnerable to Stored XSS through Forms text type field

EPSS: Низкий
github логотип

GHSA-378c-qrcg-vgq7

больше 4 лет назад

A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-378v-28hj-76wf

bn.js affected by an infinite loop

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-378r-5qcc-x537

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

CVSS3: 9
0%
Низкий
4 месяца назад
github логотип
GHSA-378r-2hmj-3r7x

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.

CVSS3: 5
1%
Низкий
больше 1 года назад
github логотип
GHSA-378r-2ff8-c4pr

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

CVSS3: 6.5
0%
Низкий
15 дней назад
github логотип
GHSA-378q-m7x3-6f3j

Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-378q-gq6q-wjhh

timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-378p-j64m-xgm4

Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-378p-hrq3-x4p3

Cross-site scripting in Shopizer

CVSS3: 4.8
3%
Низкий
больше 5 лет назад
github логотип
GHSA-378p-935f-rmpw

Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.

11%
Средний
больше 4 лет назад
github логотип
GHSA-378p-2r6r-m338

A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). The maintenance connection of affected devices fails to protect access to the device's control unit configuration. This could allow an attacker with physical access to the maintenance connection's door port to perform arbitrary configuration changes.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-378m-r762-v3g7

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-378j-qh98-9px6

Multiple cross-site scripting (XSS) vulnerabilities in the Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-378j-3jfj-8r9f

go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers

CVSS3: 6.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-378h-jm2h-7wrm

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-378h-8fph-fgpg

IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-378g-wwv2-rpm8

Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.

66%
Средний
больше 4 лет назад
github логотип
GHSA-378g-rr79-9cqw

Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-378f-jx5r-r547

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions. This makes it possible for unauthenticated attackers to delete arbitrary files, update theme options, export widget options, import widget options, generate backups, restore backups, and reset theme options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-378f-8q54-3fqx

Liferay Portal is vulnerable to Stored XSS through Forms text type field

0%
Низкий
12 месяцев назад
github логотип
GHSA-378c-qrcg-vgq7

A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу