Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-xqh2-p25v-rv7v

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Alter plugin <= 1.0 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqgx-493j-vhxr

почти 4 года назад

Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.

EPSS: Низкий
github логотип

GHSA-xqgx-39jh-mw57

почти 4 года назад

Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages.

EPSS: Низкий
github логотип

GHSA-xqgw-r8h6-587w

больше 3 лет назад

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqgw-4rjf-hj4w

почти 4 года назад

Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqgr-r875-ffmc

почти 4 года назад

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

EPSS: Низкий
github логотип

GHSA-xqgq-x2mp-x49c

почти 4 года назад

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

EPSS: Низкий
github логотип

GHSA-xqgq-c6mj-rmrj

5 месяцев назад

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqgq-669f-hf3x

почти 2 года назад

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqgq-4wpf-xfr8

больше 2 лет назад

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqgm-mm4x-rx9j

больше 2 лет назад

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqgm-4493-f736

почти 4 года назад

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xqgj-v34f-c8hw

почти 4 года назад

IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 845 / SD 850, SD 855, SD 8CX, SDM439, Snapdragon_High_Med_2016, SXR1130

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqgj-r6xv-9cw4

около 1 года назад

Withdrawn Advisory: Dask Vulnerable to Command Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqgh-qj2v-fjfx

почти 4 года назад

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xqgh-cm65-m6gj

почти 4 года назад

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xqgg-m8mq-7r3c

почти 4 года назад

The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqgg-8qqr-cmpg

почти 4 года назад

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner typo, which is mishandled in the private_size*count multiplication.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqgf-rph5-g5gf

почти 4 года назад

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31750232. References: QC-CR#1082636.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xqgf-mg6r-xcr9

почти 4 года назад

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqh2-p25v-rv7v

Cross-Site Request Forgery (CSRF) vulnerability in Alter plugin <= 1.0 versions.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqgx-493j-vhxr

Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xqgx-39jh-mw57

Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqgw-r8h6-587w

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xqgw-4rjf-hj4w

Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.

CVSS3: 7.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-xqgr-r875-ffmc

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqgq-x2mp-x49c

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqgq-c6mj-rmrj

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xqgq-669f-hf3x

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
2%
Низкий
почти 2 года назад
github логотип
GHSA-xqgq-4wpf-xfr8

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqgm-mm4x-rx9j

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqgm-4493-f736

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

CVSS3: 9.8
90%
Критический
почти 4 года назад
github логотип
GHSA-xqgj-v34f-c8hw

IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 845 / SD 850, SD 855, SD 8CX, SDM439, Snapdragon_High_Med_2016, SXR1130

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqgj-r6xv-9cw4

Withdrawn Advisory: Dask Vulnerable to Command Injection

CVSS3: 9.8
около 1 года назад
github логотип
GHSA-xqgh-qj2v-fjfx

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CVSS3: 9.8
94%
Критический
почти 4 года назад
github логотип
GHSA-xqgh-cm65-m6gj

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqgg-m8mq-7r3c

The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqgg-8qqr-cmpg

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner typo, which is mishandled in the private_size*count multiplication.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqgf-rph5-g5gf

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31750232. References: QC-CR#1082636.

CVSS3: 7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqgf-mg6r-xcr9

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу