Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35w6-wm82-6c6f

2 месяца назад

HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-35w6-mr78-cpr4

больше 4 лет назад

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4609, CVE-2016-4610, and CVE-2016-4612.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35w6-5w7x-9wf8

8 месяцев назад

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35w5-r2hj-w7cv

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.

EPSS: Низкий
github логотип

GHSA-35w5-pcw4-jx94

3 месяца назад

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35w5-h9v9-m2qp

почти 2 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Vasilis Kerasiotis Affiliator allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through 2.1.3.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-35w5-c9v9-6575

12 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS. This issue affects WP Content Protection: from n/a through 1.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35w5-2xwx-jpp4

больше 4 лет назад

HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.

EPSS: Низкий
github логотип

GHSA-35w4-w34h-84qw

больше 4 лет назад

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35w4-5hgf-f56q

больше 3 лет назад

An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local storage after logout.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35w3-pjm6-wj95

3 месяца назад

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

EPSS: Низкий
github логотип

GHSA-35w3-9295-x8r4

больше 4 лет назад

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-35w3-85xv-8x6w

больше 4 лет назад

WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.

EPSS: Низкий
github логотип

GHSA-35w3-6qhc-474v

больше 2 лет назад

@workos-inc/authkit-nextjs session replay vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-35w2-q5f9-8244

около 1 года назад

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be done within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35w2-gj48-j2p3

3 месяца назад

A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-35w2-fcvf-666f

больше 4 лет назад

The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-35vx-vx6v-j9x7

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35vx-q8fx-9jg2

больше 4 лет назад

Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

EPSS: Низкий
github логотип

GHSA-35vv-xp9m-c452

больше 4 лет назад

An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35w6-wm82-6c6f

HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.

CVSS3: 3.1
0%
Низкий
2 месяца назад
github логотип
GHSA-35w6-mr78-cpr4

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4609, CVE-2016-4610, and CVE-2016-4612.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-35w6-5w7x-9wf8

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-35w5-r2hj-w7cv

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35w5-pcw4-jx94

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-35w5-h9v9-m2qp

Unrestricted Upload of File with Dangerous Type vulnerability in Vasilis Kerasiotis Affiliator allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through 2.1.3.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-35w5-c9v9-6575

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS. This issue affects WP Content Protection: from n/a through 1.3.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-35w5-2xwx-jpp4

HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35w4-w34h-84qw

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

CVSS3: 7.2
5%
Низкий
больше 4 лет назад
github логотип
GHSA-35w4-5hgf-f56q

An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local storage after logout.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35w3-pjm6-wj95

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

0%
Низкий
3 месяца назад
github логотип
GHSA-35w3-9295-x8r4

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35w3-85xv-8x6w

WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35w3-6qhc-474v

@workos-inc/authkit-nextjs session replay vulnerability

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35w2-q5f9-8244

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be done within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
1%
Низкий
около 1 года назад
github логотип
GHSA-35w2-gj48-j2p3

A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-35w2-fcvf-666f

The portal in IBM Tealeaf Customer Experience before 8.7.1.8814, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary charts by specifying an internal chart name.

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35vx-vx6v-j9x7

Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35vx-q8fx-9jg2

Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vv-xp9m-c452

An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу