Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-2284-5wv4-383m

около 4 лет назад

Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

EPSS: Низкий
github логотип

GHSA-2284-2gj7-8cqv

около 4 лет назад

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-2283-wf8c-rw8r

3 месяца назад

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2282-g5x7-q386

около 1 года назад

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component CCC Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2282-f329-v64x

около 4 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-2282-4ccr-wfvx

больше 1 года назад

The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-227x-w5qv-2294

около 4 лет назад

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

EPSS: Низкий
github логотип

GHSA-227x-7mh8-3cf6

10 месяцев назад

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-227x-6m74-5g32

больше 3 лет назад

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227x-48c5-2jpf

около 4 лет назад

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

EPSS: Низкий
github логотип

GHSA-227w-xh58-rx2j

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

EPSS: Низкий
github логотип

GHSA-227w-wv4j-67h4

больше 4 лет назад

Class Loading Vulnerability in Artemis

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-227w-82c7-87qx

около 4 лет назад

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-227v-w3r6-6vc4

около 4 лет назад

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-227v-m6p6-j6gx

больше 2 лет назад

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-227r-w5j2-6243

больше 1 года назад

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-227r-vmhh-jq3x

8 месяцев назад

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

EPSS: Низкий
github логотип

GHSA-227r-jm2g-7cp4

29 дней назад

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-227r-cc3q-mh85

около 4 лет назад

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-227p-wwrh-m869

5 месяцев назад

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2284-5wv4-383m

Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2284-2gj7-8cqv

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."

14%
Средний
около 4 лет назад
github логотип
GHSA-2283-wf8c-rw8r

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-2282-g5x7-q386

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component CCC Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
около 1 года назад
github логотип
GHSA-2282-f329-v64x

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

0%
Низкий
около 4 лет назад
github логотип
GHSA-2282-4ccr-wfvx

The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-227x-w5qv-2294

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

2%
Низкий
около 4 лет назад
github логотип
GHSA-227x-7mh8-3cf6

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning

CVSS3: 9.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-227x-6m74-5g32

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-227x-48c5-2jpf

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-227w-xh58-rx2j

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

1%
Низкий
около 4 лет назад
github логотип
GHSA-227w-wv4j-67h4

Class Loading Vulnerability in Artemis

CVSS3: 8.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-227w-82c7-87qx

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

2%
Низкий
около 4 лет назад
github логотип
GHSA-227v-w3r6-6vc4

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-227v-m6p6-j6gx

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-227r-w5j2-6243

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-227r-vmhh-jq3x

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

0%
Низкий
8 месяцев назад
github логотип
GHSA-227r-jm2g-7cp4

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

CVSS3: 6.5
0%
Низкий
29 дней назад
github логотип
GHSA-227r-cc3q-mh85

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
3%
Низкий
около 4 лет назад
github логотип
GHSA-227p-wwrh-m869

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

CVSS3: 9.8
1%
Низкий
5 месяцев назад

Уязвимостей на страницу