Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35jp-8cgg-p4wj

около 2 лет назад

Shopware vulnerable to Server Side Template Injection in Twig using Context functions

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-35jp-44cx-hw36

больше 4 лет назад

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35jm-rm2f-hpgj

около 1 месяца назад

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-35jm-qwg4-c8wj

около 1 года назад

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35jj-wx47-4w8r

больше 2 лет назад

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-35jj-vqcf-f2jf

больше 3 лет назад

Hidden fields can be leaked on readable collections in Payload

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-35jj-h5xp-mhvc

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35jj-9635-2vjm

больше 4 лет назад

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

EPSS: Низкий
github логотип

GHSA-35jj-42hp-8gmq

9 дней назад

n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

EPSS: Низкий
github логотип

GHSA-35jh-r3h4-6jhm

больше 5 лет назад

Command Injection in lodash

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-35jh-p5wf-6gg4

больше 4 лет назад

Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

EPSS: Низкий
github логотип

GHSA-35jh-g8qg-jgf5

больше 4 лет назад

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

EPSS: Низкий
github логотип

GHSA-35jh-78c5-6rfj

больше 4 лет назад

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35jh-65jp-wj73

больше 4 лет назад

Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35jh-2r79-5r66

больше 4 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-35jg-8pwm-5q3v

больше 4 лет назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

EPSS: Низкий
github логотип

GHSA-35jf-jfrv-9p25

около 4 лет назад

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35jf-fw8j-m7v3

больше 4 лет назад

Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

EPSS: Низкий
github логотип

GHSA-35jc-cjp6-54c4

больше 4 лет назад

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35jc-5h4r-p9cg

4 месяца назад

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35jp-8cgg-p4wj

Shopware vulnerable to Server Side Template Injection in Twig using Context functions

CVSS3: 8.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-35jp-44cx-hw36

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35jm-rm2f-hpgj

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.

CVSS3: 7.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-35jm-qwg4-c8wj

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-35jj-wx47-4w8r

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

CVSS3: 7.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35jj-vqcf-f2jf

Hidden fields can be leaked on readable collections in Payload

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35jj-h5xp-mhvc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-35jj-9635-2vjm

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-35jj-42hp-8gmq

n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

0%
Низкий
9 дней назад
github логотип
GHSA-35jh-r3h4-6jhm

Command Injection in lodash

CVSS3: 7.2
21%
Средний
больше 5 лет назад
github логотип
GHSA-35jh-p5wf-6gg4

Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35jh-g8qg-jgf5

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-35jh-78c5-6rfj

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35jh-65jp-wj73

Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-35jh-2r79-5r66

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVSS3: 7.5
87%
Высокий
больше 4 лет назад
github логотип
GHSA-35jg-8pwm-5q3v

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35jf-jfrv-9p25

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-35jf-fw8j-m7v3

Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35jc-cjp6-54c4

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35jc-5h4r-p9cg

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу