Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-xqgc-3m6w-h9jw

почти 4 года назад

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.

EPSS: Низкий
github логотип

GHSA-xqg9-jvvp-rh48

почти 4 года назад

Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter.

EPSS: Низкий
github логотип

GHSA-xqg9-hvp9-6pqp

почти 4 года назад

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

EPSS: Средний
github логотип

GHSA-xqg9-33x5-6qjg

почти 4 года назад

ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.

EPSS: Низкий
github логотип

GHSA-xqg8-j998-6rqv

почти 4 года назад

Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.

EPSS: Низкий
github логотип

GHSA-xqg8-fm8q-c2p5

почти 2 года назад

In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xqg8-cv3h-xppv

больше 8 лет назад

SQL Injection in sequelize

EPSS: Низкий
github логотип

GHSA-xqg8-9xv8-w5j8

почти 4 года назад

Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.

EPSS: Низкий
github логотип

GHSA-xqg7-w425-fm4c

почти 4 года назад

Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqg7-m89g-c8qg

почти 4 года назад

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

EPSS: Низкий
github логотип

GHSA-xqg6-prcj-86cv

больше 2 лет назад

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqg6-p6hx-f752

8 дней назад

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqg6-98cw-gxhq

2 месяца назад

Prototype Pollution via FormData Processing in Qwik City

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-xqg5-vgfp-2g7g

около 3 лет назад

Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqg5-r78q-7wrx

7 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration allows Cross Site Request Forgery. This issue affects TrustMate.io – WooCommerce integration: from n/a through 1.14.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqg5-5x64-93r9

около 1 месяца назад

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xqg4-rm9f-hv4c

11 месяцев назад

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/creditor_add.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xqg4-63rp-xhx6

почти 4 года назад

Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqg3-vx4p-jmwm

больше 1 года назад

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

CVSS3: 6.6
EPSS: Средний
github логотип

GHSA-xqg2-r5rv-62x6

почти 4 года назад

Solaris ufsrestore buffer overflow.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqgc-3m6w-h9jw

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqg9-jvvp-rh48

Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqg9-hvp9-6pqp

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

11%
Средний
почти 4 года назад
github логотип
GHSA-xqg9-33x5-6qjg

ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqg8-j998-6rqv

Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqg8-fm8q-c2p5

In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xqg8-cv3h-xppv

SQL Injection in sequelize

0%
Низкий
больше 8 лет назад
github логотип
GHSA-xqg8-9xv8-w5j8

Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqg7-w425-fm4c

Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqg7-m89g-c8qg

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqg6-prcj-86cv

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqg6-p6hx-f752

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.

CVSS3: 7.5
0%
Низкий
8 дней назад
github логотип
GHSA-xqg6-98cw-gxhq

Prototype Pollution via FormData Processing in Qwik City

CVSS3: 9.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xqg5-vgfp-2g7g

Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xqg5-r78q-7wrx

Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration allows Cross Site Request Forgery. This issue affects TrustMate.io – WooCommerce integration: from n/a through 1.14.0.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xqg5-5x64-93r9

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xqg4-rm9f-hv4c

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/creditor_add.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xqg4-63rp-xhx6

Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

CVSS3: 9.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-xqg3-vx4p-jmwm

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

CVSS3: 6.6
33%
Средний
больше 1 года назад
github логотип
GHSA-xqg2-r5rv-62x6

Solaris ufsrestore buffer overflow.

CVSS3: 8.4
1%
Низкий
почти 4 года назад

Уязвимостей на страницу