Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-25rw-qhcc-7gp7

больше 4 лет назад

The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passwords via a direct request for dvr.ini.

EPSS: Низкий
github логотип

GHSA-25rw-g6ff-fmg8

7 месяцев назад

ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-25rw-5w3f-v9vr

больше 4 лет назад

Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25rv-hrr2-4wx8

больше 1 года назад

An authenticated user can modify application state data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25rv-25m9-3rxq

12 дней назад

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25rr-x6m2-gphx

около 2 месяцев назад

Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size validation on untrusted mainDataBegin and nSlots values.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25rr-9xvj-63p7

больше 4 лет назад

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25rq-9fcx-x8f3

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects Wonder Slider Lite: from n/a through 13.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-25rp-rjmq-m7jc

6 месяцев назад

The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-25rp-q786-r55q

больше 4 лет назад

Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25rp-h46x-2hjm

4 месяца назад

SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)

EPSS: Низкий
github логотип

GHSA-25rp-52g6-gv8j

5 месяцев назад

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-25rm-p4h5-753p

больше 3 лет назад

Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-25rm-72cp-x5mm

больше 2 лет назад

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-25rm-3r9j-mwmf

почти 2 года назад

PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24263.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25rj-4799-frmx

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).

EPSS: Низкий
github логотип

GHSA-25rh-cr4w-2wx6

около 1 месяца назад

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

EPSS: Низкий
github логотип

GHSA-25rg-hr6w-2fxx

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social allows Reflected XSS.This issue affects Easy Social: from n/a through 1.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-25rg-cf2m-jvph

больше 4 лет назад

The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-25rg-6fcp-95mq

больше 4 лет назад

Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25rw-qhcc-7gp7

The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing usernames and passwords via a direct request for dvr.ini.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-25rw-g6ff-fmg8

ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication

CVSS3: 8.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-25rw-5w3f-v9vr

Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25rv-hrr2-4wx8

An authenticated user can modify application state data.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-25rv-25m9-3rxq

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
12 дней назад
github логотип
GHSA-25rr-x6m2-gphx

Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size validation on untrusted mainDataBegin and nSlots values.

CVSS3: 7.5
около 2 месяцев назад
github логотип
GHSA-25rr-9xvj-63p7

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25rq-9fcx-x8f3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects Wonder Slider Lite: from n/a through 13.9.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-25rp-rjmq-m7jc

The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-25rp-q786-r55q

Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25rp-h46x-2hjm

SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)

1%
Низкий
4 месяца назад
github логотип
GHSA-25rp-52g6-gv8j

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-25rm-p4h5-753p

Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25rm-72cp-x5mm

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-25rm-3r9j-mwmf

PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24263.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-25rj-4799-frmx

PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).

3%
Низкий
больше 4 лет назад
github логотип
GHSA-25rh-cr4w-2wx6

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

0%
Низкий
около 1 месяца назад
github логотип
GHSA-25rg-hr6w-2fxx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social allows Reflected XSS.This issue affects Easy Social: from n/a through 1.3.

CVSS3: 7.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-25rg-cf2m-jvph

The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-25rg-6fcp-95mq

Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу