Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-xxhr-3f3g-r47h

около 2 лет назад

In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxhq-69mf-w8cr

около 1 месяца назад

Gogs has an Open Redirect via redirect_to

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxhm-2g3m-gv88

около 4 лет назад

main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxhj-whx7-2xjg

почти 3 года назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxhj-v997-pgq5

11 дней назад

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxhj-c62m-3wgm

4 дня назад

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

EPSS: Низкий
github логотип

GHSA-xxhh-59gh-6ffx

больше 3 лет назад

SAP Cloud SDK for AI Python has OS Command Injection when Program Objects Execution is Enabled

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxhg-xvhq-pmx2

около 4 лет назад

Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xxhg-c875-v6qf

больше 4 лет назад

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

EPSS: Средний
github логотип

GHSA-xxhf-xq6v-c8mj

около 4 лет назад

Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxhf-v2m2-422x

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: sfc: fix TX channel offset when using legacy interrupts In legacy interrupt mode the tx_channel_offset was hardcoded to 1, but that's not correct if efx_sepparate_tx_channels is false. In that case, the offset is 0 because the tx queues are in the single existing channel at index 0, together with the rx queue. Without this fix, as soon as you try to send any traffic, it tries to get the tx queues from an uninitialized channel getting these errors: WARNING: CPU: 1 PID: 0 at drivers/net/ethernet/sfc/tx.c:540 efx_hard_start_xmit+0x12e/0x170 [sfc] [...] RIP: 0010:efx_hard_start_xmit+0x12e/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_start_xmit+0xd7/0x230 sch_direct_xmit+0x9f/0x360 __dev_queue_xmit+0x890/0xa40 [...] BUG: unable to handle kernel NULL pointer dereference at 0000000000000020 [...] RIP: 0010:efx_hard_start_xmit+0x153/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_star...

EPSS: Низкий
github логотип

GHSA-xxhf-rfmq-fqmc

около 4 лет назад

A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxhf-r9rq-5rj8

больше 3 лет назад

Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxhf-g47w-wq3j

7 месяцев назад

Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxhc-wx4f-q7f9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php.

EPSS: Низкий
github логотип

GHSA-xxhc-j59w-qj54

6 месяцев назад

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation. Attackers can submit POST requests to the smoothinfo.cgi endpoint with script payloads in the WRAP or SECTIONTITLE parameters to execute arbitrary JavaScript in victim browsers.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxhc-h629-rhgx

больше 1 года назад

An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xxh9-gmrj-66fq

больше 4 лет назад

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxh9-45q4-7wjc

около 1 года назад

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxh7-j8v2-g57f

3 месяца назад

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxhr-3f3g-r47h

In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxhq-69mf-w8cr

Gogs has an Open Redirect via redirect_to

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxhm-2g3m-gv88

main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xxhj-whx7-2xjg

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxhj-v997-pgq5

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
11 дней назад
github логотип
GHSA-xxhj-c62m-3wgm

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

0%
Низкий
4 дня назад
github логотип
GHSA-xxhh-59gh-6ffx

SAP Cloud SDK for AI Python has OS Command Injection when Program Objects Execution is Enabled

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhg-xvhq-pmx2

Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxhg-c875-v6qf

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

14%
Средний
больше 4 лет назад
github логотип
GHSA-xxhf-xq6v-c8mj

Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxhf-v2m2-422x

In the Linux kernel, the following vulnerability has been resolved: sfc: fix TX channel offset when using legacy interrupts In legacy interrupt mode the tx_channel_offset was hardcoded to 1, but that's not correct if efx_sepparate_tx_channels is false. In that case, the offset is 0 because the tx queues are in the single existing channel at index 0, together with the rx queue. Without this fix, as soon as you try to send any traffic, it tries to get the tx queues from an uninitialized channel getting these errors: WARNING: CPU: 1 PID: 0 at drivers/net/ethernet/sfc/tx.c:540 efx_hard_start_xmit+0x12e/0x170 [sfc] [...] RIP: 0010:efx_hard_start_xmit+0x12e/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_start_xmit+0xd7/0x230 sch_direct_xmit+0x9f/0x360 __dev_queue_xmit+0x890/0xa40 [...] BUG: unable to handle kernel NULL pointer dereference at 0000000000000020 [...] RIP: 0010:efx_hard_start_xmit+0x153/0x170 [sfc] [...] Call Trace: <IRQ> dev_hard_star...

0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxhf-rfmq-fqmc

A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxhf-r9rq-5rj8

Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxhf-g47w-wq3j

Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xxhc-wx4f-q7f9

Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxhc-j59w-qj54

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation. Attackers can submit POST requests to the smoothinfo.cgi endpoint with script payloads in the WRAP or SECTIONTITLE parameters to execute arbitrary JavaScript in victim browsers.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xxhc-h629-rhgx

An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxh9-gmrj-66fq

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxh9-45q4-7wjc

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xxh7-j8v2-g57f

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу