Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xqgx-39jh-mw57

больше 4 лет назад

Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages.

EPSS: Низкий
github логотип

GHSA-xqgw-r8h6-587w

почти 4 года назад

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqgw-4rjf-hj4w

около 4 лет назад

Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqgr-r875-ffmc

больше 4 лет назад

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

EPSS: Низкий
github логотип

GHSA-xqgq-x2mp-x49c

больше 4 лет назад

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

EPSS: Низкий
github логотип

GHSA-xqgq-c6mj-rmrj

9 месяцев назад

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqgq-669f-hf3x

около 2 лет назад

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqgq-4wpf-xfr8

почти 3 года назад

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqgm-mm4x-rx9j

около 3 лет назад

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqgm-4493-f736

больше 4 лет назад

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xqgj-v34f-c8hw

около 4 лет назад

IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 845 / SD 850, SD 855, SD 8CX, SDM439, Snapdragon_High_Med_2016, SXR1130

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqgj-r6xv-9cw4

больше 1 года назад

Withdrawn Advisory: Dask Vulnerable to Command Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqgh-qj2v-fjfx

около 4 лет назад

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xqgh-cm65-m6gj

около 4 лет назад

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xqgg-m8mq-7r3c

около 4 лет назад

The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqgg-8qqr-cmpg

около 4 лет назад

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner typo, which is mishandled in the private_size*count multiplication.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqgf-rph5-g5gf

около 4 лет назад

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31750232. References: QC-CR#1082636.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xqgf-mg6r-xcr9

больше 4 лет назад

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xqgc-3m6w-h9jw

около 4 лет назад

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.

EPSS: Низкий
github логотип

GHSA-xqg9-r823-599h

3 месяца назад

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information using automated tools.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqgx-39jh-mw57

Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqgw-r8h6-587w

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqgw-4rjf-hj4w

Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xqgr-r875-ffmc

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqgq-x2mp-x49c

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqgq-c6mj-rmrj

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xqgq-669f-hf3x

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-xqgq-4wpf-xfr8

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xqgm-mm4x-rx9j

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xqgm-4493-f736

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

CVSS3: 9.8
74%
Высокий
больше 4 лет назад
github логотип
GHSA-xqgj-v34f-c8hw

IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 845 / SD 850, SD 855, SD 8CX, SDM439, Snapdragon_High_Med_2016, SXR1130

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqgj-r6xv-9cw4

Withdrawn Advisory: Dask Vulnerable to Command Injection

CVSS3: 9.8
больше 1 года назад
github логотип
GHSA-xqgh-qj2v-fjfx

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CVSS3: 9.8
95%
Критический
около 4 лет назад
github логотип
GHSA-xqgh-cm65-m6gj

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqgg-m8mq-7r3c

The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xqgg-8qqr-cmpg

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner typo, which is mishandled in the private_size*count multiplication.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqgf-rph5-g5gf

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31750232. References: QC-CR#1082636.

CVSS3: 7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqgf-mg6r-xcr9

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqgc-3m6w-h9jw

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqg9-r823-599h

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database information using automated tools.

CVSS3: 7.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу