Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-xxh9-gmrj-66fq

больше 4 лет назад

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxh9-45q4-7wjc

около 1 года назад

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxh7-m6m8-7839

14 дней назад

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxh7-j8v2-g57f

4 месяца назад

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxh7-fcf3-rj7f

7 месяцев назад

The Eclipse Jetty Server Artifact has a Gzip request memory leak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxh7-3px8-x367

больше 3 лет назад

A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. Affected by this issue is some unknown functionality of the file services/view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227702 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxh6-f3x3-2xgf

больше 3 лет назад

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxh6-2g83-jp5x

8 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxh5-92qj-c4gh

больше 4 лет назад

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxh4-gjrf-3883

больше 4 лет назад

Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.

EPSS: Низкий
github логотип

GHSA-xxh4-727v-gjcv

около 1 года назад

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVSS3: 8
EPSS: Высокий
github логотип

GHSA-xxh4-4cw5-j7pm

1 день назад

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxh4-49r4-6rx5

больше 4 лет назад

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxh2-qf6g-36xp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.

EPSS: Низкий
github логотип

GHSA-xxh2-9vx8-x442

около 1 года назад

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxh2-68g9-8jqr

7 месяцев назад

ormar is vulnerable to SQL Injection through aggregate functions min() and max()

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxh2-5857-h7jc

9 месяцев назад

Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.50.07.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxgx-x42c-j7x8

6 месяцев назад

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xxgx-gq2c-x92j

больше 4 лет назад

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxgx-ggrx-m55g

больше 4 лет назад

In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-129475100

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxh9-gmrj-66fq

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxh9-45q4-7wjc

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram: from n/a through 1.0.4.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xxh7-m6m8-7839

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

CVSS3: 5.4
0%
Низкий
14 дней назад
github логотип
GHSA-xxh7-j8v2-g57f

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xxh7-fcf3-rj7f

The Eclipse Jetty Server Artifact has a Gzip request memory leak

CVSS3: 7.5
1%
Низкий
7 месяцев назад
github логотип
GHSA-xxh7-3px8-x367

A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. Affected by this issue is some unknown functionality of the file services/view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227702 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxh6-f3x3-2xgf

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxh6-2g83-jp5x

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xxh5-92qj-c4gh

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxh4-gjrf-3883

Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxh4-727v-gjcv

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVSS3: 8
77%
Высокий
около 1 года назад
github логотип
GHSA-xxh4-4cw5-j7pm

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.

CVSS3: 4.3
1 день назад
github логотип
GHSA-xxh4-49r4-6rx5

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxh2-qf6g-36xp

Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxh2-9vx8-x442

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xxh2-68g9-8jqr

ormar is vulnerable to SQL Injection through aggregate functions min() and max()

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-xxh2-5857-h7jc

Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.50.07.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xxgx-x42c-j7x8

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

CVSS3: 6.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-xxgx-gq2c-x92j

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxgx-ggrx-m55g

In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-129475100

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу