Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq2v-ff2j-6gfv

около 4 лет назад

HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xq2v-cc3g-cmw3

больше 1 года назад

Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq2v-8qf4-3rg6

около 1 месяца назад

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and uses `strpos()` to check if a filename contains a configured extension string, rather than verifying the actual file extension. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files (including PHP) on the affected site's server which may make remote code execution possible, granted the "Enhanced Multi-Format Image Support" feature is enabled with at least one extension (e.g., avif) in the allowed formats.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq2q-rgqf-8r75

больше 1 года назад

A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq2q-96g9-r4pc

около 4 лет назад

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2q-8hxc-7jr2

около 4 лет назад

XXE vulnerability in Jenkins Valgrind Plugin

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq2p-cgwj-87m3

около 4 лет назад

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.

EPSS: Средний
github логотип

GHSA-xq2p-83g5-rqxp

7 месяцев назад

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2m-jgm3-gpjw

больше 4 лет назад

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

EPSS: Средний
github логотип

GHSA-xq2m-h4jc-ghmf

6 месяцев назад

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq2m-9f8c-rr6w

больше 4 лет назад

LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

EPSS: Низкий
github логотип

GHSA-xq2j-fg32-wv9c

около 4 лет назад

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq2j-2jwj-gfcq

больше 1 года назад

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2h-vm9v-fgph

больше 2 лет назад

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xq2h-p299-vjwv

5 месяцев назад

Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade

EPSS: Низкий
github логотип

GHSA-xq2h-7fp3-456v

больше 1 года назад

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xq2h-74x7-89f4

около 4 лет назад

Windows DNS Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq2g-qh2c-29p8

9 месяцев назад

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xq2g-73fq-x4mq

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq2f-wvpp-9qrx

2 месяца назад

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq2v-ff2j-6gfv

HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."

CVSS3: 7.5
29%
Средний
около 4 лет назад
github логотип
GHSA-xq2v-cc3g-cmw3

Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.

CVSS3: 7.8
больше 1 года назад
github логотип
GHSA-xq2v-8qf4-3rg6

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and uses `strpos()` to check if a filename contains a configured extension string, rather than verifying the actual file extension. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files (including PHP) on the affected site's server which may make remote code execution possible, granted the "Enhanced Multi-Format Image Support" feature is enabled with at least one extension (e.g., avif) in the allowed formats.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-xq2q-rgqf-8r75

A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq2q-96g9-r4pc

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xq2q-8hxc-7jr2

XXE vulnerability in Jenkins Valgrind Plugin

CVSS3: 7.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq2p-cgwj-87m3

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.

51%
Средний
около 4 лет назад
github логотип
GHSA-xq2p-83g5-rqxp

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-xq2m-jgm3-gpjw

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

13%
Средний
больше 4 лет назад
github логотип
GHSA-xq2m-h4jc-ghmf

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xq2m-9f8c-rr6w

LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq2j-fg32-wv9c

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq2j-2jwj-gfcq

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-xq2h-vm9v-fgph

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq2h-p299-vjwv

Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade

1%
Низкий
5 месяцев назад
github логотип
GHSA-xq2h-7fp3-456v

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq2h-74x7-89f4

Windows DNS Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq2g-qh2c-29p8

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xq2g-73fq-x4mq

Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-xq2f-wvpp-9qrx

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS3: 9.6
2%
Низкий
2 месяца назад

Уязвимостей на страницу