Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 185

Количество 326 185

github логотип

GHSA-xmqf-c7cr-275p

почти 4 года назад

Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the downloadFileDirectory property, a different vulnerability than CVE-2006-5502.

EPSS: Низкий
github логотип

GHSA-xmqf-6397-gmvx

почти 4 года назад

Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmqc-9cfr-hg4r

около 2 лет назад

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/makehtml_spec.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmq9-qw99-3695

почти 4 года назад

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmq8-c3h6-wf48

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmq7-vcg4-jfj9

почти 4 года назад

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmq7-7fxm-rr79

больше 5 лет назад

Denial of Service in Tensorflow

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmq6-3r6w-66pw

почти 4 года назад

The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmq4-6j6c-v6v5

почти 4 года назад

article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.

EPSS: Низкий
github логотип

GHSA-xmq3-w762-fqmr

почти 4 года назад

The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

EPSS: Низкий
github логотип

GHSA-xmq3-q5pm-rp26

5 месяцев назад

Nuxt DevTools vulnerable to cross-site scripting (XSS)

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-xmq3-hgjx-6997

около 4 лет назад

Cross-site Scripting in Pimcore

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmq3-c6r3-6cm9

11 месяцев назад

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmq2-m5xv-mwcj

почти 4 года назад

u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55

EPSS: Низкий
github логотип

GHSA-xmq2-8hhc-7629

около 1 года назад

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xmq2-3xpw-g24h

почти 4 года назад

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xmpx-2mhf-xq2j

около 1 года назад

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xmpw-v77r-v8qg

5 месяцев назад

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmpv-p68m-37pg

около 4 лет назад

There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.

EPSS: Низкий
github логотип

GHSA-xmpv-j7p2-j873

13 дней назад

Nautobot: Management of users via REST API does not apply configured password validators

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmqf-c7cr-275p

Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the downloadFileDirectory property, a different vulnerability than CVE-2006-5502.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xmqf-6397-gmvx

Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmqc-9cfr-hg4r

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/makehtml_spec.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xmq9-qw99-3695

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmq8-c3h6-wf48

This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xmq7-vcg4-jfj9

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

CVSS3: 6.1
3%
Низкий
почти 4 года назад
github логотип
GHSA-xmq7-7fxm-rr79

Denial of Service in Tensorflow

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-xmq6-3r6w-66pw

The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmq4-6j6c-v6v5

article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmq3-w762-fqmr

The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xmq3-q5pm-rp26

Nuxt DevTools vulnerable to cross-site scripting (XSS)

CVSS3: 6.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-xmq3-hgjx-6997

Cross-site Scripting in Pimcore

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xmq3-c6r3-6cm9

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-xmq2-m5xv-mwcj

u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmq2-8hhc-7629

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xmq2-3xpw-g24h

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmpx-2mhf-xq2j

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

CVSS3: 3.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xmpw-v77r-v8qg

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xmpv-p68m-37pg

There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xmpv-j7p2-j873

Nautobot: Management of users via REST API does not apply configured password validators

CVSS3: 2.7
0%
Низкий
13 дней назад

Уязвимостей на страницу