Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xmvx-xxj4-g48f

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmvx-vh6j-5wm2

около 4 лет назад

A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmvw-m3jj-qhfh

около 4 лет назад

The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xmvv-w44w-j8wx

больше 1 года назад

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xmvv-4vx6-5fqj

больше 4 лет назад

The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.

EPSS: Низкий
github логотип

GHSA-xmvq-j2gc-q94f

больше 4 лет назад

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmvq-76g8-6jhm

27 дней назад

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xmvq-5949-6227

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: habanalabs/gaudi: Fix a potential use after free in gaudi_memset_device_memory Our code analyzer reported a uaf. In gaudi_memset_device_memory, cb is get via hl_cb_kernel_create() with 2 refcount. If hl_cs_allocate_job() failed, the execution runs into release_cb branch. One ref of cb is dropped by hl_cb_put(cb) and could be freed if other thread also drops one ref. Then cb is used by cb->id later, which is a potential uaf. My patch add a variable 'id' to accept the value of cb->id before the hl_cb_put(cb) is called, to avoid the potential uaf.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmvp-p4p2-hprq

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmvp-3p7r-g4vm

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Webriti WordPress Themes & Plugins Shop Webriti Custom Login allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through 0.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xmvm-x7m2-gg4f

около 4 лет назад

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

EPSS: Низкий
github логотип

GHSA-xmvm-rgp2-5wfw

9 месяцев назад

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by an authenticated user, will automatically submit a forged POST request to the vulnerable endpoint. This request will be executed with the victim's privileges, allowing the attacker to perform unauthorized actions on their behalf, such as sending arbitrary messages in any chat room.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmvm-48fw-3ghc

около 4 лет назад

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering, which allows remote attackers to cause a denial of service (memory consumption) via a crafted attachment in an e-mail message, aka Bug ID CSCuv47151.

EPSS: Низкий
github логотип

GHSA-xmvj-jc33-3vmf

больше 4 лет назад

Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmvh-vfr8-8rq2

около 4 лет назад

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."

CVSS3: 3.1
EPSS: Средний
github логотип

GHSA-xmvh-m2j6-pff4

больше 4 лет назад

Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.

EPSS: Низкий
github логотип

GHSA-xmvg-w4f9-99r7

больше 7 лет назад

XML External Entity (XXE) vulnerability in bw-calendar-engine

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xmvg-c4x3-9qwp

больше 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xmvg-335g-x44q

около 2 лет назад

The OpenSearch reporting plugin improperly controls tenancy access to reporting resources

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmvf-wm3q-gh2f

около 2 лет назад

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmvx-xxj4-g48f

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xmvx-vh6j-5wm2

A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xmvw-m3jj-qhfh

The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xmvv-w44w-j8wx

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmvv-4vx6-5fqj

The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xmvq-j2gc-q94f

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xmvq-76g8-6jhm

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

CVSS3: 5
0%
Низкий
27 дней назад
github логотип
GHSA-xmvq-5949-6227

In the Linux kernel, the following vulnerability has been resolved: habanalabs/gaudi: Fix a potential use after free in gaudi_memset_device_memory Our code analyzer reported a uaf. In gaudi_memset_device_memory, cb is get via hl_cb_kernel_create() with 2 refcount. If hl_cs_allocate_job() failed, the execution runs into release_cb branch. One ref of cb is dropped by hl_cb_put(cb) and could be freed if other thread also drops one ref. Then cb is used by cb->id later, which is a potential uaf. My patch add a variable 'id' to accept the value of cb->id before the hl_cb_put(cb) is called, to avoid the potential uaf.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmvp-p4p2-hprq

Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xmvp-3p7r-g4vm

Cross-Site Request Forgery (CSRF) vulnerability in Webriti WordPress Themes & Plugins Shop Webriti Custom Login allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through 0.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmvm-x7m2-gg4f

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

8%
Низкий
около 4 лет назад
github логотип
GHSA-xmvm-rgp2-5wfw

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by an authenticated user, will automatically submit a forged POST request to the vulnerable endpoint. This request will be executed with the victim's privileges, allowing the attacker to perform unauthorized actions on their behalf, such as sending arbitrary messages in any chat room.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xmvm-48fw-3ghc

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering, which allows remote attackers to cause a denial of service (memory consumption) via a crafted attachment in an e-mail message, aka Bug ID CSCuv47151.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmvj-jc33-3vmf

Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmvh-vfr8-8rq2

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."

CVSS3: 3.1
12%
Средний
около 4 лет назад
github логотип
GHSA-xmvh-m2j6-pff4

Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-xmvg-w4f9-99r7

XML External Entity (XXE) vulnerability in bw-calendar-engine

CVSS3: 9
1%
Низкий
больше 7 лет назад
github логотип
GHSA-xmvg-c4x3-9qwp

ChakraCore RCE Vulnerability

CVSS3: 7.5
67%
Средний
больше 4 лет назад
github логотип
GHSA-xmvg-335g-x44q

The OpenSearch reporting plugin improperly controls tenancy access to reporting resources

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xmvf-wm3q-gh2f

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.

CVSS3: 9.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу