Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xmq9-qw99-3695

около 4 лет назад

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmq9-mfwm-hg4m

13 дней назад

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `<img src=... onload=...>`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmq8-c3h6-wf48

около 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmq7-vcg4-jfj9

около 4 лет назад

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmq7-7fxm-rr79

почти 6 лет назад

Denial of Service in Tensorflow

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmq6-3r6w-66pw

около 4 лет назад

The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmq4-6j6c-v6v5

больше 4 лет назад

article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.

EPSS: Низкий
github логотип

GHSA-xmq3-w762-fqmr

около 4 лет назад

The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

EPSS: Низкий
github логотип

GHSA-xmq3-q5pm-rp26

9 месяцев назад

Nuxt DevTools vulnerable to cross-site scripting (XSS)

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-xmq3-hgjx-6997

больше 4 лет назад

Cross-site Scripting in Pimcore

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmq3-c6r3-6cm9

около 1 года назад

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmq3-8wcj-rm6p

около 1 месяца назад

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in all versions up to, and including, 4.5.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the attacker to hold a Groundhogg custom role with the view_contacts capability, which is granted by default to several built-in Groundhogg roles above the base subscriber level.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmq2-m5xv-mwcj

около 4 лет назад

u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55

EPSS: Низкий
github логотип

GHSA-xmq2-crj6-vr9m

23 дня назад

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmq2-8hhc-7629

больше 1 года назад

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xmq2-3xpw-g24h

больше 4 лет назад

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xmpx-2mhf-xq2j

больше 1 года назад

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xmpw-v77r-v8qg

9 месяцев назад

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmpw-2vmm-p4p6

3 месяца назад

Malicious code in guardrails-ai 0.10.1 (supply chain compromise)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xmpv-p68m-37pg

больше 4 лет назад

There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmq9-qw99-3695

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmq9-mfwm-hg4m

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `<img src=... onload=...>`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`).

CVSS3: 6.1
0%
Низкий
13 дней назад
github логотип
GHSA-xmq8-c3h6-wf48

This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xmq7-vcg4-jfj9

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xmq7-7fxm-rr79

Denial of Service in Tensorflow

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
github логотип
GHSA-xmq6-3r6w-66pw

The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmq4-6j6c-v6v5

article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmq3-w762-fqmr

The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xmq3-q5pm-rp26

Nuxt DevTools vulnerable to cross-site scripting (XSS)

CVSS3: 6.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-xmq3-hgjx-6997

Cross-site Scripting in Pimcore

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmq3-c6r3-6cm9

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xmq3-8wcj-rm6p

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in all versions up to, and including, 4.5.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the attacker to hold a Groundhogg custom role with the view_contacts capability, which is granted by default to several built-in Groundhogg roles above the base subscriber level.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xmq2-m5xv-mwcj

u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmq2-crj6-vr9m

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

CVSS3: 7.5
0%
Низкий
23 дня назад
github логотип
GHSA-xmq2-8hhc-7629

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmq2-3xpw-g24h

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmpx-2mhf-xq2j

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmpw-v77r-v8qg

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xmpw-2vmm-p4p6

Malicious code in guardrails-ai 0.10.1 (supply chain compromise)

CVSS3: 9.6
0%
Низкий
3 месяца назад
github логотип
GHSA-xmpv-p68m-37pg

There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу