Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xhw2-xhmj-qmw7

5 месяцев назад

Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xhw2-2448-gp38

больше 4 лет назад

Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."

EPSS: Низкий
github логотип

GHSA-xhvx-fprp-87jr

больше 4 лет назад

In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhvx-9w5h-q8q6

около 1 года назад

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhvx-6vm7-468w

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

EPSS: Низкий
github логотип

GHSA-xhvw-7r48-hpxr

больше 4 лет назад

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhvw-36mm-785h

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.

EPSS: Низкий
github логотип

GHSA-xhvw-2w3w-fwpc

11 месяцев назад

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhvv-3jww-c487

больше 2 лет назад

ActiveAdmin CSV Injection leading to sensitive information disclosure

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xhvr-qq82-mmqx

около 4 лет назад

An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhvr-qpr3-6jfg

5 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xhvq-7mc2-jx9w

около 2 лет назад

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xhvp-6rv7-fw9x

около 3 лет назад

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhvm-w5fj-p25w

больше 4 лет назад

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhvm-vfp7-h7mh

7 месяцев назад

Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhvm-q4fr-5m4f

больше 4 лет назад

In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhvm-m8qv-p64r

почти 3 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhvj-h5pc-rgrw

больше 4 лет назад

Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.

EPSS: Низкий
github логотип

GHSA-xhvg-qmw2-rr5r

больше 4 лет назад

A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhvg-mcp8-54f9

больше 4 лет назад

SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhw2-xhmj-qmw7

Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xhw2-2448-gp38

Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvx-fprp-87jr

In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvx-9w5h-q8q6

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVSS3: 6.5
1%
Низкий
около 1 года назад
github логотип
GHSA-xhvx-6vm7-468w

Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvw-7r48-hpxr

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvw-36mm-785h

Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvw-2w3w-fwpc

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xhvv-3jww-c487

ActiveAdmin CSV Injection leading to sensitive information disclosure

CVSS3: 5.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xhvr-qq82-mmqx

An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhvr-qpr3-6jfg

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-xhvq-7mc2-jx9w

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

CVSS3: 8.3
3%
Низкий
около 2 лет назад
github логотип
GHSA-xhvp-6rv7-fw9x

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhvm-w5fj-p25w

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvm-vfp7-h7mh

Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xhvm-q4fr-5m4f

In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvm-m8qv-p64r

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xhvj-h5pc-rgrw

Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvg-qmw2-rr5r

A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhvg-mcp8-54f9

SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу