Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhmp-h8ff-8qf8

около 4 лет назад

The Grocery List - Tomatoes (aka com.meucarrinho) application 5.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xhmp-98v4-42g3

больше 4 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhmp-23cf-gx5x

10 месяцев назад

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xhmm-rp2q-vm34

около 4 лет назад

In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174801970

EPSS: Низкий
github логотип

GHSA-xhmm-6xr8-jx92

12 месяцев назад

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhmj-rg95-44hv

4 месяца назад

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xhmj-4cpg-8x53

больше 3 лет назад

A vulnerability, which was classified as critical, was found in pouetnet pouet 2.0. This affects an unknown part. The manipulation of the argument howmany leads to sql injection. The name of the patch is 11d615931352066fb2f6dcb07428277c2cd99baf. It is recommended to apply a patch to fix this issue. The identifier VDB-217641 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhmj-2p35-gj29

около 4 лет назад

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xhmh-cq7j-qhjr

больше 1 года назад

Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhmh-c6rr-hj3g

около 4 лет назад

The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues

EPSS: Низкий
github логотип

GHSA-xhmg-vv82-6q8v

около 4 лет назад

The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xhmg-v4fj-vm9v

больше 4 лет назад

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote authenticated users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xhmg-mv86-w89p

около 2 лет назад

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 289858.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xhmg-gfj6-x999

больше 4 лет назад

Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.

EPSS: Низкий
github логотип

GHSA-xhmg-fcjg-c5rx

больше 4 лет назад

Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.

EPSS: Низкий
github логотип

GHSA-xhmf-wpj2-g48j

больше 3 лет назад

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238718854References: N/A

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhmf-rvv9-w8mf

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in WS-Proxy in Eye-Fi 1.1.2 allow remote attackers to hijack the authentication of users for requests that modify configuration via a SOAPAction parameter of (1) urn:SetOptions for autostart, (2) urn:SetDesktopSync for file upload, or (3) urn:SetFolderConfig for file download location or modification of authentication credentials; and (4) urn:AddNetwork for adding an arbitrary Service Set Identifier (SSID) to hijack the image upload.

EPSS: Низкий
github логотип

GHSA-xhmf-mmv2-4hhx

почти 4 года назад

Go-CVSS has Out-of-bounds Read vulnerability in ParseVector function

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhmf-jjc9-v9vr

2 месяца назад

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhmc-52r9-p6jh

около 1 года назад

A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhmp-h8ff-8qf8

The Grocery List - Tomatoes (aka com.meucarrinho) application 5.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xhmp-98v4-42g3

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmp-23cf-gx5x

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.

CVSS3: 5.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xhmm-rp2q-vm34

In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174801970

0%
Низкий
около 4 лет назад
github логотип
GHSA-xhmm-6xr8-jx92

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xhmj-rg95-44hv

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xhmj-4cpg-8x53

A vulnerability, which was classified as critical, was found in pouetnet pouet 2.0. This affects an unknown part. The manipulation of the argument howmany leads to sql injection. The name of the patch is 11d615931352066fb2f6dcb07428277c2cd99baf. It is recommended to apply a patch to fix this issue. The identifier VDB-217641 was assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xhmj-2p35-gj29

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xhmh-cq7j-qhjr

Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhmh-c6rr-hj3g

The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhmg-vv82-6q8v

The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhmg-v4fj-vm9v

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote authenticated users to gain privileges via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmg-mv86-w89p

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 289858.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xhmg-gfj6-x999

Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmg-fcjg-c5rx

Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmf-wpj2-g48j

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238718854References: N/A

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xhmf-rvv9-w8mf

Multiple cross-site request forgery (CSRF) vulnerabilities in WS-Proxy in Eye-Fi 1.1.2 allow remote attackers to hijack the authentication of users for requests that modify configuration via a SOAPAction parameter of (1) urn:SetOptions for autostart, (2) urn:SetDesktopSync for file upload, or (3) urn:SetFolderConfig for file download location or modification of authentication credentials; and (4) urn:AddNetwork for adding an arbitrary Service Set Identifier (SSID) to hijack the image upload.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmf-mmv2-4hhx

Go-CVSS has Out-of-bounds Read vulnerability in ParseVector function

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xhmf-jjc9-v9vr

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xhmc-52r9-p6jh

A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад

Уязвимостей на страницу