Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xh9h-692f-mmg4

12 месяцев назад

Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module

EPSS: Низкий
github логотип

GHSA-xh9g-cqwj-6chj

больше 4 лет назад

SPBAS Business Automation Software 2012 has XSS.

EPSS: Низкий
github логотип

GHSA-xh9g-cp3v-p8q4

больше 4 лет назад

Missing Authorization in Crater Invoice

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh9g-5fg8-p3wh

около 4 лет назад

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition.

EPSS: Низкий
github логотип

GHSA-xh9c-vcf9-h94m

больше 2 лет назад

Jenkins Git server Plugin does not perform a permission check

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh9c-cqj7-g26j

больше 4 лет назад

Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh9c-76xx-xhrp

больше 4 лет назад

Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.

EPSS: Низкий
github логотип

GHSA-xh99-hw7h-wf63

больше 4 лет назад

Unchecked validity of Facing values in PlayerActionPacket

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh98-xq72-x84p

больше 4 лет назад

SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xh98-rwp8-8rpw

почти 2 года назад

An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xh98-g799-3775

больше 4 лет назад

The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

EPSS: Низкий
github логотип

GHSA-xh97-fh55-wr34

больше 1 года назад

Missing Authorization vulnerability in turitop TuriTop Booking System allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TuriTop Booking System: from n/a through 1.0.10.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh97-73h5-gfm9

больше 4 лет назад

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh97-72ww-2w58

больше 4 лет назад

Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xh96-vq46-m9ww

почти 2 года назад

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xh96-q52c-cw5m

больше 4 лет назад

S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh96-g262-xhpr

почти 3 года назад

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh96-fgxf-4776

5 месяцев назад

Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh96-5xc9-3w5h

больше 4 лет назад

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.

EPSS: Низкий
github логотип

GHSA-xh95-j7j4-ghg2

3 месяца назад

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh9h-692f-mmg4

Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module

0%
Низкий
12 месяцев назад
github логотип
GHSA-xh9g-cqwj-6chj

SPBAS Business Automation Software 2012 has XSS.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9g-cp3v-p8q4

Missing Authorization in Crater Invoice

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9g-5fg8-p3wh

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh9c-vcf9-h94m

Jenkins Git server Plugin does not perform a permission check

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh9c-cqj7-g26j

Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9c-76xx-xhrp

Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xh99-hw7h-wf63

Unchecked validity of Facing values in PlayerActionPacket

CVSS3: 7.5
больше 4 лет назад
github логотип
GHSA-xh98-xq72-x84p

SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh98-rwp8-8rpw

An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xh98-g799-3775

The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh97-fh55-wr34

Missing Authorization vulnerability in turitop TuriTop Booking System allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TuriTop Booking System: from n/a through 1.0.10.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh97-73h5-gfm9

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh97-72ww-2w58

Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client

CVSS3: 7.3
больше 4 лет назад
github логотип
GHSA-xh96-vq46-m9ww

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

CVSS3: 8.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-xh96-q52c-cw5m

S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh96-g262-xhpr

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xh96-fgxf-4776

Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xh96-5xc9-3w5h

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xh95-j7j4-ghg2

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу