Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh6j-pwvm-gcgm

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager allows Reflected XSS. This issue affects Affiliate Links Manager: from n/a through 1.0.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xh6j-j322-g8m3

около 4 лет назад

, aka 'Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh6j-gj5f-hrpp

около 4 лет назад

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xh6g-prc3-64gx

больше 4 лет назад

Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.

EPSS: Низкий
github логотип

GHSA-xh6g-hp9w-9662

около 4 лет назад

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.

EPSS: Низкий
github логотип

GHSA-xh69-9jx5-xgph

больше 1 года назад

Windows Active Directory Domain Services API Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh69-9chv-wc4v

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Földesi, Mihály Széchenyi 2020 Logo allows PHP Local File Inclusion. This issue affects Széchenyi 2020 Logo: from n/a through 1.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh69-987w-hrp8

около 1 года назад

resolv vulnerable to DoS via insufficient DNS domain name length validation

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh68-hfp5-5x5m

2 месяца назад

daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xh68-gx4p-f4cx

больше 4 лет назад

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.

EPSS: Низкий
github логотип

GHSA-xh68-c6f3-2hjc

11 месяцев назад

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh67-rj29-r547

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xh67-8c9c-jwgx

около 1 года назад

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh66-6mj6-94rg

больше 4 лет назад

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh66-6hj7-62mw

около 4 лет назад

An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory, aka 'Active Directory Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0856.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh65-fv62-6rcf

больше 4 лет назад

Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02.

EPSS: Низкий
github логотип

GHSA-xh64-rxr5-8ggh

около 1 месяца назад

The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.

EPSS: Низкий
github логотип

GHSA-xh64-rg4w-vmpm

больше 4 лет назад

Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.

EPSS: Низкий
github логотип

GHSA-xh64-jjg2-744m

больше 4 лет назад

Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xh64-ffcx-p82v

около 3 лет назад

Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh6j-pwvm-gcgm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager allows Reflected XSS. This issue affects Affiliate Links Manager: from n/a through 1.0.

CVSS3: 5.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh6j-j322-g8m3

, aka 'Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability'.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xh6j-gj5f-hrpp

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

CVSS3: 9.8
53%
Средний
около 4 лет назад
github логотип
GHSA-xh6g-prc3-64gx

Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh6g-hp9w-9662

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh69-9jx5-xgph

Windows Active Directory Domain Services API Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-xh69-9chv-wc4v

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Földesi, Mihály Széchenyi 2020 Logo allows PHP Local File Inclusion. This issue affects Széchenyi 2020 Logo: from n/a through 1.1.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xh69-987w-hrp8

resolv vulnerable to DoS via insufficient DNS domain name length validation

CVSS3: 5.3
1%
Низкий
около 1 года назад
github логотип
GHSA-xh68-hfp5-5x5m

daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators

CVSS3: 3.7
0%
Низкий
2 месяца назад
github логотип
GHSA-xh68-gx4p-f4cx

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh68-c6f3-2hjc

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xh67-rj29-r547

Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh67-8c9c-jwgx

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xh66-6mj6-94rg

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh66-6hj7-62mw

An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory, aka 'Active Directory Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0856.

CVSS3: 6.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xh65-fv62-6rcf

Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xh64-rxr5-8ggh

The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xh64-rg4w-vmpm

Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh64-jjg2-744m

Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh64-ffcx-p82v

Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу