Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgp2-f259-4rjq

больше 4 лет назад

Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

EPSS: Низкий
github логотип

GHSA-xgp2-cc4r-7vf6

почти 6 лет назад

Denial of Service in http-live-simulator

EPSS: Низкий
github логотип

GHSA-xgp2-4cpq-g2m7

больше 4 лет назад

ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xgmx-rr3c-2xgc

больше 4 лет назад

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

EPSS: Средний
github логотип

GHSA-xgmx-j3hv-jh9x

около 2 лет назад

TYPO3 Cross-Site Scripting in Link Handling

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgmx-gwqj-mmc5

больше 4 лет назад

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgmx-762m-r89c

больше 4 лет назад

PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.

EPSS: Низкий
github логотип

GHSA-xgmx-456f-v7hp

около 2 месяцев назад

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgmw-gxmf-fm4w

больше 4 лет назад

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xgmw-g7ph-gfh3

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 400, SD 600, and SD 800, a buffer overflow can occur when processing an audio buffer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgmw-fp9v-9rff

больше 2 лет назад

Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgmv-27h3-874r

около 4 лет назад

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgmv-256h-6689

11 месяцев назад

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xgmr-mh2m-j5vq

больше 2 лет назад

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgmr-hcvf-x3qc

5 дней назад

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xgmq-mgc9-gwfc

6 месяцев назад

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgmp-w3rr-9p7r

больше 4 лет назад

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

EPSS: Низкий
github логотип

GHSA-xgmp-rp9g-wppg

больше 4 лет назад

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

EPSS: Средний
github логотип

GHSA-xgmp-mj76-c47c

больше 4 лет назад

Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.

EPSS: Низкий
github логотип

GHSA-xgmm-vjx3-4m7q

около 4 лет назад

Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgp2-f259-4rjq

Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgp2-cc4r-7vf6

Denial of Service in http-live-simulator

почти 6 лет назад
github логотип
GHSA-xgp2-4cpq-g2m7

ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.

CVSS3: 7.5
26%
Средний
больше 4 лет назад
github логотип
GHSA-xgmx-rr3c-2xgc

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

60%
Средний
больше 4 лет назад
github логотип
GHSA-xgmx-j3hv-jh9x

TYPO3 Cross-Site Scripting in Link Handling

CVSS3: 6.1
около 2 лет назад
github логотип
GHSA-xgmx-gwqj-mmc5

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmx-762m-r89c

PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmx-456f-v7hp

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xgmw-gxmf-fm4w

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

CVSS3: 7.5
39%
Средний
больше 4 лет назад
github логотип
GHSA-xgmw-g7ph-gfh3

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 400, SD 600, and SD 800, a buffer overflow can occur when processing an audio buffer.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmw-fp9v-9rff

Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgmv-27h3-874r

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xgmv-256h-6689

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.

CVSS3: 7.3
1%
Низкий
11 месяцев назад
github логотип
GHSA-xgmr-mh2m-j5vq

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xgmr-hcvf-x3qc

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user.

CVSS3: 6.6
1%
Низкий
5 дней назад
github логотип
GHSA-xgmq-mgc9-gwfc

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xgmp-w3rr-9p7r

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmp-rp9g-wppg

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

13%
Средний
больше 4 лет назад
github логотип
GHSA-xgmp-mj76-c47c

Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgmm-vjx3-4m7q

Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

CVSS3: 9.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу