Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 567

Количество 359 567

github логотип

GHSA-xgm3-c7j6-6pf4

8 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xgm3-c263-cjqp

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

EPSS: Низкий
github логотип

GHSA-xgm2-cpgm-525v

больше 2 лет назад

ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-xgm2-c6j6-q2v6

около 3 лет назад

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgm2-9pcq-75hg

больше 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xgm2-6pvq-chh4

больше 4 лет назад

MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.

EPSS: Низкий
github логотип

GHSA-xgm2-5f3f-mvvc

29 дней назад

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xgjx-9p2f-rwjw

около 1 года назад

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgjx-96v4-mqxx

больше 4 лет назад

Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xgjw-vr88-rxg7

больше 3 лет назад

Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgjw-pm74-86q4

около 2 месяцев назад

sigstore-js has Insufficient Verification of Data Authenticity

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgjv-9929-vw26

почти 2 года назад

Loftware Spectrum through 4.6 has unprotected JMX Registry.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgjv-6gmp-cprw

больше 4 лет назад

PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.

EPSS: Низкий
github логотип

GHSA-xgjv-46p6-hwgv

10 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgjq-gf22-rvwq

13 дней назад

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgjq-frv6-vjfh

11 месяцев назад

A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgjp-hj9v-xx75

около 1 года назад

A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgjm-w63f-4hqq

больше 2 лет назад

Windows Compressed Folder Tampering Vulnerability

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xgjm-4322-4ccq

около 1 месяца назад

CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xgjj-x9g2-jxw7

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgm3-c7j6-6pf4

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

8 месяцев назад
github логотип
GHSA-xgm3-c263-cjqp

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xgm2-cpgm-525v

ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting.

CVSS3: 2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgm2-c6j6-q2v6

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xgm2-9pcq-75hg

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xgm2-6pvq-chh4

MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xgm2-5f3f-mvvc

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

CVSS3: 4.8
0%
Низкий
29 дней назад
github логотип
GHSA-xgjx-9p2f-rwjw

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xgjx-96v4-mqxx

Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection

CVSS3: 7.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgjw-vr88-rxg7

Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xgjw-pm74-86q4

sigstore-js has Insufficient Verification of Data Authenticity

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xgjv-9929-vw26

Loftware Spectrum through 4.6 has unprotected JMX Registry.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xgjv-6gmp-cprw

PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgjv-46p6-hwgv

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.

CVSS3: 7.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-xgjq-gf22-rvwq

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.

CVSS3: 6.5
0%
Низкий
13 дней назад
github логотип
GHSA-xgjq-frv6-vjfh

A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xgjp-hj9v-xx75

A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xgjm-w63f-4hqq

Windows Compressed Folder Tampering Vulnerability

CVSS3: 6.5
30%
Средний
больше 2 лет назад
github логотип
GHSA-xgjm-4322-4ccq

CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xgjj-x9g2-jxw7

Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

CVSS3: 10
1%
Низкий
больше 1 года назад

Уязвимостей на страницу