Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 125

Количество 26 125

msrc логотип

CVE-2025-24983

больше 1 года назад

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2025-24928

больше 1 года назад

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-24912

больше 1 года назад

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2025-24898

6 месяцев назад

rust openssl ssl::select_next_proto use after free

EPSS: Низкий
msrc логотип

CVE-2025-2486

9 месяцев назад

UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu

EPSS: Низкий
msrc логотип

CVE-2025-24855

больше 1 года назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-2476

больше 1 года назад

Chromium: CVE-2025-2476 Use after free in Lens

EPSS: Низкий
msrc логотип

CVE-2025-24528

7 месяцев назад

In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2025-24514

больше 1 года назад

Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller

EPSS: Средний
msrc логотип

CVE-2025-24513

больше 1 года назад

Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller

EPSS: Низкий
msrc логотип

CVE-2025-24294

6 месяцев назад

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-24201

больше 1 года назад

Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac

EPSS: Низкий
msrc логотип

CVE-2025-24084

больше 1 года назад

Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability

CVSS3: 8.4
EPSS: Низкий
msrc логотип

CVE-2025-24083

больше 1 года назад

Microsoft Office Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-24082

больше 1 года назад

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-24081

больше 1 года назад

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-24080

больше 1 года назад

Microsoft Office Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-24079

больше 1 года назад

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-24078

больше 1 года назад

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2025-24077

больше 1 года назад

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2025-24983

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVSS3: 7
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24928

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24912

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

CVSS3: 3.7
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24898

rust openssl ssl::select_next_proto use after free

1%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-2486

UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu

0%
Низкий
9 месяцев назад
msrc логотип
CVE-2025-24855

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-2476

Chromium: CVE-2025-2476 Use after free in Lens

1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24528

In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.

CVSS3: 7.1
1%
Низкий
7 месяцев назад
msrc логотип
CVE-2025-24514

Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller

32%
Средний
больше 1 года назад
msrc логотип
CVE-2025-24513

Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller

4%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24294

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-24201

Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac

4%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24084

Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability

CVSS3: 8.4
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24083

Microsoft Office Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24082

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24081

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24080

Microsoft Office Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24079

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24078

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-24077

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу