Github Exploits

3,713 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-4796 GITHUB HIGH python
Eventin < 4.0.35 - Unauthenticated Privilege Escalation via SpeakerController Email Update
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the 'Eventin\Speaker\Api\SpeakerController::update_item' function. This makes it possible for unauthenticated attackers with contributor-level and above permissions to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
by Nxploited
CVSS 8.8
CVE-2025-59934 GITHUB CRITICAL
formbricks < 4.0.1 - Unauthenticated Authentication Bypass via JWT Signature Verification Missing
Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the token’s signature, expiration, issuer, or audience. If an attacker learns the victim’s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victim’s password. This issue has been patched in version 4.0.1.
by suriryuk
CVSS 9.4
CVE-2025-1550 GITHUB CRITICAL python
Keras 3.0.0-3.8.0 and 3.9.0 - Remote Code Execution via Malicious .keras Archive
The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.
by ChCh0i
CVSS 9.8
CVE-2025-55315 GITHUB CRITICAL go
ASP.NET Core 2.3.0-2.3.5 - HTTP Request Smuggling via Inconsistent Request Interpretation
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
by jlinebau
2 stars
CVSS 9.9
CVE-2025-3248 GITHUB CRITICAL python
Langflow AI - Unauthenticated Remote Code Execution
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
by bambooqj
CVSS 9.8
CVE-2025-61984 GITHUB LOW shell
OpenSSH < 10.1 - Remote Code Execution via Control Characters in Username
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
by flyskyfire
CVSS 3.6
CVE-2025-61882 GITHUB CRITICAL
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
by GhoStZA-debug
1 stars
CVSS 9.8
CVE-2025-60751 GITHUB HIGH python
GeographicLib 2.5 - Buffer Overflow
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
by zer0matt
CVSS 7.5
CVE-2019-1003000 GITHUB HIGH javascript
Jenkins Script Security Plugin < 1.50 - Sandbox Bypass Remote Code Execution
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
by wjl110
175 stars
CVSS 8.8
CVE-2021-4034 GITHUB HIGH javascript
Local Privilege Escalation in polkits pkexec
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
by wjl110
175 stars
CVSS 7.8
CVE-2021-26900 GITHUB HIGH javascript
Windows 10 and Windows Server 2016 - Use-After-Free in Win32k
Windows Win32k Elevation of Privilege Vulnerability
by wjl110
175 stars
CVSS 7.8
CVE-2020-7460 GITHUB HIGH javascript
FreeBSD Race Condition in sendmsg System Call
In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use vulnerability allowing a mailcious userspace program to modify control message headers after they were validation.
by wjl110
175 stars
CVSS 7.0
CVE-2020-16939 GITHUB HIGH javascript
Windows Group Policy - Elevation of Privilege via Improper Access Check
<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.</p> <p>The security update addresses the vulnerability by correcting how Group Policy checks access.</p>
by wjl110
175 stars
CVSS 7.8
CVE-2020-12027 GITHUB MEDIUM javascript
FactoryTalk View SE - Exposure of Sensitive Information via Hostname and File Path Disclosure
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.
by wjl110
175 stars
CVSS 4.3
CVE-2020-0932 GITHUB HIGH javascript
Microsoft SharePoint - Remote Code Execution via Unchecked Application Package Markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
by wjl110
175 stars
CVSS 8.8
CVE-2020-0558 GITHUB MEDIUM javascript
Intel PROSet/Wireless WiFi < 21.70.0.6 - Denial of Service via Kernel Mode Driver Buffer Overflow
Improper buffer restrictions in kernel mode driver for Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an unprivileged user to potentially enable denial of service via adjacent access.
by wjl110
175 stars
CVSS 6.5
CVE-2019-3396 GITHUB CRITICAL javascript
Atlassian Confluence Widget Connector Macro Velocity Template Injection
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
by wjl110
175 stars
CVSS 9.8
CVE-2019-17147 GITHUB HIGH javascript
TP-LINK TL-WR841N Firmware - Unauthenticated Remote Code Execution via Host Header Buffer Overflow
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457.
by wjl110
175 stars
CVSS 8.8
CVE-2018-8406 GITHUB HIGH javascript
Windows 10 and Windows Server - Elevation of Privilege via DirectX Graphics Kernel Memory Handling
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8405.
by wjl110
175 stars
CVSS 7.8
CVE-2018-8405 GITHUB HIGH javascript
Windows - Elevation of Privilege via DirectX Graphics Kernel Memory Handling
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8406.
by wjl110
175 stars
CVSS 7.8
CVE-2018-8401 GITHUB HIGH javascript
Windows 10 and Windows Server 2016 - Elevation of Privilege via DirectX Graphics Kernel Memory Handling
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8405, CVE-2018-8406.
by wjl110
175 stars
CVSS 7.8
CVE-2018-8400 GITHUB HIGH javascript
Windows 10 and Windows Server 2016 - Elevation of Privilege via DirectX Graphics Kernel Memory Handling
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8401, CVE-2018-8405, CVE-2018-8406.
by wjl110
175 stars
CVSS 7.8
CVE-2018-8581 GITHUB HIGH javascript
Microsoft Exchange Server - Privilege Escalation
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
by wjl110
175 stars
CVSS 7.4
CVE-2018-4338 GITHUB MEDIUM javascript
macOS < 10.14 - Improper Input Validation
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
by wjl110
175 stars
CVSS 5.5
CVE-2018-2893 GITHUB CRITICAL javascript
Oracle WebLogic Server <12.2.1.3 - RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
by wjl110
175 stars
CVSS 9.8