Exploit Database

149,779 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-2856 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.13 and 4.0.0-4.0.5 - Denial of Service via VMS TCPIPtrace File Parser
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVSS 5.3
CVE-2023-2857 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.13 and 4.0.0-4.0.5 - Denial of Service via BLF File Parser
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVSS 5.3
CVE-2023-2858 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.13 and 4.0.0-4.0.5 - Denial of Service via NetScaler File Parser
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVSS 5.3
CVE-2023-2879 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.13 and 4.0.0-4.0.5 - Denial of Service via GDSDB Packet Parsing Infinite Loop
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
CVSS 6.3
CVE-2023-29772 WRITEUP MEDIUM
ASUS RT-AC51U Firmware <= 3.0.0.4.380.8591 - Cross-Site Scripting in System Log Page
A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to inject arbitrary web script or HTML via a malicious network request.
CVSS 5.2
CVE-2023-2908 WRITEUP MEDIUM
libtiff < 4.5.0 - Denial of Service via Crafted TIFF Image in tiffcp
A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility which triggers a runtime error that causes undefined behavior. This will result in an application crash, eventually leading to a denial of service.
CVSS 5.5
CVE-2023-2952 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.13 and 4.0.0-4.0.5 - Denial of Service via XRA Dissector Infinite Loop
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
CVSS 5.3
CVE-2023-2970 WRITEUP LOW
MindSpore 2.0.0-alpha/2.0.0-rc1 - Memory Corruption in JsonHelper::UpdateArray
A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the function JsonHelper::UpdateArray of the file mindspore/ccsrc/minddata/dataset/util/json_helper.cc. The manipulation leads to memory corruption. The name of the patch is 30f4729ea2c01e1ed437ba92a81e2fc098d608a9. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-230176.
CVSS 3.5
CVE-2023-31889 WRITEUP MEDIUM
ASUS RT-AC51U <3.0.0.4.380.8591 - DoS
An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service via crafted GET request.
CVSS 5.5
CVE-2023-37647 WRITEUP CRITICAL
SEMCMS v1.5 - SQL Injection via id Parameter at Ant_Suxin.php
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
CVSS 9.8
CVE-2023-40360 WRITEUP MEDIUM
QEMU 8.0.0-8.0.4 - NULL Pointer Dereference in NVMe Directive Receive
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
CVSS 5.5
CVE-2023-42225 WRITEUP HIGH
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 - Path Traversal via Attachment/DownloadTempFile
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.
CVSS 7.5
CVE-2023-42226 WRITEUP HIGH
HelpdeskAdvanced <= 11.0.33 - Path Traversal via Email/SaveAttachment Function
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.
CVSS 7.5
CVE-2023-42227 WRITEUP HIGH
HelpdeskAdvanced <= 11.0.33 - Path Traversal via WSCView/Save Function
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.
CVSS 7.5
CVE-2023-42228 WRITEUP HIGH
Zucchetti HelpdeskAdvanced <= 11.0.33 - Incorrect Access Control
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.
CVSS 8.8
CVE-2023-42229 WRITEUP MEDIUM
HelpdeskAdvanced <= 11.0.33 - Authenticated Path Traversal via WSConnector SOAP Requests
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.
CVSS 6.5
CVE-2023-42230 WRITEUP MEDIUM
HelpdeskAdvanced <= 11.0.33 - Cross-Site Scripting via WSCView/Save Function
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.
CVSS 6.1
CVE-2026-21858 GITLAB CRITICAL
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.
by sastraadiwiguna-purpleeliteteaming
CVSS 10.0
CVE-2026-22804 GITLAB HIGH
Termix 1.7.0-1.9.0 - Stored Cross-Site Scripting via SVG File Preview
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 to 1.9.0, Stored Cross-Site Scripting (XSS) vulnerability exists in the Termix File Manager component. The application fails to sanitize SVG file content before rendering it. This allows an attacker who has compromised a managed SSH server to plant a malicious file, which, when previewed by the Termix user, executes arbitrary JavaScript in the context of the application. The vulnerability is located in src/ui/desktop/apps/file-manager/components/FileViewer.tsx. This vulnerability is fixed in 1.10.0.
by ThemeHackers
CVSS 8.0
CVE-2026-0628 GITLAB HIGH
Google Chrome < 143.0.7499.192 - Insufficient Policy Enforcement in WebView Tag
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
by sastraadiwiguna-purpleeliteteaming
CVSS 8.8
CVE-2025-22869 GITLAB HIGH
go/ssh < 0.35.0 - Denial of Service via Slow Key Exchange
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.
by sempernow
CVSS 7.5
CVE-2025-24071 GITLAB MEDIUM
Windows File Explorer - Exposure of Sensitive Information to an Unauthorized Actor
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
by ThemeHackers
CVSS 6.5
CVE-2025-29972 GITLAB CRITICAL
Azure Storage Resource Provider - SSRF
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
by ThemeHackers
CVSS 9.9
CVE-2025-29927 GITLAB CRITICAL
Next.js Middleware Bypass
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
by ThemeHackers
CVSS 9.1
CVE-2025-32711 GITLAB CRITICAL
Microsoft 365 Copilot - Ai Command Injection
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
by daryllundy
CVSS 9.3