Github Exploits

2,293 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-0475 GITHUB HIGH c
Google Android - Improper Input Validation
An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31914369.
by codecat007
8 stars
CVSS 7.8
CVE-2016-6762 GITHUB HIGH c
Google Android - Access Control
An elevation of privilege vulnerability in the libziparchive library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31251826.
by codecat007
8 stars
CVSS 7.8
CVE-2016-6702 GITHUB HIGH c
Google Android - Improper Access Control
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
by codecat007
8 stars
CVSS 7.8
CVE-2016-6700 GITHUB HIGH c
Google Android - Access Control
An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30916186.
by codecat007
8 stars
CVSS 7.8
CVE-2016-5346 GITHUB MEDIUM c
Google Android < 7.0 - Information Disclosure
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).
by codecat007
8 stars
CVSS 5.5
CVE-2018-9381 GITHUB HIGH c
Google Android - Use of Uninitialized Resource
In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
by codecat007
8 stars
CVSS 7.5
CVE-2018-9365 GITHUB HIGH c
Google Android - Out-of-Bounds Read
In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
by codecat007
8 stars
CVSS 8.8
CVE-2018-9361 GITHUB HIGH c
Google Android - Out-of-Bounds Read
In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74202041.
by codecat007
8 stars
CVSS 7.5
CVE-2018-9360 GITHUB HIGH c
Google Android - Out-of-Bounds Read
In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74201143.
by codecat007
8 stars
CVSS 7.5
CVE-2018-9359 GITHUB HIGH c
Google Android - Out-of-Bounds Read
In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74196706.
by codecat007
8 stars
CVSS 7.5
CVE-2018-9358 GITHUB HIGH c
Google Android - Out-of-Bounds Read
In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-73172115.
by codecat007
8 stars
CVSS 7.5
CVE-2018-9357 GITHUB HIGH c
Google Android - Out-of-Bounds Write
In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74947856.
by codecat007
8 stars
CVSS 7.8
CVE-2018-9356 GITHUB CRITICAL c
Google Android - Double Free
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74950468.
by codecat007
8 stars
CVSS 9.8
CVE-2017-13267 GITHUB CRITICAL c
Google Android - Memory Corruption
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69479009.
by codecat007
8 stars
CVSS 9.8
CVE-2017-13266 GITHUB CRITICAL c
Google Android - Memory Corruption
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478941.
by codecat007
8 stars
CVSS 9.8
CVE-2017-13256 GITHUB HIGH c
Google Android - Out-of-Bounds Write
In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68817966.
by codecat007
8 stars
CVSS 8.8
CVE-2017-13255 GITHUB HIGH c
Google Android - Out-of-Bounds Write
In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68776054.
by codecat007
8 stars
CVSS 8.8
CVE-2017-13281 GITHUB CRITICAL c
Google Android - Memory Corruption
In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71603262.
by codecat007
8 stars
CVSS 9.8
CVE-2021-40100 GITHUB MEDIUM
Concretecms Concrete Cms < 8.5.5 - XSS
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
by bl4de
CVSS 5.4
CVE-2020-8214 GITHUB HIGH
servey < 3 - Path Traversal
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
by bl4de
CVSS 7.5
CVE-2019-5422 GITHUB MEDIUM
buttle <0.2.0 - XSS
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
by bl4de
CVSS 6.1
CVE-2018-3773 GITHUB MEDIUM
Metascraper < 3.9.2 - XSS
There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.
by bl4de
CVSS 6.1
CVE-2018-3771 GITHUB MEDIUM
Statics-server < 0.0.9 - XSS
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
by bl4de
CVSS 6.1
CVE-2018-3755 GITHUB MEDIUM
Sexstatic - XSS
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element used in directory name.
by bl4de
CVSS 6.1
CVE-2018-3754 GITHUB HIGH
Query-mysql - SQL Injection
Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database.
by bl4de
CVSS 8.8