Search

Found 4,137 results in 530ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-13272 high 10.0 KEVEXPFIX slesdebian debian rhel 5y ago Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
CVE-2021-42013 critical 10.0 KEVEXPFIX arch archdebian debian 5y ago It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Al…
CVE-2021-41773 high 10.0 KEVEXPFIX debian debianarch arch sles 5y ago A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-li…
CVE-2021-22205 critical 10.0 KEVEXPFIX arch arch 5y ago GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through Exi…
CVE-2021-21220 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could af…
CVE-2020-6418 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web…
CVE-2019-17026 critical 10.0 KEVEXPFIX arch archdebian debian rhel 5y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
CVE-2019-0211 high 10.0 KEVEXPFIX debian debianarch arch sles 5y ago In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scrip…
CVE-2018-6789 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
CVE-2017-16651 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.
CVE-2021-23017 high 9.0 EXPFIX arch arch sles rocky 5y ago RHSA-2022:0323: nginx:1.20 security update (Important)
CVE-2021-27928 high 9.0 EXPFIX sles rockydebian debian 5y ago RHSA-2021:1242: mariadb:10.3 and mariadb-devel:10.3 security update (Important)
CVE-2020-26950 critical 10.0 EXPFIX arch arch slesdebian debian 6y ago In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox …
CVE-2020-12352 high 9.0 EXPFIX arch arch slesdebian debian 6y ago Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
CVE-2020-12351 high 9.0 EXPFIX arch arch slesdebian debian 6y ago Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2019-5786 high 10.0 KEVEXPFIX arch archdebian debian 6y ago Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2020-8617 high 9.0 EXPFIX debian debianarch arch sles 6y ago RHSA-2020:2338: bind security update (Important)
CVE-2020-7656 low 3.5 EXP rocky rhel 6y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2016-10033 high 10.0 KEVEXPFIX arch archdebian debian 6y ago PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attac…
CVE-2019-18634 high 9.0 EXPFIX arch arch slesdebian debian 6y ago In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and ele…
CVE-2019-19844 high 9.0 EXPFIX arch arch slesdebian debian 7y ago Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of…
CVE-2019-8690 low 3.5 EXPFIX sles rockydebian debian 7y ago A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTun…
CVE-2019-8689 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8672 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8671 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8623 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8622 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8611 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for …
CVE-2019-8558 low 3.5 EXPFIX rockydebian debian rhel 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.1…
CVE-2019-8518 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.1…
CVE-2019-14378 high 9.0 EXPFIX sles rockydebian debian 7y ago ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
CVE-2019-14287 high 9.0 EXPFIX arch arch slesdebian debian 7y ago In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a cra…
CVE-2019-11599 high 9.0 EXPFIX slesdebian debian rhel 7y ago The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sen…
CVE-2019-1125 high 9.0 EXPFIX slesdebian debian rhel 7y ago An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged …
CVE-2019-12735 high 9.0 EXPFIX arch arch slesdebian debian 7y ago RHSA-2019:1619: vim security update (Important)
CVE-2019-11706 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-11705 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-11704 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-11703 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-9213 high 9.0 EXPFIX slesdebian debian rhel 7y ago In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SM…
CVE-2019-9816 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu…
CVE-2019-2697 critical 10.0 EXPFIX slesdebian debian rhel 7y ago RHSA-2019:1238: java-1.8.0-ibm security update (Critical)
CVE-2019-2698 critical 10.0 EXPFIX slesdebian debian rhel 7y ago RHSA-2019:1238: java-1.8.0-ibm security update (Critical)
CVE-2019-5736 high 9.0 EXPFIX arch arch sles rocky 7y ago RHSA-2019:0975: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-9813 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firef…
CVE-2019-9810 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR…
CVE-2019-9792 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory c…
CVE-2019-9791 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con…
CVE-2019-6116 high 9.0 EXPFIX arch arch slesdebian debian 7y ago RHSA-2019:0971: ghostscript security update (Important)
CVE-2019-11358 low 3.5 EXPFIX arch arch rockydebian debian 7y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2018-11784 high 9.0 EXPFIX sles rockydebian debian 8y ago When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/f…
CVE-2016-9587 high 9.0 EXPFIX debian debian slesarch arch 8y ago Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed …
CVE-2018-7602 critical 10.0 KEVEXPFIX arch arch 8y ago A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7600 critical 10.0 KEVEXPFIX arch arch 8y ago Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CVE-2017-18001 critical 9.8 10.0 EXP trustwave 9y ago Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, vi…
CVE-2015-3302 high 7.5 8.5 EXP thecartpress 9y ago The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by …
CVE-2017-17968 critical 9.8 10.0 EXP xi-soft 9y ago A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP respons…
CVE-2017-15667 high 7.5 8.5 EXP flexense 9y ago In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221.
CVE-2017-17932 critical 9.8 10.0 EXP allmediaserver 9y ago A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on th…
CVE-2017-13056 high 7.8 8.8 EXP tracker-software 9y ago The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
CVE-2016-6914 high 7.8 8.8 EXP ui 9y ago Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
CVE-2017-17876 high 7.5 8.5 EXP iwcnetwork 9y ago Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
CVE-2017-17875 critical 9.8 10.0 EXP jextn 9y ago The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17874 high 8.8 9.8 EXP vanguard_project 9y ago Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
CVE-2017-17873 critical 9.8 10.0 EXP vanguard_project 9y ago Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
CVE-2017-17872 critical 9.8 10.0 EXP jextn 9y ago The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17871 critical 9.8 10.0 EXP jextn 9y ago The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVE-2017-17870 critical 9.8 10.0 EXP jbuildozer 9y ago The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
CVE-2017-17849 critical 9.8 10.0 EXP getgosoft 9y ago A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
CVE-2017-16995 high 7.8 8.8 EXPFIX arch archdebian debian linux-kernel 9y ago The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by lev…
CVE-2017-13878 high 7.1 8.1 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows local users to bypass intended memory-read res…
CVE-2017-13876 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13875 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privi…
CVE-2017-13867 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13861 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows a…
CVE-2017-13847 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary co…
CVE-2017-17692 high 7.5 8.5 EXP samsung 9y ago Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the …
CVE-2017-17411 critical 9.8 10.0 EXP 9y ago This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exis…
CVE-2017-5262 high 8.0 9.0 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
CVE-2017-5261 high 8.8 9.8 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to …
CVE-2017-5260 high 8.8 9.8 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' acco…
CVE-2017-5259 high 8.8 9.8 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/sysc…
CVE-2017-5255 high 8.8 9.8 EXP 9y ago In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-…
CVE-2017-5254 high 8.8 9.8 EXP 9y ago In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after di…
CVE-2012-2576 critical 9.8 10.0 EXP solarwinds 9y ago SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote at…
CVE-2017-17761 critical 9.8 10.0 EXP 9y ago An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. Th…
CVE-2017-17088 high 7.5 8.5 EXP flexense 9y ago The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header …
CVE-2017-15049 high 8.8 9.8 EXP zoom 9y ago The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary…
CVE-2017-15048 high 8.8 9.8 EXP zoom 9y ago Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handle…
CVE-2017-17759 critical 9.8 10.0 EXP conarc 9y ago Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request…
CVE-2017-17105 critical 9.8 10.0 EXP 9y ago Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the w…
CVE-2017-16949 critical 9.8 10.0 EXP accesspressthemes 9y ago An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file …
CVE-2017-17721 critical 9.8 10.0 EXP zuuse 9y ago CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorde…
CVE-2017-17651 critical 9.8 10.0 EXP paid_to_read_script_project 9y ago Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
CVE-2017-17645 critical 9.8 10.0 EXP phpautoclassifiedscript 9y ago Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CVE-2017-17643 critical 9.8 10.0 EXP lynda_clone_project 9y ago FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
CVE-2017-17739 critical 9.8 10.0 EXP 9y ago The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
CVE-2017-17738 high 7.5 8.5 EXP 9y ago The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.
CVE-2017-3195 critical 9.8 10.0 EXP commvault 9y ago Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code executio…
CVE-2017-17405 high 8.8 9.8 EXP slesdebian debian rhel ruby-lang 9y ago Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument star…