Search

Found 5,007 results in 551ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-0016 unknown 2.5 KEVEXP 4y ago Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2013-7331 unknown 2.5 KEVEXP 4y ago An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applicat…
CVE-2013-3896 unknown 2.5 KEVEXP 4y ago Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
CVE-2013-2423 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
CVE-2013-0431 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
CVE-2013-0422 unknown 2.5 KEVEXP 4y ago A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
CVE-2013-0074 unknown 2.5 KEVEXP 4y ago Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
CVE-2010-1428 unknown 2.5 KEVEXP 4y ago Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs…
CVE-2010-0840 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
CVE-2010-0738 unknown 2.5 KEVEXP 4y ago The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests t…
CVE-2013-5123 unknown 1.0 EXPFIX slesdebian debian 4y ago The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVE-2021-42697 unknown 1.0 EXP 4y ago Uncontrolled Recursion in Akka HTTP
CVE-2021-22145 unknown 1.0 EXP sles 4y ago Generation of Error Message Containing Sensitive Information in Elasticsearch
CVE-2020-10770 medium 6.5 EXPFIX arch arch 4y ago Keycloak vulnerable to Server-Side Request Forgery
CVE-2020-16846 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users runnin…
CVE-2020-2231 unknown 1.0 EXP 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2230 unknown 1.0 EXP 4y ago Jenkins Cross-site Scripting vulnerability in project naming strategy
CVE-2020-2229 unknown 1.0 EXP 4y ago Jenkins Cross-Site Scripting vulnerability in help icons
CVE-2020-1147 critical 10.0 KEVEXP rhel 4y ago Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploi…
CVE-2020-11651 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some m…
CVE-2020-11652 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security …
CVE-2020-7961 unknown 2.5 KEVEXP 4y ago Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
CVE-2020-7934 unknown 1.0 EXP 4y ago Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
CVE-2020-2096 unknown 1.0 EXP 4y ago Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
CVE-2019-10475 unknown 1.0 EXP 4y ago Jenkins build-metrics Plugin reflected cross-site scripting vulnerability
CVE-2019-11932 unknown 1.0 EXP 4y ago android-gif-drawable Double Free vulnerability
CVE-2019-10349 unknown 1.0 EXP 4y ago Jenkins Dependency Graph Viewer Plugin contains Cross-site Scripting
CVE-2019-6588 unknown 1.0 EXP 4y ago Liferay Portal Allows Cross-Site Scripting (XSS) via the SimpleCaptcha API
CVE-2019-0186 unknown 1.0 EXP 4y ago Cross-site Scripting in Apache Pluto Chatroom demo
CVE-2017-0147 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
CVE-2016-6367 unknown 2.5 KEVEXP 4y ago A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
CVE-2016-6366 unknown 2.5 KEVEXP 4y ago A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute cod…
CVE-2016-4657 unknown 2.5 KEVEXP 4y ago Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTM…
CVE-2016-4656 unknown 2.5 KEVEXP 4y ago A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
CVE-2016-4655 unknown 2.5 KEVEXP 4y ago The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2019-7286 unknown 2.5 KEVEXP 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
CVE-2019-18426 unknown 2.5 KEVEXP 4y ago A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2019-13720 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2014-9390 unknown 1.0 EXPFIX debian debian 4y ago Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; …
CVE-2008-6505 unknown 1.0 EXP 4y ago Apache Struts directory traversal vulnerability
CVE-2012-6495 medium 7.0 EXP moinmo 4y ago Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users w…
CVE-2014-3120 unknown 2.5 KEVEXP 4y ago Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2008-6504 unknown 1.0 EXP 4y ago Improper Input Validation in OpenSymphony XWork
CVE-2022-30525 unknown 2.5 KEVEXP 4y ago A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CVE-2014-3146 medium 6.1 7.1 EXPFIX debian debian lxml 4y ago Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme t…
CVE-2013-4200 medium 6.8 EXP plone 4y ago The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows …
CVE-2015-1427 unknown 2.5 KEVEXP 4y ago The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2008-5518 unknown 1.0 EXP 4y ago Apache Geronimo Application Server multiple directory traversal vulnerabilities
CVE-2008-5619 unknown 1.0 EXPFIX debian debian 4y ago html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
CVE-2016-7201 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-7200 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2018-1306 unknown 1.0 EXP 4y ago Exposure of Sensitive Information in Apache Pluto
CVE-2018-8718 unknown 1.0 EXP 4y ago Cross-Site Request Forgery in Jenkins Mailer Plugin
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2017-12617 unknown 2.5 KEVEXP sles 4y ago When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv…
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2018-10054 unknown 1.0 EXP sles 4y ago Improper Input Validation in Datomic
CVE-2017-9791 unknown 2.5 KEVEXP 4y ago The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVE-2018-8298 unknown 2.5 KEVEXP 4y ago The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2019-1003002 unknown 1.0 EXP 4y ago Jenkins Pipeline Declarative Plugin sandbox bypass vulnerability
CVE-2019-1003001 unknown 1.0 EXP 4y ago Jenkins Groovy Plugin sandbox bypass vulnerability
CVE-2019-1003000 unknown 1.0 EXP 4y ago Protection Mechanism Failure in Jenkins Script Security Plugin
CVE-2019-1003030 unknown 2.5 KEVEXP 4y ago Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2013-2251 unknown 2.5 KEVEXP 4y ago Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2019-6804 unknown 1.0 EXP 4y ago Rundeck Community Edition vulnerable to Cross-site Scripting
CVE-2017-8046 unknown 1.0 EXP 4y ago Remote code execution in PATCH requests in Spring Data REST
CVE-2017-1000353 unknown 2.5 KEVEXP 4y ago Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would…
CVE-2018-1000861 unknown 2.5 KEVEXP 4y ago A code execution vulnerability exists in the Stapler web framework used by Jenkins
CVE-2019-1003029 unknown 2.5 KEVEXP 4y ago Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
CVE-2019-1003005 unknown 1.0 EXP 4y ago Sandbox Bypass in Script Security Plugin
CVE-2022-29885 unknown 1.0 EXPFIX slesdebian debian 4y ago The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to r…
CVE-2022-1388 unknown 2.5 KEVEXP 4y ago F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
CVE-2012-0391 unknown 2.5 KEVEXP 4y ago The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
CVE-2014-4113 unknown 2.5 KEVEXP 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2014-0322 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
CVE-2014-0160 unknown 2.5 KEVEXPFIX debian debian 4y ago The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CVE-2009-5065 medium 5.3 EXPFIX debian debian mark_pilgrim 4y ago Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via …
CVE-2009-1595 unknown 1.0 EXP 4y ago Ignite Realtime Openfire Allows Users to Change Passwords of Arbitrary Accounts
CVE-2009-1523 unknown 1.0 EXP 4y ago Directory traversal in Mort Bay Jetty
CVE-2009-0580 unknown 1.0 EXP 4y ago Exposure of Sensitive Information in Apache Tomcat
CVE-2009-0039 unknown 1.0 EXP 4y ago Apache Geronimo Application Server CSRF vulnerabilities
CVE-2009-0038 unknown 1.0 EXP 4y ago Apache Geronimo Application Server multiple cross-site scripting (XSS) vulnerabilities
CVE-2009-0026 unknown 1.0 EXP 4y ago Apache Jackrabbit contains Cross-site Scripting
CVE-2008-2938 unknown 1.0 EXP 4y ago Apache Tomcat Directory Traversal vulnerability
CVE-2008-2370 unknown 1.0 EXP 4y ago Apache Tomcat Path Traversal Vulnerability
CVE-2008-1510 unknown 1.0 EXP 4y ago Alkacon OpenCMS XSS via searchfilter or listSearchFilter parameter
CVE-2008-1301 unknown 1.0 EXP 4y ago Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter
CVE-2008-1300 unknown 1.0 EXP 4y ago Alkacon Open CMS XSS via Logfile Viewer Settings function
CVE-2008-1232 unknown 1.0 EXP 4y ago Apache Tomcat Cross-site scripting (XSS) vulnerability
CVE-2008-1045 unknown 1.0 EXP 4y ago Alkacon OpenCMS XSS via file tree navigation in system/workplace/views/explorer/tree_files.jsp
CVE-2007-5461 unknown 1.0 EXP 4y ago Apache Tomcat Path Traversal Vulnerability
CVE-2007-5333 unknown 1.0 EXP 4y ago Exposure of Sensitive Information in Apache Tomcat
CVE-2007-3382 unknown 1.0 EXP 4y ago Apache Tomcat treats single quotes as delimiters in cookies
CVE-2007-2449 unknown 1.0 EXP 4y ago Apache Tomcat XSS Vulnerabilities in Examples Web Application
CVE-2007-2353 unknown 1.0 EXP debian debian 4y ago Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
CVE-2007-1355 unknown 1.0 EXP 4y ago Apache Tomcat Vulnerable to Cross-Site Scripting