Search

Found 6,352 results in 634ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-0601 unknown 2.5 KEVEXP 4y ago Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by usin…
CVE-2022-33891 unknown 2.5 KEVEXP sles 4y ago Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CVE-2021-43116 unknown 1.0 EXP 4y ago Use of Hard-coded Credentials in Nacos
CVE-2021-4034 high 10.0 KEVEXPFIX arch arch sles rocky 4y ago The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
CVE-2020-3837 unknown 2.5 KEVEXP 4y ago Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
CVE-2019-8605 unknown 2.5 KEVEXP 4y ago A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
CVE-2022-30190 unknown 2.5 KEVEXP 4y ago A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code …
CVE-2016-2388 unknown 2.5 KEVEXP 4y ago The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
CVE-2016-2386 unknown 2.5 KEVEXP 4y ago SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2019-7195 unknown 2.5 KEVEXP 4y ago QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
CVE-2019-7194 unknown 2.5 KEVEXP 4y ago QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
CVE-2019-7192 unknown 2.5 KEVEXP 4y ago QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
CVE-2019-5825 unknown 2.5 KEVEXPFIX debian debian 4y ago Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2018-6065 unknown 2.5 KEVEXP 4y ago Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect mult…
CVE-2012-4969 unknown 2.5 KEVEXP 4y ago Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.
CVE-2012-1889 unknown 2.5 KEVEXP 4y ago Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
CVE-2012-0754 unknown 2.5 KEVEXP 4y ago Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2011-2462 unknown 2.5 KEVEXP 4y ago The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
CVE-2011-0609 unknown 2.5 KEVEXP 4y ago Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2010-2883 unknown 2.5 KEVEXP 4y ago Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2010-1297 unknown 2.5 KEVEXP 4y ago Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2009-4324 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.
CVE-2009-3953 unknown 2.5 KEVEXP 4y ago Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
CVE-2007-5659 unknown 2.5 KEVEXP 4y ago Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.
CVE-2022-26134 unknown 2.5 KEVEXP 4y ago Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
CVE-2019-3010 unknown 2.5 KEVEXP 4y ago Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2016-0984 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-0016 unknown 2.5 KEVEXP 4y ago Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2013-7331 unknown 2.5 KEVEXP 4y ago An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applicat…
CVE-2013-3896 unknown 2.5 KEVEXP 4y ago Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
CVE-2013-2423 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
CVE-2013-0431 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
CVE-2013-0422 unknown 2.5 KEVEXP 4y ago A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
CVE-2013-0074 unknown 2.5 KEVEXP 4y ago Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
CVE-2010-1428 unknown 2.5 KEVEXP 4y ago Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs…
CVE-2010-0840 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
CVE-2010-0738 unknown 2.5 KEVEXP 4y ago The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests t…
CVE-2013-5123 unknown 1.0 EXPFIX slesdebian debian 4y ago The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVE-2021-42697 unknown 1.0 EXP 4y ago Uncontrolled Recursion in Akka HTTP
CVE-2021-22145 unknown 1.0 EXP sles 4y ago Generation of Error Message Containing Sensitive Information in Elasticsearch
CVE-2020-10770 medium 6.5 EXPFIX arch arch 4y ago Keycloak vulnerable to Server-Side Request Forgery
CVE-2020-16846 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users runnin…
CVE-2020-2231 unknown 1.0 EXP 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2230 unknown 1.0 EXP 4y ago Jenkins Cross-site Scripting vulnerability in project naming strategy
CVE-2020-2229 unknown 1.0 EXP 4y ago Jenkins Cross-Site Scripting vulnerability in help icons
CVE-2020-11651 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some m…
CVE-2020-11652 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security …
CVE-2020-7961 unknown 2.5 KEVEXP 4y ago Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
CVE-2020-7934 unknown 1.0 EXP 4y ago Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
CVE-2020-2096 unknown 1.0 EXP 4y ago Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
CVE-2019-10475 unknown 1.0 EXP 4y ago Jenkins build-metrics Plugin reflected cross-site scripting vulnerability
CVE-2019-11932 unknown 1.0 EXP 4y ago android-gif-drawable Double Free vulnerability
CVE-2019-10349 unknown 1.0 EXP 4y ago Jenkins Dependency Graph Viewer Plugin contains Cross-site Scripting
CVE-2019-6588 unknown 1.0 EXP 4y ago Liferay Portal Allows Cross-Site Scripting (XSS) via the SimpleCaptcha API
CVE-2019-0186 unknown 1.0 EXP 4y ago Cross-site Scripting in Apache Pluto Chatroom demo
CVE-2017-8291 high 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.
CVE-2017-0147 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
CVE-2016-6367 unknown 2.5 KEVEXP 4y ago A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
CVE-2016-6366 unknown 2.5 KEVEXP 4y ago A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute cod…
CVE-2016-4657 unknown 2.5 KEVEXP 4y ago Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTM…
CVE-2016-4656 unknown 2.5 KEVEXP 4y ago A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
CVE-2016-4655 unknown 2.5 KEVEXP 4y ago The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2019-7286 unknown 2.5 KEVEXP 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
CVE-2019-18426 unknown 2.5 KEVEXP 4y ago A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2019-11708 high 10.0 KEVEXPFIX arch archdebian debian rhel 4y ago Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2014-9390 unknown 1.0 EXPFIX debian debian 4y ago Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; …
CVE-2008-6505 unknown 1.0 EXP 4y ago Apache Struts directory traversal vulnerability
CVE-2012-6495 medium 7.0 EXP moinmo 4y ago Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users w…
CVE-2014-3120 unknown 2.5 KEVEXP 4y ago Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2008-6504 unknown 1.0 EXP 4y ago Improper Input Validation in OpenSymphony XWork
CVE-2022-30525 unknown 2.5 KEVEXP 4y ago A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CVE-2014-3146 medium 6.1 7.1 EXPFIX debian debian lxml 4y ago Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme t…
CVE-2013-4200 medium 6.8 EXP plone 4y ago The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows …
CVE-2015-1427 unknown 2.5 KEVEXP 4y ago The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2008-5518 unknown 1.0 EXP 4y ago Apache Geronimo Application Server multiple directory traversal vulnerabilities
CVE-2008-5619 unknown 1.0 EXPFIX debian debian 4y ago html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
CVE-2016-7201 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-7200 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2018-1306 unknown 1.0 EXP 4y ago Exposure of Sensitive Information in Apache Pluto
CVE-2018-8718 unknown 1.0 EXP 4y ago Cross-Site Request Forgery in Jenkins Mailer Plugin
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2017-12617 unknown 2.5 KEVEXP sles 4y ago When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv…
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2018-10054 unknown 1.0 EXP sles 4y ago Improper Input Validation in Datomic
CVE-2017-9791 unknown 2.5 KEVEXP 4y ago The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVE-2018-8298 unknown 2.5 KEVEXP 4y ago The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2019-1003002 unknown 1.0 EXP 4y ago Jenkins Pipeline Declarative Plugin sandbox bypass vulnerability
CVE-2019-1003001 unknown 1.0 EXP 4y ago Jenkins Groovy Plugin sandbox bypass vulnerability
CVE-2019-1003000 unknown 1.0 EXP 4y ago Protection Mechanism Failure in Jenkins Script Security Plugin
CVE-2019-1003030 unknown 2.5 KEVEXP 4y ago Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2013-2251 unknown 2.5 KEVEXP 4y ago Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2019-6804 unknown 1.0 EXP 4y ago Rundeck Community Edition vulnerable to Cross-site Scripting
CVE-2017-8046 unknown 1.0 EXP 4y ago Remote code execution in PATCH requests in Spring Data REST
CVE-2017-1000353 unknown 2.5 KEVEXP 4y ago Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would…
CVE-2018-1999002 high 9.0 EXPFIX arch arch 4y ago multiple issues in jenkins
CVE-2018-1000861 unknown 2.5 KEVEXP 4y ago A code execution vulnerability exists in the Stapler web framework used by Jenkins
CVE-2019-1003029 unknown 2.5 KEVEXP 4y ago Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.