Search

Found 5,186 results in 538ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2007-2449 unknown 1.0 EXP 4y ago Apache Tomcat XSS Vulnerabilities in Examples Web Application
CVE-2007-2353 unknown 1.0 EXP debian debian 4y ago Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
CVE-2007-1355 unknown 1.0 EXP 4y ago Apache Tomcat Vulnerable to Cross-Site Scripting
CVE-2007-0450 unknown 1.0 EXP 4y ago Apache Tomcat Directory Traversal
CVE-2006-7196 unknown 1.0 EXP 4y ago Cross-site scripting in Apache Tomcat
CVE-2006-3835 unknown 1.0 EXP 4y ago Apache Tomcat Reveals Directories
CVE-2006-2758 unknown 1.0 EXP sles 4y ago Jetty Directory Traversal Vulnerability
CVE-2006-0254 unknown 1.0 EXP 4y ago Apache Geronimo console 1.0 vulnerable to cross-site scripting
CVE-2005-4703 unknown 1.0 EXP 4y ago Apache Tomcat Discloses MS-DOS Pathname
CVE-2005-3747 unknown 1.0 EXP sles 4y ago Mortbay Jetty Discloses JSP Source Code
CVE-2005-3745 unknown 1.0 EXP 4y ago Apache Struts Cross-site scripting Vulnerability
CVE-2002-2272 unknown 1.0 EXP 4y ago Apache Tomcat DoS via Malicious Get Request
CVE-2002-2006 unknown 1.0 EXP 4y ago Apache Tomcat Default Installation Reveals Sensitive Information
CVE-2002-1567 unknown 1.0 EXP 4y ago Apache Tomcat XSS Vulnerability
CVE-2002-1533 unknown 1.0 EXP 4y ago Jetty Javascript Inclusion Vulnerability
CVE-2002-1148 unknown 1.0 EXP 4y ago Apache Tomcat Source Code Disclosure
CVE-2001-0590 unknown 1.0 EXP 4y ago Apache Tomcat Allows Source Disclosure
CVE-2000-0759 unknown 1.0 EXP 4y ago Jakarta Apache Tomcat Reveals Physical Paths
CVE-2003-0866 unknown 1.0 EXP 4y ago Apache Tomcat Denial of Service vulnerability in the Catalina package
CVE-2003-0042 unknown 1.0 EXP 4y ago Jakarta Tomcat Directory Listing vulnerability
CVE-2022-29464 unknown 2.5 KEVEXP 4y ago Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
CVE-2022-26904 unknown 2.5 KEVEXP 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2012-1592 unknown 1.0 EXP 4y ago Unrestricted Upload of File with Dangerous Type in Apache Struts2
CVE-2011-3923 unknown 1.0 EXP 4y ago Struts ParameterInterceptor vulnerability allows remote command execution
CVE-2022-22960 unknown 2.5 KEVEXP 4y ago VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
CVE-2019-3929 unknown 2.5 KEVEXP 4y ago Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system comma…
CVE-2018-7841 unknown 2.5 KEVEXP 4y ago A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
CVE-2014-0780 unknown 2.5 KEVEXP 4y ago InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
CVE-2007-3010 unknown 2.5 KEVEXP 4y ago masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
CVE-2022-22954 unknown 2.5 KEVEXP 4y ago VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
CVE-2015-5122 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-3113 unknown 2.5 KEVEXP 4y ago Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-0313 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-0311 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2017-11317 unknown 2.5 KEVEXP 4y ago Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2021-31166 unknown 2.5 KEVEXP 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2017-0148 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
CVE-2022-22963 unknown 2.5 KEVEXP 4y ago When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code executio…
CVE-2022-22965 unknown 2.5 KEVEXP debian debian 4y ago Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-1040 unknown 2.5 KEVEXP 4y ago An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
CVE-2021-21551 unknown 2.5 KEVEXP 4y ago Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
CVE-2018-10562 unknown 2.5 KEVEXP 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
CVE-2018-10561 unknown 2.5 KEVEXP 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
CVE-2022-0543 unknown 2.5 KEVEXPFIX debian debian 4y ago Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CVE-2021-26085 unknown 2.5 KEVEXP 4y ago Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2018-8440 unknown 2.5 KEVEXP 4y ago An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
CVE-2017-0213 unknown 2.5 KEVEXP 4y ago Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
CVE-2017-0059 unknown 2.5 KEVEXP 4y ago Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2017-0037 unknown 2.5 KEVEXP 4y ago Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
CVE-2016-0189 unknown 2.5 KEVEXP 4y ago The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web s…
CVE-2016-0151 unknown 2.5 KEVEXP 4y ago The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
CVE-2016-0040 unknown 2.5 KEVEXP 4y ago The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
CVE-2015-2426 unknown 2.5 KEVEXP 4y ago A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
CVE-2015-2419 unknown 2.5 KEVEXP 4y ago JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2013-3660 unknown 2.5 KEVEXP 4y ago The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to ga…
CVE-2013-2729 unknown 2.5 KEVEXP 4y ago Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2013-2551 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
CVE-2013-2465 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related …
CVE-2013-1690 unknown 2.5 KEVEXP 4y ago Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execu…
CVE-2012-5076 unknown 2.5 KEVEXP 4y ago The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet coul…
CVE-2011-2005 unknown 2.5 KEVEXP 4y ago afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
CVE-2010-4398 unknown 2.5 KEVEXP 4y ago Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
CVE-2017-9841 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., exte…
CVE-2022-26318 unknown 2.5 KEVEXP 4y ago On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
CVE-2022-21999 unknown 2.5 KEVEXP 4y ago Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
CVE-2021-42237 unknown 2.5 KEVEXP 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2020-7247 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
CVE-2020-25223 unknown 2.5 KEVEXP 4y ago A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
CVE-2019-2616 unknown 2.5 KEVEXP 4y ago Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for au…
CVE-2019-15107 unknown 2.5 KEVEXP 4y ago An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
CVE-2019-12991 unknown 2.5 KEVEXP 4y ago Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
CVE-2019-12989 unknown 2.5 KEVEXP 4y ago Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
CVE-2019-11043 critical 10.0 KEVEXPFIX arch arch sles rocky 4y ago In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
CVE-2019-10068 unknown 2.5 KEVEXP 4y ago Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
CVE-2018-6961 unknown 2.5 KEVEXP 4y ago VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
CVE-2018-11138 unknown 2.5 KEVEXP 4y ago The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
CVE-2017-6334 unknown 2.5 KEVEXP 4y ago dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
CVE-2017-6316 unknown 2.5 KEVEXP 4y ago A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthent…
CVE-2017-3881 unknown 2.5 KEVEXP 4y ago A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected …
CVE-2017-0146 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
CVE-2016-1555 unknown 2.5 KEVEXP 4y ago Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
CVE-2016-11021 unknown 2.5 KEVEXP 4y ago setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
CVE-2016-10174 unknown 2.5 KEVEXP 4y ago The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
CVE-2015-3035 unknown 2.5 KEVEXP 4y ago Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVE-2015-1187 unknown 2.5 KEVEXP 4y ago The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
CVE-2014-6332 unknown 2.5 KEVEXP 4y ago OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
CVE-2014-6324 unknown 2.5 KEVEXP 4y ago The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
CVE-2014-6287 unknown 2.5 KEVEXP 4y ago The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
CVE-2013-5223 unknown 2.5 KEVEXP 4y ago A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
CVE-2013-4810 unknown 2.5 KEVEXP 4y ago HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet …
CVE-2012-1823 unknown 2.5 KEVEXP 4y ago sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
CVE-2010-4345 unknown 2.5 KEVEXPFIX debian debian 4y ago Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
CVE-2010-4344 unknown 2.5 KEVEXPFIX debian debian 4y ago Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
CVE-2010-2861 unknown 2.5 KEVEXP 4y ago A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVE-2009-1151 unknown 2.5 KEVEXPFIX debian debian 4y ago Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
CVE-2009-0927 unknown 2.5 KEVEXP 4y ago Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
CVE-2005-2773 unknown 2.5 KEVEXP 4y ago HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
CVE-2019-1405 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-1322 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated conte…
CVE-2019-1253 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.