Search

Found 8,646 results in 618ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-21809 unknown 1.0 EXP 4y ago Moodle command execution vulnerability exists in the default legacy spellchecker plugin
CVE-2021-25282 unknown 1.0 EXP sles 4y ago An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
CVE-2021-25281 unknown 1.0 EXP sles 4y ago An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the mast…
CVE-2021-3291 unknown 1.0 EXP 4y ago Zen Cart vulnerable to authenticated remote code execution
CVE-2020-28413 unknown 1.0 EXP 4y ago MantisBT SQL Injection via mc_project_get_users function
CVE-2020-29471 unknown 1.0 EXP 4y ago OpenCart Stored Cross-Site Scripting
CVE-2020-29470 unknown 1.0 EXP 4y ago OpenCart Cross-site Scripting (XSS) in the Subject field of mail.
CVE-2020-10770 medium 6.5 EXPFIX arch arch 4y ago Keycloak vulnerable to Server-Side Request Forgery
CVE-2020-25592 unknown 1.0 EXP sles 4y ago In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
CVE-2020-16846 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users runnin…
CVE-2020-25540 unknown 1.0 EXP 4y ago ThinkAdmin directory traversal vulnerability
CVE-2020-14209 unknown 1.0 EXP 4y ago Dolibarr Unrestricted Upload of File with Dangerous Type
CVE-2020-2231 unknown 1.0 EXP 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2020-2230 unknown 1.0 EXP 4y ago Jenkins Cross-site Scripting vulnerability in project naming strategy
CVE-2020-2229 unknown 1.0 EXP 4y ago Jenkins Cross-Site Scripting vulnerability in help icons
CVE-2020-1147 critical 10.0 KEVEXP rhel 4y ago Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploi…
CVE-2020-13693 unknown 1.0 EXP 4y ago bbPress unauthenticated privilege-escalation
CVE-2020-11651 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some m…
CVE-2020-11652 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security …
CVE-2020-10963 unknown 1.0 EXP 4y ago FrozenNode Laravel-Administrator unrestricted file upload
CVE-2020-7961 unknown 2.5 KEVEXP 4y ago Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
CVE-2020-8819 unknown 1.0 EXP 4y ago CardGate Payments plugin for WooCommerce does not validate request origin
CVE-2020-7934 unknown 1.0 EXP 4y ago Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet
CVE-2020-2096 unknown 1.0 EXP 4y ago Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
CVE-2020-5504 unknown 1.0 EXPFIX debian debian 4y ago In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this …
CVE-2019-9553 unknown 1.0 EXP 4y ago Bolt Cross-site Scripting via the slug, teaser or title parameters
CVE-2019-10475 unknown 1.0 EXP 4y ago Jenkins build-metrics Plugin reflected cross-site scripting vulnerability
CVE-2019-15715 unknown 1.0 EXP 4y ago MantisBT Remote Code Execution
CVE-2019-11932 unknown 1.0 EXP 4y ago android-gif-drawable Double Free vulnerability
CVE-2019-16173 unknown 1.0 EXP 4y ago Cross-site Scripting in LimeSurvey
CVE-2019-16172 unknown 1.0 EXP 4y ago Cross-site Scripting in LimeSurvey
CVE-2019-15954 unknown 1.0 EXP 4y ago Total.js CMS RCE Vulnerability
CVE-2019-14470 unknown 1.0 EXP 4y ago Cosenary Instagram-PHP-API contains reflected XSS vulnerability
CVE-2019-14322 unknown 1.0 EXPFIX debian debian 4y ago Pallets Werkzeug vulnerable to Path Traversal
CVE-2019-10349 unknown 1.0 EXP 4y ago Jenkins Dependency Graph Viewer Plugin contains Cross-site Scripting
CVE-2019-13068 unknown 1.0 EXP sles 4y ago Grafana Cross-site Scripting vulnerability
CVE-2019-12799 unknown 1.0 EXP 4y ago Shopware Insecure Deserialization Vulnerability
CVE-2019-12616 unknown 1.0 EXPFIX debian debian 4y ago phpMyAdmin CSRF Vulnerability
CVE-2019-6588 unknown 1.0 EXP 4y ago Liferay Portal Allows Cross-Site Scripting (XSS) via the SimpleCaptcha API
CVE-2019-0186 unknown 1.0 EXP 4y ago Cross-site Scripting in Apache Pluto Chatroom demo
CVE-2018-20434 unknown 1.0 EXP 4y ago LibreNMS arbitrary OS commands execution
CVE-2019-10226 unknown 1.0 EXP 4y ago Fat Free CRM Cross-site Scripting vulnerability
CVE-2017-8291 high 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.
CVE-2017-0147 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
CVE-2016-6367 unknown 2.5 KEVEXP 4y ago A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
CVE-2016-6366 unknown 2.5 KEVEXP 4y ago A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute cod…
CVE-2016-4657 unknown 2.5 KEVEXP 4y ago Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTM…
CVE-2016-4656 unknown 2.5 KEVEXP 4y ago A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
CVE-2016-4655 unknown 2.5 KEVEXP 4y ago The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2019-7286 unknown 2.5 KEVEXP 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
CVE-2019-18426 unknown 2.5 KEVEXP 4y ago A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2019-13720 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11708 high 10.0 KEVEXPFIX arch archdebian debian rhel 4y ago Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2014-9390 unknown 1.0 EXPFIX debian debian 4y ago Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; …
CVE-2014-8739 unknown 1.0 EXP 4y ago jQuery File Upload Plugin Unrestricted file upload vulnerability
CVE-2008-6505 unknown 1.0 EXP 4y ago Apache Struts directory traversal vulnerability
CVE-2012-6495 medium 7.0 EXP moinmo 4y ago Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users w…
CVE-2014-3120 unknown 2.5 KEVEXP 4y ago Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2008-6504 unknown 1.0 EXP 4y ago Improper Input Validation in OpenSymphony XWork
CVE-2022-30781 unknown 1.0 EXP 4y ago Shell command injection in gitea in code.gitea.io/gitea
CVE-2022-30525 unknown 2.5 KEVEXP 4y ago A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CVE-2014-3146 medium 6.1 7.1 EXPFIX debian debian lxml 4y ago Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme t…
CVE-2018-7490 unknown 1.0 EXPFIX debian debian 4y ago uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
CVE-2018-10188 unknown 1.0 EXPFIX debian debian 4y ago phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution
CVE-2018-10366 unknown 1.0 EXP 4y ago User Plugin for October CSS Allows XSS
CVE-2018-10094 unknown 1.0 EXP 4y ago Dolibarr SQL injection vulnerability
CVE-2018-11564 unknown 1.0 EXP 4y ago Pagekit Stored Cross-site Scripting
CVE-2017-15367 unknown 1.0 EXP 4y ago Bacula-web SQL Injection Vulnerabilities
CVE-2013-4200 medium 6.8 EXP plone 4y ago The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows …
CVE-2015-1427 unknown 2.5 KEVEXP 4y ago The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2008-5518 unknown 1.0 EXP 4y ago Apache Geronimo Application Server multiple directory traversal vulnerabilities
CVE-2008-5619 unknown 1.0 EXPFIX debian debian 4y ago html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attack…
CVE-2008-6540 unknown 1.0 EXP 4y ago DotNetNuke Default Machine Key Exposure
CVE-2018-14058 unknown 1.0 EXP 4y ago Pimcore SQLi Vulnerability
CVE-2018-14057 unknown 1.0 EXP 4y ago Pimcore CSRF Vulnerability
CVE-2016-7201 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-7200 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2018-15845 unknown 1.0 EXP 4y ago Gleez CMS CSRF Allows Adding of Administrator Accounts
CVE-2018-14059 unknown 1.0 EXP 4y ago Pimcore XSS Vulnerability
CVE-2018-14840 unknown 1.0 EXP 4y ago Subrion CMS Cross-site Scripting
CVE-2018-18548 unknown 1.0 EXP 4y ago ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
CVE-2018-19246 unknown 1.0 EXP 4y ago LFI in PHP-Proxy 5.1.0
CVE-2018-19458 unknown 1.0 EXP 4y ago Unauthenticated File Read in PHP Proxy
CVE-2018-19933 unknown 1.0 EXP 4y ago Bolt Cross-site Scripting (XSS) via text input click preview button
CVE-2018-19799 unknown 1.0 EXP 4y ago Dolibarr ERP and CRM contain XSS Vulnerability
CVE-2018-1306 unknown 1.0 EXP 4y ago Exposure of Sensitive Information in Apache Pluto
CVE-2018-8718 unknown 1.0 EXP 4y ago Cross-Site Request Forgery in Jenkins Mailer Plugin
CVE-2018-20418 unknown 1.0 EXP 4y ago Craft CMS Cross-site Scripting (XSS) Vulnerability
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2017-12617 unknown 2.5 KEVEXP sles 4y ago When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv…
CVE-2017-1000499 unknown 1.0 EXPFIX debian debian 4y ago phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as dele…
CVE-2017-18357 unknown 1.0 EXP 4y ago Shopware XXE Vulnerability
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2018-1042 unknown 1.0 EXP 4y ago Moodle SSRF Vulnerability
CVE-2019-9648 unknown 1.0 EXP 4y ago CoreFTP Directory Traversal
CVE-2018-9160 unknown 1.0 EXP 4y ago SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
CVE-2018-8947 unknown 1.0 EXP 4y ago Plaintext Storage of Sensitive Information in Laravel Log Viewer before v0.13.0
CVE-2018-8145 unknown 1.0 EXP 4y ago ChakraCore information disclosure vulnerability