Search

Found 2,454 results in 431ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-26950 critical 10.0 EXPFIX arch arch slesdebian debian 6y ago In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox …
CVE-2020-11978 unknown 2.5 KEVEXP 6y ago A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
CVE-2020-5410 unknown 2.5 KEVEXP 6y ago Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
CVE-2020-7656 low 3.5 EXP rocky rhel 6y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2020-10199 unknown 2.5 KEVEXP 6y ago Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.
CVE-2019-17558 unknown 2.5 KEVEXP debian debian 6y ago The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-17554 unknown 1.0 EXP 6y ago Improper Restriction of XML External Entity Reference in Apache Olingo
CVE-2019-13236 unknown 1.0 EXP 7y ago XSS issues in the management interface
CVE-2019-13235 unknown 1.0 EXP 7y ago XSS in login form
CVE-2019-13237 unknown 1.0 EXP 7y ago Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms
CVE-2019-13234 unknown 1.0 EXP 7y ago XSS in search engine
CVE-2019-8690 low 3.5 EXPFIX sles rockydebian debian 7y ago A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTun…
CVE-2019-8689 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8672 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8671 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8623 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8622 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8611 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for …
CVE-2019-8558 low 3.5 EXPFIX rockydebian debian rhel 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.1…
CVE-2019-8518 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.1…
CVE-2018-15811 unknown 2.5 KEVEXP 7y ago DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
CVE-2018-18325 unknown 2.5 KEVEXP 7y ago DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch f…
CVE-2019-11269 unknown 1.0 EXP 7y ago Open Redirect in Spring Security OAuth
CVE-2019-0221 unknown 1.0 EXPFIX slesdebian debian 7y ago The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by…
CVE-2013-7285 unknown 1.0 EXPFIX slesdebian debian 7y ago Command Injection in Xstream
CVE-2019-3799 unknown 1.0 EXP 7y ago Path Traversal in Spring Cloud Config
CVE-2019-9816 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu…
CVE-2019-2697 critical 10.0 EXPFIX slesdebian debian rhel 7y ago RHSA-2019:1238: java-1.8.0-ibm security update (Critical)
CVE-2019-0227 unknown 1.0 EXP debian debian sles 7y ago Server Side Request Forgery in Apache Axis
CVE-2019-2698 critical 10.0 EXPFIX slesdebian debian rhel 7y ago RHSA-2019:1238: java-1.8.0-ibm security update (Critical)
CVE-2019-9813 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firef…
CVE-2019-9810 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR…
CVE-2019-9792 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory c…
CVE-2019-9791 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con…
CVE-2019-11358 low 3.5 EXPFIX arch arch rockydebian debian 7y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2019-0232 unknown 1.0 EXPFIX debian debian 7y ago When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a b…
CVE-2019-3778 unknown 1.0 EXP 7y ago spring-security-oauth and spring-security-oauth2 Open Redirect vulnerability
CVE-2019-5418 unknown 2.5 KEVEXPFIX slesdebian debian 7y ago Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server…
CVE-2019-6340 unknown 2.5 KEVEXP 7y ago In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2018-11770 unknown 1.0 EXP sles 8y ago org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11 Improper Authentication vulnerability
CVE-2018-1321 unknown 1.0 EXP 8y ago High severity vulnerability that affects org.apache.syncope:syncope-core
CVE-2018-1322 unknown 1.0 EXP 8y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache syncope-cope
CVE-2018-11776 unknown 2.5 KEVEXP 8y ago Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defi…
CVE-2017-5638 unknown 2.5 KEVEXP 8y ago Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
CVE-2017-12615 unknown 2.5 KEVEXP sles 8y ago When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it conta…
CVE-2018-1335 unknown 1.0 EXPFIX debian debian 8y ago Command injection in org.apache.tika:tika-core
CVE-2017-9805 unknown 2.5 KEVEXP 8y ago Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
CVE-2017-9822 unknown 2.5 KEVEXP 8y ago DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
CVE-2018-7602 critical 10.0 KEVEXPFIX arch arch 8y ago A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7600 critical 10.0 KEVEXPFIX arch arch 8y ago Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CVE-2017-18001 critical 9.8 10.0 EXP trustwave 9y ago Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, vi…
CVE-2017-17968 critical 9.8 10.0 EXP xi-soft 9y ago A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP respons…
CVE-2017-17932 critical 9.8 10.0 EXP allmediaserver 9y ago A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on th…
CVE-2017-17875 critical 9.8 10.0 EXP jextn 9y ago The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17873 critical 9.8 10.0 EXP vanguard_project 9y ago Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
CVE-2017-17872 critical 9.8 10.0 EXP jextn 9y ago The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17871 critical 9.8 10.0 EXP jextn 9y ago The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVE-2017-17870 critical 9.8 10.0 EXP jbuildozer 9y ago The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
CVE-2017-17849 critical 9.8 10.0 EXP getgosoft 9y ago A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
CVE-2017-17411 critical 9.8 10.0 EXP 9y ago This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exis…
CVE-2012-2576 critical 9.8 10.0 EXP solarwinds 9y ago SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote at…
CVE-2017-17761 critical 9.8 10.0 EXP 9y ago An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. Th…
CVE-2017-17759 critical 9.8 10.0 EXP conarc 9y ago Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request…
CVE-2017-17105 critical 9.8 10.0 EXP 9y ago Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the w…
CVE-2017-16949 critical 9.8 10.0 EXP accesspressthemes 9y ago An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file …
CVE-2017-17721 critical 9.8 10.0 EXP zuuse 9y ago CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorde…
CVE-2017-17651 critical 9.8 10.0 EXP paid_to_read_script_project 9y ago Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
CVE-2017-17645 critical 9.8 10.0 EXP phpautoclassifiedscript 9y ago Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CVE-2017-17643 critical 9.8 10.0 EXP lynda_clone_project 9y ago FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
CVE-2017-17739 critical 9.8 10.0 EXP 9y ago The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
CVE-2017-3195 critical 9.8 10.0 EXP commvault 9y ago Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code executio…
CVE-2017-17672 critical 9.8 10.0 EXP vbulletin 9y ago In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage o…
CVE-2017-17648 critical 9.8 10.0 EXP entrepreneur_dating_script_project 9y ago Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
CVE-2017-17642 critical 9.8 10.0 EXP basic_job_site_script_project 9y ago Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
CVE-2017-17641 critical 9.8 10.0 EXP resume_clone_script_project 9y ago Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
CVE-2017-17640 critical 9.8 10.0 EXP advanced_world_database_project 9y ago Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
CVE-2017-17639 critical 9.8 10.0 EXP muslim_matrimonial_script_project 9y ago Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
CVE-2017-17638 critical 9.8 10.0 EXP groupon_clone_script_project 9y ago Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
CVE-2017-17637 critical 9.8 10.0 EXP car_rental_script_project 9y ago Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
CVE-2017-17636 critical 9.8 10.0 EXP mlm_forced_matrix_project 9y ago MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
CVE-2017-17635 critical 9.8 10.0 EXP mlm_forex_market_plan_script_project 9y ago MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
CVE-2017-17634 critical 9.8 10.0 EXP single_theater_booking_script_project 9y ago Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
CVE-2017-17633 critical 9.8 10.0 EXP multiplex_movie_theater_booking_script_project 9y ago Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
CVE-2017-17632 critical 9.8 10.0 EXP responsive_events_and_movie_ticket_booking_script_project 9y ago Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
CVE-2017-17631 critical 9.8 10.0 EXP multireligion_responsive_matrimonial_project 9y ago Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
CVE-2017-17630 critical 9.8 10.0 EXP yoga_class_script_project 9y ago Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17629 critical 9.8 10.0 EXP secure_e-commerce_script_project 9y ago Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
CVE-2017-17628 critical 9.8 10.0 EXP responsive_realestate_script_project 9y ago Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
CVE-2017-17627 critical 9.8 10.0 EXP readymade_video_sharing_script_project 9y ago Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
CVE-2017-17626 critical 9.8 10.0 EXP readymade_php_classified_script_project 9y ago Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
CVE-2017-17625 critical 9.8 10.0 EXP on_demand_marketplace_script_project 9y ago Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
CVE-2017-17624 critical 9.8 10.0 EXP php_multivendor_ecommerce_project 9y ago PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
CVE-2017-17623 critical 9.8 10.0 EXP opensource_classified_ads_script_project 9y ago Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
CVE-2017-17622 critical 9.8 10.0 EXP online_exam_test_application_script_project 9y ago Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
CVE-2017-17621 critical 9.8 10.0 EXP multivendor_penny_auction_clone_script_project 9y ago Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
CVE-2017-17620 critical 9.8 10.0 EXP lawyer_search_script_project 9y ago Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
CVE-2017-17619 critical 9.8 10.0 EXP laundry_booking_script_project 9y ago Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17618 critical 9.8 10.0 EXP kickstarter_clone_script_project 9y ago Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
CVE-2017-17617 critical 9.8 10.0 EXP foodspotting_clone_script_project 9y ago Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
CVE-2017-17616 critical 9.8 10.0 EXP event_calendar_category_script_project 9y ago Event Search Script 1.0 has SQL Injection via the /event-list city parameter.