Search

Found 5,019 results in 623ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-14287 high 9.0 EXPFIX arch arch slesdebian debian 7y ago In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a cra…
CVE-2019-11599 high 9.0 EXPFIX slesdebian debian rhel 7y ago The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sen…
CVE-2019-1125 high 9.0 EXPFIX slesdebian debian rhel 7y ago An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged …
CVE-2018-15811 unknown 2.5 KEVEXP 7y ago DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
CVE-2018-18325 unknown 2.5 KEVEXP 7y ago DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch f…
CVE-2019-12735 high 9.0 EXPFIX arch arch slesdebian debian 7y ago RHSA-2019:1619: vim security update (Important)
CVE-2019-11706 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-11705 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-11704 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-11703 high 9.0 EXPFIX arch arch slesdebian debian 7y ago multiple issues in thunderbird
CVE-2019-9213 high 9.0 EXPFIX slesdebian debian rhel 7y ago In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SM…
CVE-2019-11269 unknown 1.0 EXP 7y ago Open Redirect in Spring Security OAuth
CVE-2019-0221 unknown 1.0 EXPFIX slesdebian debian 7y ago The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by…
CVE-2013-7285 unknown 1.0 EXPFIX slesdebian debian 7y ago Command Injection in Xstream
CVE-2019-3799 unknown 1.0 EXP 7y ago Path Traversal in Spring Cloud Config
CVE-2019-9816 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu…
CVE-2019-2697 critical 10.0 EXPFIX slesdebian debian rhel 7y ago RHSA-2019:1238: java-1.8.0-ibm security update (Critical)
CVE-2019-0227 unknown 1.0 EXP debian debian sles 7y ago Server Side Request Forgery in Apache Axis
CVE-2019-2698 critical 10.0 EXPFIX slesdebian debian rhel 7y ago RHSA-2019:1238: java-1.8.0-ibm security update (Critical)
CVE-2019-5736 high 9.0 EXPFIX arch arch sles rocky 7y ago RHSA-2019:0975: container-tools:rhel8 security and bug fix update (Important)
CVE-2019-9813 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firef…
CVE-2019-9810 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR…
CVE-2019-9792 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory c…
CVE-2019-9791 critical 10.0 EXPFIX arch arch slesdebian debian 7y ago The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con…
CVE-2019-6116 high 9.0 EXPFIX arch arch slesdebian debian 7y ago RHSA-2019:0971: ghostscript security update (Important)
CVE-2019-11358 low 3.5 EXPFIX arch arch rockydebian debian 7y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2019-0232 unknown 1.0 EXPFIX debian debian 7y ago When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a b…
CVE-2019-3778 unknown 1.0 EXP 7y ago spring-security-oauth and spring-security-oauth2 Open Redirect vulnerability
CVE-2019-5418 unknown 2.5 KEVEXPFIX slesdebian debian 7y ago Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server…
CVE-2019-6340 unknown 2.5 KEVEXP 7y ago In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2018-11770 unknown 1.0 EXP sles 8y ago org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11 Improper Authentication vulnerability
CVE-2018-1321 unknown 1.0 EXP 8y ago High severity vulnerability that affects org.apache.syncope:syncope-core
CVE-2018-1322 unknown 1.0 EXP 8y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache syncope-cope
CVE-2018-11776 unknown 2.5 KEVEXP 8y ago Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defi…
CVE-2017-5638 unknown 2.5 KEVEXP 8y ago Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
CVE-2018-11784 high 9.0 EXPFIX sles rockydebian debian 8y ago When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/f…
CVE-2017-12615 unknown 2.5 KEVEXP sles 8y ago When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it conta…
CVE-2018-1335 unknown 1.0 EXPFIX debian debian 8y ago Command injection in org.apache.tika:tika-core
CVE-2017-9805 unknown 2.5 KEVEXP 8y ago Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
CVE-2017-9822 unknown 2.5 KEVEXP 8y ago DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
CVE-2016-9587 high 9.0 EXPFIX debian debian slesarch arch 8y ago Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed …
CVE-2018-7602 critical 10.0 KEVEXPFIX arch arch 8y ago A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7600 critical 10.0 KEVEXPFIX arch arch 8y ago Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CVE-2017-18001 critical 9.8 10.0 EXP trustwave 9y ago Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, vi…
CVE-2015-3302 high 7.5 8.5 EXP thecartpress 9y ago The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by …
CVE-2017-17968 critical 9.8 10.0 EXP xi-soft 9y ago A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP respons…
CVE-2017-15667 high 7.5 8.5 EXP flexense 9y ago In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221.
CVE-2017-17932 critical 9.8 10.0 EXP allmediaserver 9y ago A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on th…
CVE-2017-13056 high 7.8 8.8 EXP tracker-software 9y ago The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
CVE-2016-6914 high 7.8 8.8 EXP ui 9y ago Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
CVE-2017-17876 high 7.5 8.5 EXP iwcnetwork 9y ago Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
CVE-2017-17875 critical 9.8 10.0 EXP jextn 9y ago The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17874 high 8.8 9.8 EXP vanguard_project 9y ago Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
CVE-2017-17873 critical 9.8 10.0 EXP vanguard_project 9y ago Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
CVE-2017-17872 critical 9.8 10.0 EXP jextn 9y ago The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17871 critical 9.8 10.0 EXP jextn 9y ago The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVE-2017-17870 critical 9.8 10.0 EXP jbuildozer 9y ago The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
CVE-2017-17849 critical 9.8 10.0 EXP getgosoft 9y ago A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
CVE-2017-16995 high 7.8 8.8 EXPFIX arch archdebian debian linux-kernel 9y ago The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by lev…
CVE-2017-13878 high 7.1 8.1 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows local users to bypass intended memory-read res…
CVE-2017-13876 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13875 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privi…
CVE-2017-13867 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13861 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows a…
CVE-2017-13847 high 7.8 8.8 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary co…
CVE-2017-17692 high 7.5 8.5 EXP samsung 9y ago Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the …
CVE-2017-17411 critical 9.8 10.0 EXP 9y ago This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exis…
CVE-2017-5262 high 8.0 9.0 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
CVE-2017-5261 high 8.8 9.8 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to …
CVE-2017-5260 high 8.8 9.8 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' acco…
CVE-2017-5259 high 8.8 9.8 EXP 9y ago In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/sysc…
CVE-2017-5255 high 8.8 9.8 EXP 9y ago In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-…
CVE-2017-5254 high 8.8 9.8 EXP 9y ago In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after di…
CVE-2012-2576 critical 9.8 10.0 EXP solarwinds 9y ago SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote at…
CVE-2017-17761 critical 9.8 10.0 EXP 9y ago An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. Th…
CVE-2017-17088 high 7.5 8.5 EXP flexense 9y ago The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header …
CVE-2017-15049 high 8.8 9.8 EXP zoom 9y ago The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary…
CVE-2017-15048 high 8.8 9.8 EXP zoom 9y ago Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handle…
CVE-2017-17759 critical 9.8 10.0 EXP conarc 9y ago Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request…
CVE-2017-17105 critical 9.8 10.0 EXP 9y ago Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the w…
CVE-2017-16949 critical 9.8 10.0 EXP accesspressthemes 9y ago An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file …
CVE-2017-17721 critical 9.8 10.0 EXP zuuse 9y ago CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorde…
CVE-2017-17651 critical 9.8 10.0 EXP paid_to_read_script_project 9y ago Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
CVE-2017-17645 critical 9.8 10.0 EXP phpautoclassifiedscript 9y ago Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CVE-2017-17643 critical 9.8 10.0 EXP lynda_clone_project 9y ago FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
CVE-2017-17739 critical 9.8 10.0 EXP 9y ago The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
CVE-2017-17738 high 7.5 8.5 EXP 9y ago The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.
CVE-2017-3195 critical 9.8 10.0 EXP commvault 9y ago Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code executio…
CVE-2017-17405 high 8.8 9.8 EXP slesdebian debian rhel ruby-lang 9y ago Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument star…
CVE-2017-5264 high 8.8 9.8 EXP rapid7 9y ago Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site requ…
CVE-2017-17672 critical 9.8 10.0 EXP vbulletin 9y ago In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage o…
CVE-2017-17648 critical 9.8 10.0 EXP entrepreneur_dating_script_project 9y ago Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
CVE-2017-17642 critical 9.8 10.0 EXP basic_job_site_script_project 9y ago Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
CVE-2017-17641 critical 9.8 10.0 EXP resume_clone_script_project 9y ago Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
CVE-2017-17640 critical 9.8 10.0 EXP advanced_world_database_project 9y ago Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
CVE-2017-17639 critical 9.8 10.0 EXP muslim_matrimonial_script_project 9y ago Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
CVE-2017-17638 critical 9.8 10.0 EXP groupon_clone_script_project 9y ago Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
CVE-2017-17637 critical 9.8 10.0 EXP car_rental_script_project 9y ago Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
CVE-2017-17636 critical 9.8 10.0 EXP mlm_forced_matrix_project 9y ago MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
CVE-2017-17635 critical 9.8 10.0 EXP mlm_forex_market_plan_script_project 9y ago MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.