Search

Found 2,911 results in 652ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44596 medium 6.5 EXP 8d ago Yamcs has No Rate Limiting on Authentication Endpoint
CVE-2026-44595 medium 6.5 EXP 8d ago Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
CVE-2026-42568 medium 6.5 EXP 8d ago Yamcs Vulnerable to LDAP Injection in LdapAuthModule
CVE-2026-44376 medium 6.1 7.1 EXP 21d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.p…
CVE-2026-6815 medium 5.9 6.9 EXP casbin 23d ago An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perfo…
CVE-2024-30167 medium 6.3 7.3 EXP 27d ago /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.
CVE-2026-32202 medium 4.3 6.8 KEVEXPFIX windows windows 2mo ago Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33829 medium 4.3 5.3 EXP 2mo ago Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-40271 medium 6.5 EXPFIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which m…
CVE-2025-10370 medium 5.4 6.4 EXP sourcefabric 9mo ago A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script le…
CVE-2025-8550 medium 5.4 6.4 EXP pybbs_project 10mo ago A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/topic/list. The manipulation o…
CVE-2025-8191 medium 5.4 6.4 EXP macrozheng 10mo ago A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The man…
CVE-2025-4123 medium 6.1 7.1 EXPFIX rhel rocky sles grafana 1y ago RHSA-2025:7894: grafana security update (Important)
CVE-2025-24813 medium 8.0 KEVEXPFIX rhel rocky sles 1y ago Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2024-47175 low 3.5 EXPFIX rhel rockydebian debian 2y ago Low: cups security update
CVE-2024-29510 medium 6.5 EXPFIX rheldebian debian sles 2y ago Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
CVE-2023-6710 medium 6.5 EXP rhel 2y ago Moderate: mod_jk and mod_proxy_cluster security update
CVE-2022-3358 low 3.5 EXPFIX rhel slesdebian debian 4y ago Low: openssl security and bug fix update
CVE-2020-10770 medium 6.5 EXPFIX arch arch 4y ago Keycloak vulnerable to Server-Side Request Forgery
CVE-2012-6495 medium 7.0 EXP moinmo 4y ago Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users w…
CVE-2014-3146 medium 6.1 7.1 EXPFIX debian debian lxml 4y ago Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme t…
CVE-2013-4200 medium 6.8 EXP plone 4y ago The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows …
CVE-2019-8506 low 5.0 KEVEXPFIX rockydebian debian rhel 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2009-5065 medium 5.3 EXPFIX debian debian mark_pilgrim 4y ago Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via …
CVE-2021-22204 medium 8.0 KEVEXPFIX arch archdebian debian 5y ago Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
CVE-2021-31807 medium 6.5 EXPFIX arch arch sles rocky 5y ago RHSA-2021:4292: squid:4 security, bug fix, and enhancement update (Moderate)
CVE-2021-31806 medium 6.5 EXPFIX arch arch sles rocky 5y ago RHSA-2021:4292: squid:4 security, bug fix, and enhancement update (Moderate)
CVE-2019-15794 medium 6.5 EXPFIX debian debian rhel 5y ago Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the or…
CVE-2020-1472 medium 8.0 KEVEXPFIX arch arch sles rocky 5y ago Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An at…
CVE-2019-3842 medium 6.5 EXPFIX sles rockydebian debian 5y ago RHSA-2021:1611: systemd security, bug fix, and enhancement update (Moderate)
CVE-2020-28949 medium 8.0 KEVEXPFIX rockydebian debian rhel 6y ago PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and di…
CVE-2019-10098 medium 6.5 EXPFIX debian debian sles rocky 6y ago In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL wi…
CVE-2019-10092 medium 6.5 EXPFIX debian debian sles rocky 6y ago In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instea…
CVE-2019-6977 medium 6.5 EXPFIX arch arch slesdebian debian 6y ago RHSA-2020:4659: gd security update (Moderate)
CVE-2020-9850 medium 6.5 EXPFIX sles rockydebian debian 6y ago A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2…
CVE-2019-8820 medium 6.5 EXPFIX sles rockydebian debian 6y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCl…
CVE-2012-6708 medium 6.5 EXPFIX slesarch arch 6y ago Cross-Site Scripting in jquery
CVE-2020-1938 medium 8.0 KEVEXPFIX sles rockydebian debian 6y ago Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploit…
CVE-2020-7656 low 3.5 EXP rocky rhel 6y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2020-11023 medium 8.0 KEVEXPFIX rhel rocky sles 6y ago JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in …
CVE-2020-11022 medium 6.5 EXPFIX sles rockydebian debian 6y ago RHSA-2020:4847: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2019-9851 medium 6.5 EXPFIX slesdebian debian rhel 6y ago LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection …
CVE-2019-3844 medium 6.5 EXPFIX slesdebian debian rhel 6y ago RHSA-2020:1794: systemd security, bug fix, and enhancement update (Moderate)
CVE-2019-3843 medium 6.5 EXPFIX slesdebian debian rhel 6y ago RHSA-2020:1794: systemd security, bug fix, and enhancement update (Moderate)
CVE-2019-8765 medium 6.5 EXPFIX slesdebian debian rhel 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.
CVE-2019-8649 medium 6.5 EXPFIX slesdebian debian rhel 7y ago A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1…
CVE-2019-6706 medium 6.5 EXPFIX sles rockydebian debian 7y ago RHSA-2019:3706: lua security and bug fix update (Moderate)
CVE-2019-8690 low 3.5 EXPFIX sles rockydebian debian 7y ago A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTun…
CVE-2019-8689 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8672 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6…
CVE-2019-8671 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for …
CVE-2019-8623 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8622 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9…
CVE-2019-8611 low 3.5 EXPFIX rockydebian debianalmalinux almalinux 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for …
CVE-2019-8558 low 3.5 EXPFIX rockydebian debian rhel 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.1…
CVE-2019-8518 low 3.5 EXPFIX sles rockydebian debian 7y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.1…
CVE-2019-6111 medium 6.5 EXPFIX arch arch slesdebian debian 7y ago An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only perf…
CVE-2019-11358 low 3.5 EXPFIX arch arch rockydebian debian 7y ago RHSA-2021:4142: pcs security, bug fix, and enhancement update (Low)
CVE-2018-3639 medium 5.5 6.5 EXPFIX slesdebian debian rhel intelarmredhat 8y ago Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of i…
CVE-2017-5753 medium 5.6 6.6 EXPFIX arch arch slesdebian debian inteloraclesynology 9y ago Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVE-2015-7889 medium 5.5 6.5 EXP 9y ago The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service a…
CVE-2017-7154 medium 6.6 7.6 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows lo…
CVE-2017-13869 medium 5.5 6.5 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13868 medium 5.5 6.5 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13865 medium 5.5 6.5 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-13855 medium 5.5 6.5 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
CVE-2017-17752 medium 6.1 7.1 EXP codecrafters 9y ago Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.…
CVE-2017-17649 medium 6.1 7.1 EXP readymade_video_sharing_script_project 9y ago Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
CVE-2017-17737 medium 6.1 7.1 EXP 9y ago The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.
CVE-2017-12373 medium 5.9 6.9 EXP 9y ago A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive i…
CVE-2017-16787 medium 6.5 7.5 EXP 9y ago The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access.
CVE-2017-17427 medium 5.9 6.9 EXP 9y ago Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). This allows an attacker to decrypt observed …
CVE-2017-17382 medium 5.9 6.9 EXP 9y ago Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote …
CVE-2017-13099 medium 5.9 6.9 EXPFIX debian debian wolfsslarubanetworks 9y ago wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL…
CVE-2017-13098 medium 5.9 6.9 EXPFIX debian debian bouncycastle 9y ago Observable Discrepancy in BouncyCastle
CVE-2017-11906 medium 5.3 6.3 EXP windows windows microsoft 9y ago Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Serv…
CVE-2017-11885 medium 6.6 7.6 EXP windows windows 9y ago Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709…
CVE-2017-1000385 medium 5.9 6.9 EXPFIX slesdebian debian erlang 9y ago The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's priv…
CVE-2017-16884 medium 6.1 7.1 EXP mistserver 9y ago Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.
CVE-2016-1252 medium 5.9 6.9 EXPFIX debian debianubuntu ubuntu debian 9y ago The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 bef…
CVE-2017-16952 medium 5.5 6.5 EXP kmplayer 9y ago KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
CVE-2017-16951 medium 5.5 6.5 EXP audiovalley 9y ago Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file.
CVE-2017-16994 medium 5.5 6.5 EXPFIX slesdebian debian linux-kernel 9y ago The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kern…
CVE-2017-16962 medium 6.1 7.1 EXP communigate 9y ago The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a craf…
CVE-2017-16819 medium 5.4 6.4 EXP 9y ago A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name)…
CVE-2017-16843 medium 5.4 6.4 EXP 9y ago Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic.
CVE-2017-16841 medium 6.1 7.1 EXP lansweeper 9y ago LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
CVE-2017-16836 medium 6.1 7.1 EXP 9y ago Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
CVE-2017-15271 medium 5.9 6.9 EXP psftp 9y ago A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did not automatically res…
CVE-2017-15270 medium 5.3 6.3 EXP psftp 9y ago The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface…
CVE-2017-11831 medium 4.7 5.7 EXP windows windows 9y ago Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Windows Serv…
CVE-2017-11830 medium 5.3 6.3 EXP windows windows 9y ago Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security f…
CVE-2017-16807 medium 5.4 6.4 EXP getkirby 9y ago Kirby XSS Vulnerability
CVE-2017-13849 medium 5.5 6.5 EXPFIX macos macos 9y ago An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows re…
CVE-2017-16781 medium 5.4 6.4 EXP mybb 9y ago The installer in MyBB before 1.8.13 has XSS.
CVE-2017-16568 medium 5.4 6.4 EXP logitech 9y ago Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, w…
CVE-2017-16567 medium 5.4 6.4 EXP logitech 9y ago Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malic…
CVE-2017-14016 medium 6.3 7.3 EXP advantech 9y ago A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying…
CVE-2017-16353 medium 6.5 7.5 EXPFIX slesdebian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The p…
CVE-2017-15878 medium 6.1 7.1 EXP keystonejs 9y ago Cross-Site Scripting in keystone