Search

Found 1,565 results in 114ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-1770 unknown 1.5 KEV 4y ago Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
CVE-2013-3660 unknown 2.5 KEVEXP 4y ago The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to ga…
CVE-2013-2729 unknown 2.5 KEVEXP 4y ago Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2013-2551 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
CVE-2013-2465 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related …
CVE-2013-1690 unknown 2.5 KEVEXP 4y ago Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execu…
CVE-2012-5076 unknown 2.5 KEVEXP 4y ago The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet coul…
CVE-2012-2539 unknown 1.5 KEV 4y ago Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
CVE-2012-2034 unknown 1.5 KEV 4y ago Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
CVE-2012-0518 unknown 1.5 KEV 4y ago Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
CVE-2011-2005 unknown 2.5 KEVEXP 4y ago afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
CVE-2010-4398 unknown 2.5 KEVEXP 4y ago Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
CVE-2022-26318 unknown 2.5 KEVEXP 4y ago On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
CVE-2022-26143 unknown 1.5 KEV 4y ago A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degr…
CVE-2022-21999 unknown 2.5 KEVEXP 4y ago Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
CVE-2021-42237 unknown 2.5 KEVEXP 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-22941 unknown 1.5 KEV 4y ago Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
CVE-2020-9377 unknown 1.5 KEV 4y ago D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
CVE-2020-9054 unknown 1.5 KEV 4y ago Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.
CVE-2020-25223 unknown 2.5 KEVEXP 4y ago A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
CVE-2020-2506 unknown 1.5 KEV 4y ago QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
CVE-2020-2021 unknown 1.5 KEV 4y ago Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
CVE-2020-1631 unknown 1.5 KEV 4y ago A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZT…
CVE-2019-2616 unknown 2.5 KEVEXP 4y ago Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for au…
CVE-2019-16920 unknown 1.5 KEV 4y ago Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
CVE-2019-15107 unknown 2.5 KEVEXP 4y ago An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
CVE-2019-12991 unknown 2.5 KEVEXP 4y ago Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
CVE-2019-12989 unknown 2.5 KEVEXP 4y ago Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
CVE-2019-10068 unknown 2.5 KEVEXP 4y ago Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
CVE-2019-0903 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could…
CVE-2018-8414 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
CVE-2018-8373 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
CVE-2018-6961 unknown 2.5 KEVEXP 4y ago VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
CVE-2018-14839 unknown 1.5 KEV 4y ago LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
CVE-2018-11138 unknown 2.5 KEVEXP 4y ago The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
CVE-2018-0147 unknown 1.5 KEV 4y ago A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulne…
CVE-2018-0125 unknown 1.5 KEV 4y ago A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
CVE-2017-6334 unknown 2.5 KEVEXP 4y ago dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
CVE-2017-6316 unknown 2.5 KEVEXP 4y ago A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthent…
CVE-2017-3881 unknown 2.5 KEVEXP 4y ago A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected …
CVE-2017-0146 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
CVE-2016-7892 unknown 1.5 KEV 4y ago Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
CVE-2016-4171 unknown 1.5 KEV sles 4y ago Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
CVE-2016-1555 unknown 2.5 KEVEXP 4y ago Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
CVE-2016-11021 unknown 2.5 KEVEXP 4y ago setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
CVE-2016-10174 unknown 2.5 KEVEXP 4y ago The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
CVE-2015-4068 unknown 1.5 KEV 4y ago Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
CVE-2015-3035 unknown 2.5 KEVEXP 4y ago Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVE-2015-1187 unknown 2.5 KEVEXP 4y ago The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
CVE-2015-0666 unknown 1.5 KEV 4y ago Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
CVE-2014-6332 unknown 2.5 KEVEXP 4y ago OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
CVE-2014-6324 unknown 2.5 KEVEXP 4y ago The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
CVE-2014-6287 unknown 2.5 KEVEXP 4y ago The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
CVE-2013-5223 unknown 2.5 KEVEXP 4y ago A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
CVE-2013-4810 unknown 2.5 KEVEXP 4y ago HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet …
CVE-2012-1823 unknown 2.5 KEVEXP 4y ago sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
CVE-2010-4345 unknown 2.5 KEVEXPFIX debian debian 4y ago Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary comm…
CVE-2010-4344 unknown 2.5 KEVEXPFIX debian debian 4y ago Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conj…
CVE-2010-3035 unknown 1.5 KEV 4y ago Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
CVE-2010-2861 unknown 2.5 KEVEXP 4y ago A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVE-2009-2055 unknown 1.5 KEV 4y ago Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
CVE-2009-1151 unknown 2.5 KEVEXPFIX debian debian 4y ago Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
CVE-2009-0927 unknown 2.5 KEVEXP 4y ago Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
CVE-2005-2773 unknown 2.5 KEVEXP 4y ago HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
CVE-2020-5135 unknown 1.5 KEV 4y ago A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
CVE-2019-1405 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-1322 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated conte…
CVE-2019-1315 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted fi…
CVE-2019-1253 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
CVE-2019-1132 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2019-1129 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
CVE-2019-1069 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
CVE-2019-1064 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
CVE-2019-0841 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
CVE-2019-0543 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated conte…
CVE-2018-8120 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2017-0101 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
CVE-2016-3309 unknown 2.5 KEVEXP 4y ago A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in k…
CVE-2015-2546 unknown 1.5 KEV 4y ago The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
CVE-2022-0492 high 7.8 10.0 KEVEXPFIX sles rockydebian debian redhatnetapp 4y ago Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CVE-2022-26486 high 9.5 KEVFIX debian debian sles rocky 4y ago Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2022-26485 high 9.5 KEVFIX slesdebian debian rocky 4y ago Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
CVE-2021-21973 unknown 1.5 KEV 4y ago VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
CVE-2020-8218 unknown 1.5 KEV 4y ago A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
CVE-2019-11581 unknown 1.5 KEV 4y ago Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
CVE-2017-6077 unknown 2.5 KEVEXP 4y ago NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
CVE-2016-6277 unknown 2.5 KEVEXP 4y ago NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
CVE-2013-0631 unknown 1.5 KEV 4y ago Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
CVE-2013-0629 unknown 2.5 KEVEXP 4y ago Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
CVE-2013-0625 unknown 2.5 KEVEXP 4y ago Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
CVE-2009-3960 unknown 2.5 KEVEXP 4y ago Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
CVE-2022-22947 unknown 2.5 KEVEXP 4y ago Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
CVE-2022-20708 unknown 1.5 KEV 4y ago A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary …
CVE-2022-20703 unknown 1.5 KEV 4y ago A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary …
CVE-2022-20701 unknown 1.5 KEV 4y ago A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary …
CVE-2022-20700 unknown 1.5 KEV 4y ago A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary …
CVE-2022-20699 unknown 2.5 KEVEXP 4y ago A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary …
CVE-2021-41379 unknown 1.5 KEV 4y ago Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
CVE-2020-11899 unknown 1.5 KEV 4y ago The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
CVE-2019-1652 unknown 2.5 KEVEXP 4y ago A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges…