Search

Found 1,611 results in 188ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-0147 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
CVE-2017-0022 unknown 1.5 KEV 4y ago Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
CVE-2017-0005 unknown 1.5 KEV 4y ago The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
CVE-2016-6367 unknown 2.5 KEVEXP 4y ago A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
CVE-2016-6366 unknown 2.5 KEVEXP 4y ago A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute cod…
CVE-2016-4657 unknown 2.5 KEVEXP 4y ago Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTM…
CVE-2016-4656 unknown 2.5 KEVEXP 4y ago A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
CVE-2016-4655 unknown 2.5 KEVEXP 4y ago The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2016-3351 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific f…
CVE-2016-3298 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow th…
CVE-2016-0162 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.
CVE-2022-20821 unknown 1.5 KEV 4y ago Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running …
CVE-2021-30883 unknown 1.5 KEV 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
CVE-2021-1048 unknown 1.5 KEVFIX slesdebian debian 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2021-0920 high 9.5 KEVFIX sles rockydebian debian 4y ago Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.
CVE-2020-1027 unknown 1.5 KEV 4y ago An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated …
CVE-2020-0638 unknown 1.5 KEV 4y ago Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
CVE-2019-8720 medium 7.0 KEVFIX sles rockydebian debian 4y ago WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
CVE-2019-7287 unknown 1.5 KEV 4y ago Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.
CVE-2019-7286 unknown 2.5 KEVEXP 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
CVE-2019-18426 unknown 2.5 KEVEXP 4y ago A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2019-1385 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
CVE-2019-13720 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11708 high 10.0 KEVEXPFIX arch archdebian debian rhel 4y ago Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2019-1130 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
CVE-2019-0880 unknown 1.5 KEV 4y ago A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system …
CVE-2019-0703 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
CVE-2019-0676 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of fi…
CVE-2018-8589 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security contex…
CVE-2018-5002 unknown 1.5 KEV 4y ago Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
CVE-2014-3120 unknown 2.5 KEVEXP 4y ago Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2022-30525 unknown 2.5 KEVEXP 4y ago A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CVE-2015-1427 unknown 2.5 KEVEXP 4y ago The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2016-7201 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-7200 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2017-12617 unknown 2.5 KEVEXP sles 4y ago When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv…
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2015-5317 unknown 1.5 KEV 4y ago Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
CVE-2017-9791 unknown 2.5 KEVEXP 4y ago The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVE-2018-8298 unknown 2.5 KEVEXP 4y ago The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2018-14667 unknown 1.5 KEV 4y ago Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute…
CVE-2016-8735 unknown 1.5 KEVFIX slesdebian debian 4y ago Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This C…
CVE-2019-1003030 unknown 2.5 KEVEXP 4y ago Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2013-2251 unknown 2.5 KEVEXP 4y ago Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2017-1000353 unknown 2.5 KEVEXP 4y ago Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would…
CVE-2018-1000861 unknown 2.5 KEVEXP 4y ago A code execution vulnerability exists in the Stapler web framework used by Jenkins
CVE-2019-1003029 unknown 2.5 KEVEXP 4y ago Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
CVE-2022-1388 unknown 2.5 KEVEXP 4y ago F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
CVE-2012-0391 unknown 2.5 KEVEXP 4y ago The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
CVE-2021-1789 medium 7.0 KEVFIX arch arch sles rocky 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2019-8506 low 5.0 KEVEXPFIX rockydebian debian rhel 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2014-4113 unknown 2.5 KEVEXP 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2014-0322 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
CVE-2014-0160 unknown 2.5 KEVEXPFIX debian debian 4y ago The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CVE-2006-1547 unknown 1.5 KEV 4y ago ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).
CVE-2022-29464 unknown 2.5 KEVEXP 4y ago Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
CVE-2022-26904 unknown 2.5 KEVEXP 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-21919 unknown 1.5 KEV 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-0847 high 10.0 KEVEXPFIX arch arch sles rocky 4y ago Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
CVE-2021-41357 unknown 1.5 KEV 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-40450 unknown 1.5 KEV 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-22718 unknown 1.5 KEV 4y ago Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
CVE-2019-3568 unknown 1.5 KEV 4y ago A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
CVE-2018-6882 unknown 1.5 KEV 4y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2022-22960 unknown 2.5 KEVEXP 4y ago VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
CVE-2022-1364 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2019-3929 unknown 2.5 KEVEXP 4y ago Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system comma…
CVE-2019-16057 unknown 1.5 KEV 4y ago The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
CVE-2018-7841 unknown 2.5 KEVEXP 4y ago A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
CVE-2016-4523 unknown 1.5 KEV 4y ago The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
CVE-2014-0780 unknown 2.5 KEVEXP 4y ago InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
CVE-2010-5330 unknown 1.5 KEV 4y ago Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
CVE-2007-3010 unknown 2.5 KEVEXP 4y ago masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
CVE-2022-22954 unknown 2.5 KEVEXP 4y ago VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
CVE-2022-24521 unknown 1.5 KEV 4y ago Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2018-20753 unknown 1.5 KEV 4y ago Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
CVE-2015-5123 unknown 1.5 KEV 4y ago Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-5122 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-3113 unknown 2.5 KEVEXP 4y ago Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-2502 unknown 1.5 KEV 4y ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
CVE-2015-0313 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-0311 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2014-9163 unknown 1.5 KEV 4y ago Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
CVE-2022-23176 unknown 1.5 KEV 4y ago WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
CVE-2021-42287 unknown 1.5 KEV 4y ago Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-42278 unknown 1.5 KEV 4y ago Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-39793 unknown 1.5 KEV 4y ago Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
CVE-2021-27852 unknown 1.5 KEV 4y ago Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
CVE-2021-22600 unknown 1.5 KEVFIX slesdebian debian 4y ago Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly fo…
CVE-2020-2509 unknown 1.5 KEV 4y ago QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
CVE-2017-11317 unknown 2.5 KEVEXP 4y ago Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2021-3156 high 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
CVE-2021-31166 unknown 2.5 KEVEXP 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2017-0148 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
CVE-2022-22675 unknown 1.5 KEV 4y ago macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
CVE-2022-22674 unknown 1.5 KEV 4y ago macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
CVE-2021-45382 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.