Search

Found 1,516 results in 314ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-29464 unknown 2.5 KEVEXP 4y ago Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
CVE-2022-26904 unknown 2.5 KEVEXP 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-21919 unknown 1.5 KEV 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-41357 unknown 1.5 KEV 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-40450 unknown 1.5 KEV 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-22718 unknown 1.5 KEV 4y ago Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
CVE-2019-3568 unknown 1.5 KEV 4y ago A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
CVE-2018-6882 unknown 1.5 KEV 4y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2022-22960 unknown 2.5 KEVEXP 4y ago VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
CVE-2022-1364 unknown 1.5 KEVFIX debian debian 4y ago Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-3929 unknown 2.5 KEVEXP 4y ago Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system comma…
CVE-2019-16057 unknown 1.5 KEV 4y ago The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
CVE-2018-7841 unknown 2.5 KEVEXP 4y ago A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
CVE-2016-4523 unknown 1.5 KEV 4y ago The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
CVE-2014-0780 unknown 2.5 KEVEXP 4y ago InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
CVE-2010-5330 unknown 1.5 KEV 4y ago Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
CVE-2007-3010 unknown 2.5 KEVEXP 4y ago masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.
CVE-2022-22954 unknown 2.5 KEVEXP 4y ago VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
CVE-2022-24521 unknown 1.5 KEV 4y ago Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2018-20753 unknown 1.5 KEV 4y ago Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
CVE-2015-5123 unknown 1.5 KEV 4y ago Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-5122 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
CVE-2015-3113 unknown 2.5 KEVEXP 4y ago Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-2502 unknown 1.5 KEV 4y ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
CVE-2015-0313 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-0311 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2014-9163 unknown 1.5 KEV 4y ago Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
CVE-2022-23176 unknown 1.5 KEV 4y ago WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
CVE-2021-42287 unknown 1.5 KEV 4y ago Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-42278 unknown 1.5 KEV 4y ago Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-39793 unknown 1.5 KEV 4y ago Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
CVE-2021-27852 unknown 1.5 KEV 4y ago Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
CVE-2021-22600 unknown 1.5 KEVFIX slesdebian debian 4y ago Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly fo…
CVE-2020-2509 unknown 1.5 KEV 4y ago QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
CVE-2017-11317 unknown 2.5 KEVEXP 4y ago Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2021-31166 unknown 2.5 KEVEXP 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2017-0148 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
CVE-2022-22675 unknown 1.5 KEV 4y ago macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
CVE-2022-22674 unknown 1.5 KEV 4y ago macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
CVE-2021-45382 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
CVE-2022-22963 unknown 2.5 KEVEXP 4y ago When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code executio…
CVE-2022-22965 unknown 2.5 KEVEXP debian debian 4y ago Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-26871 unknown 1.5 KEV 4y ago An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
CVE-2022-1040 unknown 2.5 KEVEXP 4y ago An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
CVE-2021-34484 unknown 1.5 KEV 4y ago Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-28799 unknown 1.5 KEV 4y ago QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
CVE-2021-21551 unknown 2.5 KEVEXP 4y ago Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
CVE-2018-10562 unknown 2.5 KEVEXP 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
CVE-2018-10561 unknown 2.5 KEVEXP 4y ago Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
CVE-2022-0543 unknown 2.5 KEVEXPFIX debian debian 4y ago Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CVE-2021-38646 unknown 1.5 KEV 4y ago Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
CVE-2021-34486 unknown 1.5 KEV 4y ago Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
CVE-2021-26085 unknown 2.5 KEVEXP 4y ago Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2021-20028 unknown 1.5 KEV 4y ago SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2019-7483 unknown 1.5 KEV 4y ago In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CVE-2018-8440 unknown 2.5 KEVEXP 4y ago An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
CVE-2018-8406 unknown 1.5 KEV 4y ago An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-8405 unknown 1.5 KEV 4y ago An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2017-0213 unknown 2.5 KEVEXP 4y ago Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
CVE-2017-0059 unknown 2.5 KEVEXP 4y ago Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2017-0037 unknown 2.5 KEVEXP 4y ago Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
CVE-2016-0189 unknown 2.5 KEVEXP 4y ago The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web s…
CVE-2016-0151 unknown 2.5 KEVEXP 4y ago The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
CVE-2016-0040 unknown 2.5 KEVEXP 4y ago The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
CVE-2015-2426 unknown 2.5 KEVEXP 4y ago A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
CVE-2015-2419 unknown 2.5 KEVEXP 4y ago JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2015-1770 unknown 1.5 KEV 4y ago Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
CVE-2013-3660 unknown 2.5 KEVEXP 4y ago The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to ga…
CVE-2013-2729 unknown 2.5 KEVEXP 4y ago Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2013-2551 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
CVE-2013-2465 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related …
CVE-2013-1690 unknown 2.5 KEVEXP 4y ago Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execu…
CVE-2012-5076 unknown 2.5 KEVEXP 4y ago The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet coul…
CVE-2012-2539 unknown 1.5 KEV 4y ago Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
CVE-2012-2034 unknown 1.5 KEV 4y ago Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
CVE-2012-0518 unknown 1.5 KEV 4y ago Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
CVE-2011-2005 unknown 2.5 KEVEXP 4y ago afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
CVE-2010-4398 unknown 2.5 KEVEXP 4y ago Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
CVE-2017-9841 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by …
CVE-2022-26318 unknown 2.5 KEVEXP 4y ago On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
CVE-2022-26143 unknown 1.5 KEV 4y ago A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degr…
CVE-2022-21999 unknown 2.5 KEVEXP 4y ago Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
CVE-2021-42237 unknown 2.5 KEVEXP 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-22941 unknown 1.5 KEV 4y ago Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
CVE-2020-9377 unknown 1.5 KEV 4y ago D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
CVE-2020-9054 unknown 1.5 KEV 4y ago Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.
CVE-2020-7247 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
CVE-2020-25223 unknown 2.5 KEVEXP 4y ago A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
CVE-2020-2506 unknown 1.5 KEV 4y ago QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
CVE-2020-2021 unknown 1.5 KEV 4y ago Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
CVE-2020-1631 unknown 1.5 KEV 4y ago A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZT…
CVE-2019-2616 unknown 2.5 KEVEXP 4y ago Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for au…
CVE-2019-16920 unknown 1.5 KEV 4y ago Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
CVE-2019-15107 unknown 2.5 KEVEXP 4y ago An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
CVE-2019-12991 unknown 2.5 KEVEXP 4y ago Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
CVE-2019-12989 unknown 2.5 KEVEXP 4y ago Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
CVE-2019-11043 critical 10.0 KEVEXPFIX arch arch sles rocky 4y ago In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
CVE-2019-10068 unknown 2.5 KEVEXP 4y ago Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
CVE-2019-0903 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could…
CVE-2018-8414 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.