Search

Found 124 results in 117ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-34197 unknown 2.5 KEVEXP debian debian 2mo ago Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-5281 unknown 1.5 KEVFIX debian debian 2mo ago Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability …
CVE-2026-3910 unknown 1.5 KEVFIX debian debian 3mo ago Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via …
CVE-2026-3909 unknown 1.5 KEVFIX debian debian 3mo ago Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome a…
CVE-2021-30952 medium 7.0 KEVFIX sles rockydebian debian 3mo ago Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code executio…
CVE-2025-68461 unknown 1.5 KEVFIX debian debian 3mo ago RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2026-2441 unknown 2.5 KEVEXPFIX debian debian sles 4mo ago Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple…
CVE-2026-24061 unknown 2.5 KEVEXPFIX debian debian 4mo ago GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2018-14634 unknown 2.5 KEVEXPFIX slesdebian debian 4mo ago Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escala…
CVE-2025-6218 unknown 1.5 KEVFIX debian debian 6mo ago RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2014-6278 unknown 2.5 KEVEXPFIX debian debian 8mo ago GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2025-32463 unknown 2.5 KEVEXPFIX slesdebian debian 8mo ago Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary command…
CVE-2025-10585 unknown 1.5 KEVFIX debian debian 8mo ago Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-6554 unknown 1.5 KEVFIX debian debian 11mo ago Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web bro…
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2024-42009 unknown 1.5 KEVFIX debian debian 1y ago RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desan…
CVE-2025-5419 unknown 1.5 KEVFIX debian debian 1y ago Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could a…
CVE-2024-53150 medium 7.0 KEVFIX rhel rocky sles 1y ago Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.
CVE-2025-24813 medium 8.0 KEVEXPFIX rhel rocky sles 1y ago Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2025-2783 unknown 2.5 KEVEXPFIX debian debian 1y ago Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability…
CVE-2024-50302 medium 5.5 7.0 KEVFIX rhel rocky sles 1y ago The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.
CVE-2025-0411 unknown 1.5 KEVFIX debian debian sles 1y ago 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2024-44308 unknown 1.5 KEVFIX slesdebian debian 2y ago Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
CVE-2024-37383 unknown 2.5 KEVEXPFIX debian debian 2y ago RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
CVE-2017-1000253 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
CVE-2016-3714 unknown 2.5 KEVEXPFIX debian debian 2y ago ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code v…
CVE-2024-7965 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect…
CVE-2024-7971 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that…
CVE-2020-13965 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
CVE-2024-4577 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE-2024-5274 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Ch…
CVE-2024-4947 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2024-4761 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, includ…
CVE-2024-4671 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers…
CVE-2023-43770 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
CVE-2023-4762 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Ch…
CVE-2024-0519 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could …
CVE-2023-7101 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Num…
CVE-2023-7024 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit …
CVE-2023-6345 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. …
CVE-2023-46604 unknown 2.5 KEVEXPFIX debian debian 3y ago Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class type…
CVE-2023-5631 unknown 1.5 KEVFIX slesdebian debian 3y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
CVE-2023-20867 low 4.0 KEVFIX rhel rocky sles 3y ago VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the…
CVE-2021-44026 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2020-12641 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVE-2023-3079 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2023-32409 unknown 1.5 KEVFIX debian debian 3y ago Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impa…
CVE-2016-3427 unknown 1.5 KEVFIX slesdebian debian 3y ago Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions …
CVE-2014-0196 unknown 2.5 KEVEXPFIX debian debian 3y ago Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with l…
CVE-2023-2136 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2023-2033 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-3038 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2022-46169 unknown 2.5 KEVEXPFIX debian debian sles 3y ago Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
CVE-2022-4262 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-4135 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML p…
CVE-2022-2586 medium 7.0 KEVFIX rhelalmalinux almalinux rocky 4y ago Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.
CVE-2022-3723 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-3493 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2022-32893 medium 7.0 KEVFIX arch arch rhel sles 4y ago Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.
CVE-2013-6282 unknown 2.5 KEVEXPFIX debian debian 4y ago The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory whi…
CVE-2013-2596 unknown 1.5 KEVFIX debian debian 4y ago Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.
CVE-2013-2094 unknown 2.5 KEVEXPFIX debian debian 4y ago Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for pri…
CVE-2022-3075 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a craf…
CVE-2022-2294 unknown 1.5 KEVFIX debian debian 4y ago WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerab…
CVE-2022-2856 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability…
CVE-2022-30333 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2019-5825 unknown 2.5 KEVEXPFIX debian debian 4y ago Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2021-1048 unknown 1.5 KEVFIX slesdebian debian 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2019-8720 medium 7.0 KEVFIX sles rockydebian debian 4y ago WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2016-8735 unknown 1.5 KEVFIX slesdebian debian 4y ago Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This C…
CVE-2021-1789 medium 7.0 KEVFIX arch arch sles rocky 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2019-8506 low 5.0 KEVEXPFIX rockydebian debian rhel 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2014-0160 unknown 2.5 KEVEXPFIX debian debian 4y ago The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CVE-2022-1364 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-22600 unknown 1.5 KEVFIX slesdebian debian 4y ago Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly fo…
CVE-2022-22965 unknown 2.5 KEVEXP debian debian 4y ago Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-0543 unknown 2.5 KEVEXPFIX debian debian 4y ago Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CVE-2010-4345 unknown 2.5 KEVEXPFIX debian debian 4y ago Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
CVE-2010-4344 unknown 2.5 KEVEXPFIX debian debian 4y ago Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
CVE-2009-1151 unknown 2.5 KEVEXPFIX debian debian 4y ago Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.
CVE-2015-4902 unknown 1.5 KEVFIX debian debian 4y ago Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
CVE-2015-2590 unknown 1.5 KEVFIX debian debian 4y ago An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
CVE-2022-0609 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-23134 unknown 1.5 KEVFIX slesdebian debian 4y ago Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
CVE-2022-23131 unknown 1.5 KEVFIX slesdebian debian 4y ago Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
CVE-2022-22620 medium 7.0 KEVFIX arch arch sles rocky 4y ago Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers t…
CVE-2014-7169 unknown 2.5 KEVEXPFIX debian debian 4y ago GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vul…
CVE-2014-6271 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
CVE-2020-6572 unknown 1.5 KEVFIX debian debian 5y ago Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2021-45046 unknown 2.5 KEVEXPFIX debian debian sles 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in…
CVE-2021-22204 medium 8.0 KEVEXPFIX arch archdebian debian 5y ago Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
CVE-2021-30858 medium 7.0 KEVFIX arch arch sles rocky 5y ago Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers t…
CVE-2021-30762 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, in…
CVE-2021-30761 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit,…