Search

Found 14,238 results in 633ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-50290 unknown FIX debian debian 2y ago Apache Solr allows read access to host environmet variables
CVE-2023-46749 unknown FIX debian debian 2y ago Apache Shiro vulnerable to path traversal
CVE-2023-49569 unknown FIX debian debian 2y ago A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, rem…
CVE-2022-3328 unknown FIX debian debian 2y ago Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2023-51441 unknown debian debian sles 2y ago Apache Axis Improper Input Validation vulnerability
CVE-2023-7101 unknown 2.5 KEVEXPFIX slesdebian debian 3y ago Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Num…
CVE-2023-7024 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit …
CVE-2023-51074 unknown FIX debian debian 3y ago json-path Out-of-bounds Write vulnerability
CVE-2023-49568 unknown FIX debian debian 3y ago A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted res…
CVE-2023-46750 unknown debian debian 3y ago Open redirect in Apache Shiro
CVE-2019-3826 unknown FIX debian debian 3y ago A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
CVE-2023-6481 unknown FIX debian debian 3y ago Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
CVE-2023-49735 unknown debian debian 3y ago Apache Tiles: Unvalidated input may lead to path traversal and XXE
CVE-2023-6345 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. …
CVE-2023-6378 unknown FIX debian debian 3y ago logback serialization vulnerability
CVE-2022-41678 unknown FIX debian debian 3y ago Apache ActiveMQ Deserialization of Untrusted Data vulnerability
CVE-2023-34053 unknown FIX debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2023-49081 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create…
CVE-2023-49082 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even cre…
CVE-2023-33202 unknown FIX debian debian 3y ago Bouncy Castle Denial of Service (DoS)
CVE-2022-46337 unknown FIX debian debian 3y ago Apache Derby: LDAP injection vulnerability in authenticator
CVE-2023-5072 unknown FIX debian debian 3y ago Java: DoS Vulnerability in JSON-JAVA
CVE-2023-47627 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parse…
CVE-2023-47641 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protoc…
CVE-2023-47122 unknown FIX debian debian 3y ago Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the loc…
CVE-2023-46735 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` return…
CVE-2023-46734 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Tw…
CVE-2023-46733 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListene…
CVE-2023-46446 unknown FIX debian debian 3y ago An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
CVE-2023-46445 unknown FIX debian debian 3y ago An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
CVE-2023-46737 unknown FIX debian debian sles 3y ago Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high num…
CVE-2023-43665 unknown FIX slesdebian debian 3y ago In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of …
CVE-2023-41164 unknown FIX slesdebian debian 3y ago In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large …
CVE-2023-46695 unknown FIX slesdebian debian 3y ago An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is s…
CVE-2023-46129 unknown FIX debian debian 3y ago NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recent…
CVE-2023-46604 unknown 2.5 KEVEXPFIX debian debian 3y ago Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class type…
CVE-2023-5631 unknown 1.5 KEVFIX slesdebian debian 3y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
CVE-2023-5752 unknown FIX slesdebian debian 3y ago When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to th…
CVE-2023-31582 unknown FIX slesdebian debian 3y ago jose4j uses weak cryptographic algorithm
CVE-2023-45805 unknown FIX debian debian 3y ago pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source proj…
CVE-2023-44483 unknown FIX debian debian 3y ago Apache Santuario - XML Security for Java are vulnerable to private key disclosure
CVE-2023-44690 unknown debian debian 3y ago Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
CVE-2023-47090 unknown FIX debian debian 3y ago NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the int…
CVE-2024-43806 unknown FIX slesdebian debian 3y ago Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Com…
CVE-2023-45807 unknown debian debian 3y ago OpenSearch Issue with tenant read-only permissions
CVE-2023-44981 unknown FIX slesdebian debian 3y ago Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
CVE-2023-36478 unknown FIX slesdebian debian 3y ago HTTP/2 HPACK integer overflow and buffer allocation
CVE-2023-43643 unknown FIX debian debian 3y ago mXSS in AntiSamy
CVE-2023-44270 unknown FIX debian debian 3y ago An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains part…
CVE-2023-43655 unknown FIX debian debian sles 3y ago Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code exec…
CVE-2023-3223 unknown FIX debian debian 3y ago Undertow vulnerable to denial of service
CVE-2022-4245 unknown FIX debian debian 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-4244 unknown FIX debian debian 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2023-43642 unknown FIX debian debian 3y ago snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
CVE-2023-42810 unknown FIX debian debian 3y ago systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.…
CVE-2015-8371 unknown FIX debian debian 3y ago Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because o…
CVE-2022-28357 unknown FIX debian debian 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2023-4759 unknown FIX slesdebian debian 3y ago Arbitrary File Overwrite in Eclipse JGit
CVE-2023-41900 unknown FIX slesdebian debian 3y ago Jetty's OpenId Revoked authentication allows one request
CVE-2023-40167 unknown FIX slesdebian debian 3y ago Jetty accepts "+" prefixed value in Content-Length
CVE-2023-36479 unknown FIX slesdebian debian 3y ago Jetty vulnerable to errant command quoting in CGI Servlet
CVE-2023-1108 unknown FIX debian debian 3y ago Undertow denial of service vulnerability
CVE-2023-42503 unknown FIX slesdebian debian 3y ago Apache Commons Compress denial of service vulnerability
CVE-2023-26141 unknown FIX debian debian 3y ago Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipu…
CVE-2023-41887 unknown FIX debian debian 3y ago OpenRefine Remote Code execution in project import with mysql jdbc url attack
CVE-2023-41886 unknown FIX debian debian 3y ago OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
CVE-2023-40743 unknown FIX debian debian 3y ago Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
CVE-2021-32050 unknown FIX debian debian 3y ago Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data…
CVE-2023-40828 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via expandIfZip method in the extract function
CVE-2023-40827 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via loadpluginPath parameter
CVE-2023-40826 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via the zippluginPath parameter
CVE-2023-40030 unknown FIX debian debian sles 3y ago Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo did not escape Cargo feature names when including them in the report generated…
CVE-2023-40577 unknown FIX slesdebian debian 3y ago Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute…
CVE-2022-44729 unknown FIX debian debian 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-41401 unknown FIX debian debian 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2023-37895 unknown FIX debian debian 3y ago Remote code execution in Apache Jackrabbit
CVE-2023-3637 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2023-34478 unknown debian debian 3y ago Path Traversal in Apache Shiro
CVE-2023-37276 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request pars…
CVE-2022-40896 unknown FIX slesdebian debian 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2023-37476 unknown FIX debian debian 3y ago OpenRefine vulnerable to zip slip in project import
CVE-2023-3635 unknown FIX debian debian 3y ago Okio Signed to Unsigned Conversion Error vulnerability
CVE-2023-32200 unknown FIX debian debian 3y ago Apache Jena Expression Language Injection vulnerability
CVE-2023-35887 unknown FIX debian debian 3y ago Apache MINA SSHD information disclosure vulnerability
CVE-2023-29824 unknown FIX slesdebian debian 3y ago A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
CVE-2023-32732 unknown slesdebian debian 3y ago gRPC connection termination issue
CVE-2023-25399 unknown FIX slesdebian debian 3y ago A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not …
CVE-2023-33201 unknown FIX debian debian sles 3y ago Bouncy Castle For Java LDAP injection vulnerability
CVE-2023-3432 unknown debian debian 3y ago PlantUML Server-Side Request Forgery vulnerability
CVE-2023-3431 unknown debian debian 3y ago PlantUML Improper Access Control vulnerability
CVE-2021-44026 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2020-12641 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVE-2023-34981 unknown FIX slesdebian debian 3y ago A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for th…
CVE-2023-34462 unknown FIX slesdebian debian 3y ago netty-handler SniHandler 16MB allocation
CVE-2023-53159 unknown FIX debian debian 3y ago The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVE-2023-2976 unknown FIX slesdebian debian google 3y ago Guava vulnerable to insecure use of temporary directory
CVE-2023-34624 unknown FIX debian debian 3y ago htmlcleaner vulnerable to stack exhaustion
CVE-2023-3079 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2023-33546 unknown FIX slesdebian debian 3y ago janino vulnerable to denial of service due to stack overflow
CVE-2023-1521 unknown FIX slesdebian debian 3y ago On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (…