Search

Found 15,728 results in 2714ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-21490 unknown FIX debian debian sles 2y ago angular vulnerable to super-linear runtime due to backtracking
CVE-2023-50386 unknown 1.0 EXPFIX debian debian 2y ago Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
CVE-2023-50298 unknown FIX debian debian 2y ago Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
CVE-2023-50292 unknown FIX debian debian 2y ago Apache Solr Schema Designer blindly "trusts" all configsets
CVE-2023-50291 unknown FIX debian debian 2y ago Apache Solr can leak certain passwords due to System Property redaction logic inconsistencies
CVE-2024-25817 unknown FIX debian debian 2y ago Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.
CVE-2024-24821 unknown FIX debian debian sles 2y ago Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the e…
CVE-2024-24680 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with ve…
CVE-2023-4762 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Ch…
CVE-2024-23635 unknown debian debian 2y ago Malicious input can provoke XSS when preserving comments
CVE-2024-24557 unknown FIX debian debian sles 2y ago Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to…
CVE-2018-12608 unknown FIX debian debian 2y ago An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows sy…
CVE-2020-27534 unknown FIX debian debian sles 2y ago util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.T…
CVE-2020-15136 unknown FIX slesdebian debian 2y ago In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on e…
CVE-2020-15114 unknown FIX slesdebian debian 2y ago In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoin…
CVE-2020-15113 unknown FIX slesdebian debian 2y ago In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS con…
CVE-2024-23334 unknown 1.0 EXPFIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static f…
CVE-2024-23829 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must tr…
CVE-2024-22233 unknown FIX debian debian 2y ago Spring Framework server Web DoS Vulnerability
CVE-2017-20189 unknown FIX debian debian 2y ago Clojure classes can be used to craft a serialized object that runs arbitrary code on deserialization
CVE-2024-22421 unknown FIX debian debian 2y ago JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Au…
CVE-2024-22420 unknown FIX debian debian 2y ago JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicio…
CVE-2024-21733 unknown FIX slesdebian debian 2y ago Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL vers…
CVE-2024-0519 unknown 1.5 KEVFIX debian debian 2y ago Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could …
CVE-2023-50290 unknown FIX debian debian 2y ago Apache Solr allows read access to host environmet variables
CVE-2023-46749 unknown FIX debian debian 2y ago Apache Shiro vulnerable to path traversal
CVE-2023-49569 unknown FIX debian debian 2y ago A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, rem…
CVE-2022-3328 unknown FIX debian debian 2y ago Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2023-51441 unknown debian debian sles 2y ago Apache Axis Improper Input Validation vulnerability
CVE-2023-7101 unknown 2.5 KEVEXPFIX slesdebian debian 3y ago Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Num…
CVE-2023-7024 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit …
CVE-2023-51074 unknown FIX debian debian 3y ago json-path Out-of-bounds Write vulnerability
CVE-2023-49568 unknown FIX debian debian 3y ago A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted res…
CVE-2024-2408 low 2.5 FIX rocky slesdebian debian 3y ago RHSA-2023:7877: openssl security update (Low)
CVE-2023-46750 unknown debian debian 3y ago Open redirect in Apache Shiro
CVE-2019-3826 unknown FIX debian debian 3y ago A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prome…
CVE-2023-6481 unknown FIX debian debian 3y ago Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
CVE-2023-49735 unknown debian debian 3y ago Apache Tiles: Unvalidated input may lead to path traversal and XXE
CVE-2023-6345 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. …
CVE-2023-6378 unknown FIX debian debian 3y ago logback serialization vulnerability
CVE-2022-41678 unknown FIX debian debian 3y ago Apache ActiveMQ Deserialization of Untrusted Data vulnerability
CVE-2023-34053 unknown FIX debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2023-49081 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create…
CVE-2023-49082 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even cre…
CVE-2023-33202 unknown FIX debian debian 3y ago Bouncy Castle Denial of Service (DoS)
CVE-2022-46337 unknown FIX debian debian 3y ago Apache Derby: LDAP injection vulnerability in authenticator
CVE-2023-5072 unknown FIX debian debian 3y ago Java: DoS Vulnerability in JSON-JAVA
CVE-2023-47627 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parse…
CVE-2023-47641 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protoc…
CVE-2023-47122 unknown FIX debian debian 3y ago Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the loc…
CVE-2023-46735 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` return…
CVE-2023-46734 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Tw…
CVE-2023-46733 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListene…
CVE-2023-46446 unknown FIX debian debian 3y ago An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
CVE-2023-46445 unknown FIX debian debian 3y ago An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
CVE-2023-46737 unknown FIX debian debian sles 3y ago Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high num…
CVE-2023-4641 low 2.5 FIX rhel slesdebian debian 3y ago Low: shadow-utils security and bug fix update
CVE-2023-4016 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7187: procps-ng security update (Low)
CVE-2023-32665 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-32611 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-32573 low 2.5 FIX rhel slesdebian debian 3y ago In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
CVE-2023-2977 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7160: opensc security and bug fix update (Low)
CVE-2023-29499 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-22745 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7166: tpm2-tss security and enhancement update (Low)
CVE-2021-43618 low 2.5 FIX rhelarch arch sles 3y ago Low: gmp security and enhancement update
CVE-2021-3826 low 2.5 FIX rheldebian debian sles 3y ago Low: gdb security update
CVE-2023-43665 unknown FIX slesdebian debian 3y ago In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of …
CVE-2023-41164 unknown FIX slesdebian debian 3y ago In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large …
CVE-2023-46695 unknown FIX slesdebian debian 3y ago An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is s…
CVE-2023-46129 unknown FIX debian debian 3y ago NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recent…
CVE-2023-46604 unknown 2.5 KEVEXPFIX debian debian 3y ago Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class type…
CVE-2023-5631 unknown 1.5 KEVFIX slesdebian debian 3y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
CVE-2023-5752 unknown FIX slesdebian debian 3y ago When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to th…
CVE-2023-31582 unknown FIX slesdebian debian 3y ago jose4j uses weak cryptographic algorithm
CVE-2023-45805 unknown FIX debian debian 3y ago pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source proj…
CVE-2023-44483 unknown FIX debian debian 3y ago Apache Santuario - XML Security for Java are vulnerable to private key disclosure
CVE-2023-44690 unknown debian debian 3y ago Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
CVE-2023-47090 unknown FIX debian debian 3y ago NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the int…
CVE-2024-43806 unknown FIX slesdebian debian 3y ago Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Com…
CVE-2023-45807 unknown debian debian 3y ago OpenSearch Issue with tenant read-only permissions
CVE-2023-38546 low 3.7 3.7 FIX rhelarch arch rocky haxx 3y ago This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application crea…
CVE-2023-44981 unknown FIX slesdebian debian 3y ago Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
CVE-2023-36478 unknown FIX slesdebian debian 3y ago HTTP/2 HPACK integer overflow and buffer allocation
CVE-2023-43643 unknown FIX debian debian 3y ago mXSS in AntiSamy
CVE-2023-44270 unknown FIX debian debian 3y ago An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains part…
CVE-2023-43655 unknown FIX debian debian sles 3y ago Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code exec…
CVE-2023-3223 unknown FIX debian debian 3y ago Undertow vulnerable to denial of service
CVE-2022-4245 unknown FIX debian debian 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-4244 unknown FIX debian debian 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2023-43642 unknown FIX debian debian 3y ago snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
CVE-2023-42810 unknown FIX debian debian 3y ago systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.…
CVE-2015-8371 unknown FIX debian debian 3y ago Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because o…
CVE-2022-28357 unknown FIX debian debian 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2023-4759 unknown FIX slesdebian debian 3y ago Arbitrary File Overwrite in Eclipse JGit
CVE-2023-41900 unknown FIX slesdebian debian 3y ago Jetty's OpenId Revoked authentication allows one request
CVE-2023-40167 unknown FIX slesdebian debian 3y ago Jetty accepts "+" prefixed value in Content-Length
CVE-2023-36479 unknown FIX slesdebian debian 3y ago Jetty vulnerable to errant command quoting in CGI Servlet
CVE-2023-1108 unknown FIX debian debian 3y ago Undertow denial of service vulnerability
CVE-2023-42503 unknown FIX slesdebian debian 3y ago Apache Commons Compress denial of service vulnerability
CVE-2023-26141 unknown FIX debian debian 3y ago Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipu…