Search

Found 15,716 results in 1558ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-32050 unknown FIX debian debian 3y ago Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data…
CVE-2023-40828 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via expandIfZip method in the extract function
CVE-2023-40827 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via loadpluginPath parameter
CVE-2023-40826 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via the zippluginPath parameter
CVE-2023-40030 unknown FIX debian debian sles 3y ago Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo did not escape Cargo feature names when including them in the report generated…
CVE-2023-40577 unknown FIX slesdebian debian 3y ago Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute…
CVE-2022-44729 unknown FIX debian debian 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-41401 unknown FIX debian debian 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2023-37895 unknown FIX debian debian 3y ago Remote code execution in Apache Jackrabbit
CVE-2023-3637 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2023-34478 unknown debian debian 3y ago Path Traversal in Apache Shiro
CVE-2023-37276 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request pars…
CVE-2023-22049 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22045 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22036 low 3.7 3.7 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-22006 low 3.1 3.1 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-40896 unknown FIX slesdebian debian 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2023-37476 unknown FIX debian debian 3y ago OpenRefine vulnerable to zip slip in project import
CVE-2023-3635 unknown FIX debian debian 3y ago Okio Signed to Unsigned Conversion Error vulnerability
CVE-2023-32200 unknown FIX debian debian 3y ago Apache Jena Expression Language Injection vulnerability
CVE-2023-35887 unknown FIX debian debian 3y ago Apache MINA SSHD information disclosure vulnerability
CVE-2023-29824 unknown FIX slesdebian debian 3y ago A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
CVE-2023-32732 unknown slesdebian debian 3y ago gRPC connection termination issue
CVE-2023-25399 unknown FIX slesdebian debian 3y ago A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not …
CVE-2023-33201 unknown FIX debian debian sles 3y ago Bouncy Castle For Java LDAP injection vulnerability
CVE-2023-20867 low 4.0 KEVFIX rhel rocky sles 3y ago VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the…
CVE-2023-3432 unknown debian debian 3y ago PlantUML Server-Side Request Forgery vulnerability
CVE-2023-3431 unknown debian debian 3y ago PlantUML Improper Access Control vulnerability
CVE-2021-44026 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2020-12641 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVE-2023-34981 unknown FIX slesdebian debian 3y ago A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for th…
CVE-2023-34462 unknown FIX slesdebian debian 3y ago netty-handler SniHandler 16MB allocation
CVE-2023-53159 unknown FIX debian debian 3y ago The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVE-2023-2976 unknown FIX slesdebian debian google 3y ago Guava vulnerable to insecure use of temporary directory
CVE-2023-34624 unknown FIX debian debian 3y ago htmlcleaner vulnerable to stack exhaustion
CVE-2023-3079 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2023-33546 unknown FIX slesdebian debian 3y ago janino vulnerable to denial of service due to stack overflow
CVE-2023-1521 unknown FIX slesdebian debian 3y ago On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (…
CVE-2023-33199 unknown FIX slesdebian debian 3y ago Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed entry of the `intoto/v0.0.2` type can cause a pan…
CVE-2023-32697 unknown FIX debian debian 3y ago Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
CVE-2023-32409 unknown 1.5 KEVFIX debian debian 3y ago Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impa…
CVE-2023-29159 unknown FIX debian debian 3y ago Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
CVE-2023-53160 unknown FIX slesdebian debian 3y ago The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVE-2023-32082 unknown FIX debian debian sles 3y ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease wh…
CVE-2016-3427 unknown 1.5 KEVFIX slesdebian debian 3y ago Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions …
CVE-2014-0196 unknown 2.5 KEVEXPFIX debian debian 3y ago Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with l…
CVE-2023-31141 unknown debian debian 3y ago OpenSearch issue with fine-grained access control during extremely rare race conditions
CVE-2022-43552 low 2.5 FIX rheldebian debian sles 3y ago A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operat…
CVE-2022-36227 low 2.5 FIX rocky rhel sles 3y ago RHSA-2023:3018: libarchive security update (Low)
CVE-2022-35252 low 2.5 FIX rheldebian debian sles 3y ago When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. …
CVE-2022-28805 low 2.5 FIX rhel slesdebian debian 3y ago Low: lua security update
CVE-2022-1615 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:2987: samba security, bug fix, and enhancement update (Low)
CVE-2023-30551 unknown FIX slesdebian debian 3y ago Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory witho…
CVE-2023-22665 unknown FIX debian debian 3y ago Arbitrary javascript injection in Apache Jena
CVE-2023-2136 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2023-1892 unknown FIX debian debian 3y ago Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVE-2023-29197 unknown FIX debian debian 3y ago guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names a…
CVE-2023-26048 unknown FIX slesdebian debian 3y ago OutOfMemoryError for large multipart without filename in Eclipse Jetty
CVE-2023-21968 low 3.7 3.7 FIX rhel rocky sles oraclenetapp 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2023-26049 unknown FIX slesdebian debian 3y ago Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
CVE-2023-2033 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2023-20863 unknown debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2022-41862 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7016: libpq security update (Low)
CVE-2023-28840 unknown FIX debian debian sles 3y ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon componen…
CVE-2023-28841 unknown FIX debian debian sles 3y ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon componen…
CVE-2023-28842 unknown FIX debian debian sles 3y ago Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon compone…
CVE-2021-28235 unknown FIX slesdebian debian 3y ago Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVE-2022-3038 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2023-20860 unknown debian debian 3y ago Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVE-2023-28628 unknown debian debian 3y ago lambdaisland/uri `authority-regex` returns the wrong authority
CVE-2023-20861 unknown debian debian 3y ago Spring Framework vulnerable to denial of service via specially crafted SpEL expression
CVE-2023-1370 unknown FIX debian debian 3y ago json-smart Uncontrolled Recursion vulnerability
CVE-2023-1436 unknown FIX slesdebian debian 3y ago Jettison vulnerable to infinite recursion
CVE-2021-46877 unknown FIX slesdebian debian 3y ago jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
CVE-2023-24535 unknown FIX debian debian 3y ago Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a…
CVE-2023-26464 unknown FIX debian debian 3y ago Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
CVE-2023-27476 unknown FIX slesdebian debian 3y ago OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lx…
CVE-2022-41918 unknown FIX debian debian 3y ago OpenSearch has issue with fine-grained access control of indices backing data streams
CVE-2022-3277 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2022-4492 unknown FIX debian debian 3y ago Undertow client not checking server identity presented by server certificate in https connections
CVE-2023-26302 unknown FIX slesdebian debian 3y ago Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.
CVE-2023-26303 unknown FIX slesdebian debian 3y ago Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.
CVE-2022-46169 unknown 2.5 KEVEXPFIX debian debian sles 3y ago Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
CVE-2023-30798 unknown FIX debian debian 3y ago There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause e…
CVE-2022-24894 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers…
CVE-2022-24895 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the…
CVE-2022-47951 unknown FIX debian debian sles 3y ago An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0…
CVE-2023-23613 unknown debian debian 3y ago Field-level security issue with .keyword fields in OpenSearch
CVE-2023-23612 unknown debian debian 3y ago Issue with whitespace in JWT roles in OpenSearch
CVE-2023-22742 unknown FIX slesdebian debian 3y ago libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versio…
CVE-2022-47950 unknown FIX slesdebian debian 3y ago An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file c…
CVE-2022-25901 unknown FIX debian debian 3y ago cookiejar Regular Expression Denial of Service via Cookie.parse function
CVE-2023-22602 unknown debian debian 3y ago Apache Shiro Interpretation Conflict vulnerability
CVE-2022-41721 unknown FIX debian debian 3y ago A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from th…
CVE-2022-46176 unknown FIX debian debian sles 3y ago Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could explo…
CVE-2023-22899 unknown FIX debian debian 3y ago Zip4j Origin Validation Error
CVE-2023-22466 unknown FIX debian debian 4y ago Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` …
CVE-2022-45143 unknown FIX slesdebian debian 4y ago The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from use…
CVE-2022-40151 unknown slesdebian debian 4y ago XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow
CVE-2022-41966 unknown FIX slesdebian debian 4y ago XStream can cause Denial of Service via stack overflow