Search

Found 18,360 results in 1187ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-46734 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Tw…
CVE-2023-46733 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListene…
CVE-2023-46446 unknown FIX debian debian 3y ago An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
CVE-2023-46445 unknown FIX debian debian 3y ago An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
CVE-2023-46737 unknown FIX debian debian sles 3y ago Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker controlled registry. An attacker who controls a remote registry can return a high num…
CVE-2023-47359 critical 9.8 9.8 FIX debian debian videolan 3y ago Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
CVE-2023-4641 low 2.5 FIX rhel slesdebian debian 3y ago Low: shadow-utils security and bug fix update
CVE-2023-4016 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7187: procps-ng security update (Low)
CVE-2023-32665 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-32611 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-32573 low 2.5 FIX rhel slesdebian debian 3y ago In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
CVE-2023-2977 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7160: opensc security and bug fix update (Low)
CVE-2023-29499 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-22745 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7166: tpm2-tss security and enhancement update (Low)
CVE-2021-43618 low 2.5 FIX rhelarch arch sles 3y ago Low: gmp security and enhancement update
CVE-2021-3826 low 2.5 FIX rheldebian debian sles 3y ago Low: gdb security update
CVE-2023-43665 unknown FIX slesdebian debian 3y ago In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of …
CVE-2023-41164 unknown FIX slesdebian debian 3y ago In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large …
CVE-2023-46695 unknown FIX slesdebian debian 3y ago An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is s…
CVE-2023-46848 critical 9.5 FIX rhel sles rocky 3y ago Critical: squid security update
CVE-2023-46847 critical 9.5 FIX rhel rocky sles 3y ago RHSA-2023:7213: squid:4 security update (Critical)
CVE-2023-46846 critical 9.5 FIX rhel rocky sles 3y ago RHSA-2023:7213: squid:4 security update (Critical)
CVE-2023-46129 unknown FIX debian debian 3y ago NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recent…
CVE-2023-46604 unknown 2.5 KEVEXPFIX debian debian 3y ago Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class type…
CVE-2023-5631 unknown 1.5 KEVFIX slesdebian debian 3y ago Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
CVE-2023-5752 unknown FIX slesdebian debian 3y ago When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to th…
CVE-2023-31582 unknown FIX slesdebian debian 3y ago jose4j uses weak cryptographic algorithm
CVE-2023-45805 unknown FIX debian debian 3y ago pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source proj…
CVE-2023-44483 unknown FIX debian debian 3y ago Apache Santuario - XML Security for Java are vulnerable to private key disclosure
CVE-2023-44690 unknown debian debian 3y ago Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
CVE-2023-47090 unknown FIX debian debian 3y ago NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the int…
CVE-2024-43806 unknown FIX slesdebian debian 3y ago Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Com…
CVE-2023-45807 unknown debian debian 3y ago OpenSearch Issue with tenant read-only permissions
CVE-2023-38546 low 3.7 3.7 FIX rhelarch arch rocky haxx 3y ago This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application crea…
CVE-2023-38545 critical 9.8 9.8 FIX rhelarch archdebian debian haxxnetapp 3y ago This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it…
CVE-2023-45853 critical 9.5 FIX arch arch slesdebian debian 3y ago pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency
CVE-2023-44981 unknown FIX slesdebian debian 3y ago Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
CVE-2023-36478 unknown FIX slesdebian debian 3y ago HTTP/2 HPACK integer overflow and buffer allocation
CVE-2023-43643 unknown FIX debian debian 3y ago mXSS in AntiSamy
CVE-2023-45199 critical 9.8 9.8 FIX debian debian trustedfirmware 3y ago Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVE-2023-44270 unknown FIX debian debian 3y ago An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains part…
CVE-2023-43655 unknown FIX debian debian sles 3y ago Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code exec…
CVE-2023-3223 unknown FIX debian debian 3y ago Undertow vulnerable to denial of service
CVE-2022-4245 unknown FIX debian debian 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-4244 unknown FIX debian debian 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2023-43642 unknown FIX debian debian 3y ago snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
CVE-2023-42810 unknown FIX debian debian 3y ago systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.…
CVE-2015-8371 unknown FIX debian debian 3y ago Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because o…
CVE-2022-28357 unknown FIX debian debian 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2023-4759 unknown FIX slesdebian debian 3y ago Arbitrary File Overwrite in Eclipse JGit
CVE-2023-41900 unknown FIX slesdebian debian 3y ago Jetty's OpenId Revoked authentication allows one request
CVE-2023-40167 unknown FIX slesdebian debian 3y ago Jetty accepts "+" prefixed value in Content-Length
CVE-2023-36479 unknown FIX slesdebian debian 3y ago Jetty vulnerable to errant command quoting in CGI Servlet
CVE-2023-1108 unknown FIX debian debian 3y ago Undertow denial of service vulnerability
CVE-2023-42503 unknown FIX slesdebian debian 3y ago Apache Commons Compress denial of service vulnerability
CVE-2023-26141 unknown FIX debian debian 3y ago Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipu…
CVE-2023-41887 unknown FIX debian debian 3y ago OpenRefine Remote Code execution in project import with mysql jdbc url attack
CVE-2023-41886 unknown FIX debian debian 3y ago OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
CVE-2023-40743 unknown FIX debian debian 3y ago Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
CVE-2021-32050 unknown FIX debian debian 3y ago Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data…
CVE-2023-40828 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via expandIfZip method in the extract function
CVE-2023-40827 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via loadpluginPath parameter
CVE-2023-40826 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via the zippluginPath parameter
CVE-2023-40030 unknown FIX debian debian sles 3y ago Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo did not escape Cargo feature names when including them in the report generated…
CVE-2023-40577 unknown FIX slesdebian debian 3y ago Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute…
CVE-2022-44729 unknown FIX debian debian 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-41401 unknown FIX debian debian 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2023-37895 unknown FIX debian debian 3y ago Remote code execution in Apache Jackrabbit
CVE-2023-3637 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2023-34478 unknown debian debian 3y ago Path Traversal in Apache Shiro
CVE-2023-37276 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request pars…
CVE-2023-22049 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22045 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22036 low 3.7 3.7 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-22006 low 3.1 3.1 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-40896 unknown FIX slesdebian debian 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2023-37476 unknown FIX debian debian 3y ago OpenRefine vulnerable to zip slip in project import
CVE-2023-3635 unknown FIX debian debian 3y ago Okio Signed to Unsigned Conversion Error vulnerability
CVE-2023-32200 unknown FIX debian debian 3y ago Apache Jena Expression Language Injection vulnerability
CVE-2023-35887 unknown FIX debian debian 3y ago Apache MINA SSHD information disclosure vulnerability
CVE-2023-29824 unknown FIX slesdebian debian 3y ago A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
CVE-2023-32732 unknown slesdebian debian 3y ago gRPC connection termination issue
CVE-2023-25399 unknown FIX slesdebian debian 3y ago A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not …
CVE-2023-33201 unknown FIX debian debian sles 3y ago Bouncy Castle For Java LDAP injection vulnerability
CVE-2023-29405 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29404 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29403 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29402 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-20867 low 4.0 KEVFIX rhel rocky sles 3y ago VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the…
CVE-2023-3432 unknown debian debian 3y ago PlantUML Server-Side Request Forgery vulnerability
CVE-2023-3431 unknown debian debian 3y ago PlantUML Improper Access Control vulnerability
CVE-2021-44026 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2020-12641 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVE-2016-9079 critical 10.0 KEVEXPFIX arch arch slesdebian debian 3y ago Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2023-34981 unknown FIX slesdebian debian 3y ago A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for th…
CVE-2023-34462 unknown FIX slesdebian debian 3y ago netty-handler SniHandler 16MB allocation
CVE-2023-53159 unknown FIX debian debian 3y ago The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVE-2023-2976 unknown FIX slesdebian debian google 3y ago Guava vulnerable to insecure use of temporary directory
CVE-2023-34624 unknown FIX debian debian 3y ago htmlcleaner vulnerable to stack exhaustion
CVE-2023-3079 unknown 1.5 KEVFIX debian debian 3y ago Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)