Search

Found 18,501 results in 5504ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-44690 unknown debian debian 3y ago Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
CVE-2023-47090 unknown FIX debian debian 3y ago NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the int…
CVE-2024-43806 unknown FIX slesdebian debian 3y ago Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Com…
CVE-2023-45807 unknown debian debian 3y ago OpenSearch Issue with tenant read-only permissions
CVE-2023-38546 low 3.7 3.7 FIX rhelarch arch rocky haxx 3y ago multiple issues in libcurl-compat, curl, libcurl-gnutls
CVE-2023-38545 critical 9.8 9.8 FIX rhelarch archdebian debian haxxnetapp 3y ago multiple issues in libcurl-compat, curl, libcurl-gnutls
CVE-2023-45853 critical 9.5 FIX arch arch slesdebian debian 3y ago pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency
CVE-2023-44981 unknown FIX slesdebian debian 3y ago Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
CVE-2023-36478 unknown FIX slesdebian debian 3y ago HTTP/2 HPACK integer overflow and buffer allocation
CVE-2023-43643 unknown FIX debian debian 3y ago mXSS in AntiSamy
CVE-2023-45199 critical 9.8 9.8 FIX debian debian trustedfirmware 3y ago Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVE-2023-44270 unknown FIX debian debian 3y ago An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains part…
CVE-2023-43655 unknown FIX debian debian sles 3y ago Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code exec…
CVE-2023-3223 unknown FIX debian debian 3y ago Undertow vulnerable to denial of service
CVE-2022-4245 unknown FIX debian debian 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-4244 unknown FIX debian debian 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2023-43642 unknown FIX debian debian 3y ago snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
CVE-2023-42810 unknown FIX debian debian 3y ago systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.…
CVE-2015-8371 unknown FIX debian debian 3y ago Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because o…
CVE-2022-28357 unknown FIX debian debian 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2023-4759 unknown FIX slesdebian debian 3y ago Arbitrary File Overwrite in Eclipse JGit
CVE-2023-41900 unknown FIX slesdebian debian 3y ago Jetty's OpenId Revoked authentication allows one request
CVE-2023-40167 unknown FIX slesdebian debian 3y ago Jetty accepts "+" prefixed value in Content-Length
CVE-2023-36479 unknown FIX slesdebian debian 3y ago Jetty vulnerable to errant command quoting in CGI Servlet
CVE-2023-1108 unknown FIX debian debian 3y ago Undertow denial of service vulnerability
CVE-2023-42503 unknown FIX slesdebian debian 3y ago Apache Commons Compress denial of service vulnerability
CVE-2023-26141 unknown FIX debian debian 3y ago Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipu…
CVE-2023-41887 unknown FIX debian debian 3y ago OpenRefine Remote Code execution in project import with mysql jdbc url attack
CVE-2023-41886 unknown FIX debian debian 3y ago OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
CVE-2023-40743 unknown FIX debian debian 3y ago Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
CVE-2023-41040 unknown FIX slesdebian debianubuntu ubuntu 3y ago GitPython vulnerabilities
CVE-2021-32050 unknown FIX debian debian 3y ago Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data…
CVE-2023-40828 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via expandIfZip method in the extract function
CVE-2023-40827 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via loadpluginPath parameter
CVE-2023-40826 unknown FIX debian debian 3y ago pf4j vulnerable to remote code execution via the zippluginPath parameter
CVE-2023-40030 unknown FIX debian debian sles 3y ago Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo did not escape Cargo feature names when including them in the report generated…
CVE-2023-40577 unknown FIX slesdebian debian 3y ago Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute…
CVE-2022-44729 unknown FIX debian debian 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-41401 unknown FIX debian debian 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2023-37895 unknown FIX debian debian 3y ago Remote code execution in Apache Jackrabbit
CVE-2023-3637 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2023-34478 unknown debian debian 3y ago Path Traversal in Apache Shiro
CVE-2023-37276 unknown FIX slesdebian debian 3y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request pars…
CVE-2023-22049 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22045 low 3.7 3.7 FIX rhel rocky sles 3y ago Moderate: java-1.8.0-openjdk security and bug fix update
CVE-2023-22036 low 3.7 3.7 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2023-22006 low 3.1 3.1 FIX rhel slesdebian debian 3y ago RHSA-2023:4175: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-40896 unknown FIX slesdebian debian 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2023-37476 unknown FIX debian debian 3y ago OpenRefine vulnerable to zip slip in project import
CVE-2023-3635 unknown FIX debian debian 3y ago Okio Signed to Unsigned Conversion Error vulnerability
CVE-2023-32200 unknown FIX debian debian 3y ago Apache Jena Expression Language Injection vulnerability
CVE-2023-35887 unknown FIX debian debian 3y ago Apache MINA SSHD information disclosure vulnerability
CVE-2023-29824 unknown FIX slesdebian debian 3y ago A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
CVE-2023-32732 unknown slesdebian debian 3y ago gRPC connection termination issue
CVE-2023-25399 unknown FIX slesdebian debian 3y ago A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not …
CVE-2023-33201 unknown FIX debian debian sles 3y ago Bouncy Castle For Java LDAP injection vulnerability
CVE-2023-29405 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29404 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29403 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-29402 critical 9.5 FIX rheldebian debian rocky 3y ago RHSA-2023:3922: go-toolset:rhel8 security update (Critical)
CVE-2023-20867 low 4.0 KEVFIX rhel rocky sles 3y ago VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the…
CVE-2023-3432 unknown debian debian 3y ago PlantUML Server-Side Request Forgery vulnerability
CVE-2023-3431 unknown debian debian 3y ago PlantUML Improper Access Control vulnerability
CVE-2021-44026 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail is vulnerable to SQL injection via search or search_params.
CVE-2020-12641 unknown 1.5 KEVFIX debian debian 3y ago Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
CVE-2016-9079 critical 10.0 KEVEXPFIX arch arch slesdebian debian 3y ago Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2023-34981 unknown FIX slesdebian debian 3y ago A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for th…
CVE-2023-34462 unknown FIX slesdebian debian 3y ago netty-handler SniHandler 16MB allocation
CVE-2023-53159 unknown FIX debian debian 3y ago The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVE-2023-2976 unknown FIX slesdebian debian google 3y ago Guava vulnerable to insecure use of temporary directory
CVE-2023-34624 unknown FIX debian debian 3y ago htmlcleaner vulnerable to stack exhaustion
CVE-2023-3079 unknown 1.5 KEVFIX debian debian 3y ago Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-33546 unknown FIX slesdebian debian 3y ago janino vulnerable to denial of service due to stack overflow
CVE-2023-1521 unknown FIX slesdebian debian 3y ago On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (…
CVE-2023-33199 unknown FIX slesdebian debian 3y ago Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed entry of the `intoto/v0.0.2` type can cause a pan…
CVE-2023-32697 unknown FIX debian debian 3y ago Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
CVE-2023-32409 unknown 1.5 KEVFIX debian debian 3y ago The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote a…
CVE-2023-29159 unknown FIX debian debian 3y ago Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
CVE-2023-53160 unknown FIX slesdebian debian 3y ago The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVE-2023-32082 unknown FIX debian debian sles 3y ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease wh…
CVE-2016-3427 unknown 1.5 KEVFIX slesdebian debian 3y ago Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions …
CVE-2014-0196 unknown 2.5 KEVEXPFIX debian debian 3y ago Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with l…
CVE-2023-31141 unknown debian debian 3y ago OpenSearch issue with fine-grained access control during extremely rare race conditions
CVE-2022-43552 low 2.5 FIX rheldebian debian sles 3y ago A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operat…
CVE-2022-38784 unknown FIX arch arch rhel rocky 3y ago unknown in poppler, poppler-glib, poppler-qt6, poppler-qt5
CVE-2022-36227 low 2.5 FIX rocky rhel sles 3y ago RHSA-2023:3018: libarchive security update (Low)
CVE-2022-35252 low 2.5 FIX rheldebian debian sles 3y ago When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. …
CVE-2022-28805 low 2.5 FIX rhel slesdebian debian 3y ago Low: lua security update
CVE-2022-1615 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:2987: samba security, bug fix, and enhancement update (Low)
CVE-2023-30551 unknown FIX slesdebian debian 3y ago Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory witho…
CVE-2023-22665 unknown FIX debian debian 3y ago Arbitrary javascript injection in Apache Jena
CVE-2023-2136 unknown 1.5 KEVFIX debian debian 3y ago Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (…
CVE-2023-1892 unknown FIX debian debian 3y ago Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVE-2023-29197 unknown FIX debian debian 3y ago guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names a…
CVE-2023-26048 unknown FIX slesdebian debian 3y ago OutOfMemoryError for large multipart without filename in Eclipse Jetty
CVE-2023-21968 low 3.7 3.7 FIX rhel rocky sles oraclenetapp 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2023-26049 unknown FIX slesdebian debian 3y ago Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
CVE-2023-2033 unknown 1.5 KEVFIX debian debian 3y ago Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-20863 unknown debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2022-41862 low 2.5 FIX rhel rocky sles 3y ago RHSA-2023:7016: libpq security update (Low)