Search

Found 20,976 results in 891ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-12356 unknown 2.5 KEVEXP 2y ago BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site use…
CVE-2024-45338 unknown FIX debian debian sles 2y ago An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
CVE-2024-56145 unknown 2.5 KEVEXP 2y ago Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
CVE-2024-56128 unknown 2y ago Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
CVE-2023-37940 unknown 2y ago Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page
CVE-2022-23227 unknown 1.5 KEV 2y ago NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
CVE-2021-40407 unknown 1.5 KEV 2y ago Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
CVE-2019-11001 unknown 1.5 KEV 2y ago Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail…
CVE-2018-14933 unknown 2.5 KEVEXP 2y ago NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVE-2024-49194 unknown 2y ago Databricks JDBC Driver Command Injection vulnerability
CVE-2024-12539 unknown 2y ago Elasticsearch Incorrect Authorization vulnerability
CVE-2024-11993 unknown 2y ago Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
CVE-2024-55956 unknown 2.5 KEVEXP 2y ago Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitra…
CVE-2024-35230 unknown 2y ago Welcome and About GeoServer pages communicate version and revision information
CVE-2024-35250 unknown 2.5 KEVEXP 2y ago Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
CVE-2024-20767 unknown 2.5 KEVEXP 2y ago Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVE-2024-55887 unknown 2y ago Ucum-java has an XXE vulnerability in XML parsing
CVE-2024-50623 unknown 1.5 KEV 2y ago Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated priv…
CVE-2024-55662 unknown 2y ago XWiki allows remote code execution through the extension sheet
CVE-2024-55663 unknown 2y ago XWiki Platform has an SQL injection in getdocuments.vm with sort parameter
CVE-2024-55875 unknown 2y ago http4k has a potential XXE (XML External Entity Injection) vulnerability
CVE-2024-55876 unknown 2y ago XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
CVE-2024-55877 unknown 2y ago XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
CVE-2024-55879 unknown 2y ago XWiki allows RCE from script right in configurable sections
CVE-2024-12401 unknown 2y ago cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs
CVE-2024-12397 unknown 2y ago io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
CVE-2024-45337 unknown FIX debian debian sles 2y ago Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerCo…
CVE-2024-53677 unknown sles 2y ago Apache Struts file upload logic is flawed
CVE-2024-49138 unknown 2.5 KEVEXP 2y ago Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
CVE-2024-6156 unknown FIX debian debian 2y ago Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
CVE-2024-6219 unknown FIX debian debian 2y ago Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVE-2024-55601 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks…
CVE-2024-55565 unknown FIX debian debian 2y ago nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVE-2024-53908 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subje…
CVE-2024-53907 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack…
CVE-2024-54140 unknown 2y ago sigstore-java has a vulnerability with bundle verification
CVE-2022-41137 unknown 2y ago Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2024-38829 unknown debian debian 2y ago Spring LDAP data exposure vulnerability
CVE-2024-51378 unknown 2.5 KEVEXP 2y ago CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
CVE-2024-37303 unknown FIX debian debian 2y ago Synapse's unauthenticated writes to the media repository allow planting of problematic content
CVE-2024-37302 unknown FIX debian debian 2y ago Synapse denial of service through media disk space consumption
CVE-2024-45106 unknown 2y ago Apache Ozone: Improper authentication when generating S3 secrets
CVE-2024-11680 unknown 2.5 KEVEXP 2y ago ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP re…
CVE-2024-11667 unknown 1.5 KEV 2y ago Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
CVE-2023-45727 unknown 1.5 KEV 2y ago North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated at…
CVE-2024-53981 unknown FIX slesdebian debian 2y ago python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the…
CVE-2024-53990 unknown debian debian 2y ago AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
CVE-2024-38827 unknown 2y ago Spring Framework has Authorization Bypass for Case Sensitive Comparisons
CVE-2024-35371 unknown 2y ago Ant-Media-Server vulnerable to Improper Output Neutralization for Logs
CVE-2024-36623 unknown FIX debian debian sles 2y ago moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application cr…
CVE-2024-36621 unknown FIX debian debian sles 2y ago moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function result…
CVE-2024-36620 unknown FIX debian debian 2y ago moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-49203 unknown 2y ago Querydsl vulnerable to HQL injection through orderBy
CVE-2024-54004 unknown 2y ago Jenkins Filesystem List Parameter Plugin has Path Traversal vulnerability
CVE-2024-54003 unknown 2y ago Jenkins Simple Queue Plugin has stored cross-site scripting (XSS) vulnerability
CVE-2024-53267 unknown 2y ago sigstore-java has vulnerability with bundle verification
CVE-2024-10039 unknown 2y ago Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
CVE-2024-9666 unknown 2y ago Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
CVE-2024-10451 unknown 2y ago Keycloak Build Process Exposes Sensitive Data
CVE-2024-53916 unknown FIX debian debian 2y ago In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileg…
CVE-2023-28461 unknown 1.5 KEV 2y ago Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
CVE-2024-44308 unknown 1.5 KEVFIX slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing malici…
CVE-2024-21287 unknown 1.5 KEV 2y ago Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this v…
CVE-2024-52797 unknown 2y ago Searching Opencast may cause a denial of service
CVE-2024-38813 unknown 1.5 KEV 2y ago VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by …
CVE-2024-38812 unknown 1.5 KEV 2y ago VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter S…
CVE-2024-31141 unknown 2y ago Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
CVE-2024-52304 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request s…
CVE-2024-52303 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError…
CVE-2024-52506 unknown 2y ago Graylog concurrent PDF report rendering can leak other users' reports
CVE-2024-52318 unknown FIX slesdebian debian 2y ago Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97…
CVE-2024-8781 unknown 2y ago Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abuse. This issue affe…
CVE-2024-52317 unknown FIX slesdebian debian 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us…
CVE-2024-52316 unknown FIX slesdebian debian 2y ago Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception dur…
CVE-2024-38828 unknown debian debian 2y ago Spring MVC controller vulnerable to a DoS attack
CVE-2024-9474 unknown 2.5 KEVEXP 2y ago Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls …
CVE-2024-1212 unknown 2.5 KEVEXP 2y ago Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbi…
CVE-2024-0012 unknown 2.5 KEVEXP 2y ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
CVE-2023-4639 unknown FIX debian debian 2y ago Undertow incorrectly parses cookies
CVE-2023-1419 unknown 2y ago Debezium database connector has a script injection vulnerability
CVE-2024-42499 unknown 2y ago FitNesse Path Traversal
CVE-2024-39610 unknown 2y ago FitNesse Cross-site scripting
CVE-2024-7787 unknown 2y ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Computer Technology vSRM Supplier Relationship Management System allows Reflected XSS,…
CVE-2024-9465 unknown 1.5 KEV 2y ago Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configu…
CVE-2024-9463 unknown 1.5 KEV 2y ago Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of use…
CVE-2024-52554 unknown 2y ago Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin
CVE-2024-52553 unknown 2y ago Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
CVE-2024-52552 unknown 2y ago Stored XSS vulnerability in Jenkins Authorize Project Plugin
CVE-2024-52551 unknown 2y ago Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
CVE-2024-52550 unknown 2y ago Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin
CVE-2024-52549 unknown 2y ago Missing permission check in Jenkins Script Security Plugin
CVE-2024-51996 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted i…
CVE-2024-47535 unknown FIX slesdebian debian 2y ago Denial of Service attack on windows app using netty
CVE-2024-8074 unknown 2y ago Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2…
CVE-2024-49039 unknown 1.5 KEV 2y ago Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access pr…
CVE-2024-43451 unknown 1.5 KEV 2y ago Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this h…
CVE-2021-41277 unknown 1.5 KEV 2y ago Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
CVE-2021-26086 unknown 2.5 KEVEXP 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2014-2120 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML…
CVE-2024-51135 unknown 2y ago powertac-server XML External Entity vulnerability