Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2019-19634 |
|
Unrestricted File Upload in verot/class.upload.php (CVE-2019-19634)
vulnerability in verot/class.upload.php (CVE-2019-19634). Successful exploitation can lead to full system takeover.
|
| CVE-2019-19576 |
|
Unrestricted File Upload in verot/class.upload.php (CVE-2019-19576)
vulnerability in verot/class.upload.php (CVE-2019-19576). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.4` or later.
|
| CVE-2019-19378 |
|
Out-of-Bounds Write in c (CVE-2019-19378)
out-of-bounds write in c (CVE-2019-19378). Successful exploitation can lead to full system takeover.
|
| CVE-2019-18197 |
|
Use-After-Free in nokogiri (CVE-2019-18197)
vulnerability in nokogiri (CVE-2019-18197). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-16230 |
|
Vulnerability in c (CVE-2019-16230)
vulnerability in c (CVE-2019-16230). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-16168 |
|
Vulnerability in c (CVE-2019-16168)
vulnerability in c (CVE-2019-16168). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-15213 |
|
Use-After-Free in c (CVE-2019-15213)
vulnerability in c (CVE-2019-15213). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-14750 |
|
Cross-Site Scripting (XSS) in enhancesoft (CVE-2019-14750)
cross-site scripting in enhancesoft (CVE-2019-14750). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-14286 |
|
Cross-Site Scripting (XSS) in misp-project (CVE-2019-14286)
cross-site scripting in misp-project (CVE-2019-14286). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-13117 |
|
Vulnerability in nokogiri (CVE-2019-13117)
vulnerability in nokogiri (CVE-2019-13117). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-13118 |
|
Vulnerability in nokogiri (CVE-2019-13118)
vulnerability in nokogiri (CVE-2019-13118). Confidential information can be exposed externally. Exploitable via ``numbers.c``. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-11840 |
|
Vulnerability in c (CVE-2019-11840)
vulnerability in c (CVE-2019-11840). Confidential information can be exposed externally.
|
| CVE-2018-16988 |
|
Vulnerability in buffalo (CVE-2018-16988)
vulnerability in buffalo (CVE-2018-16988). Successful exploitation can lead to full system takeover.
|
| CVE-2019-11537 |
|
Cross-Site Scripting (XSS) in enhancesoft (CVE-2019-11537)
cross-site scripting in enhancesoft (CVE-2019-11537). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-7317 |
|
Use-After-Free in c (CVE-2019-7317)
vulnerability in c (CVE-2019-7317). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-6109 |
|
Vulnerability in c (CVE-2019-6109)
vulnerability in c (CVE-2019-6109). Confidential information can be exposed externally.
|
| CVE-2019-6129 |
|
Vulnerability in c (CVE-2019-6129)
vulnerability in c (CVE-2019-6129). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-19211 |
|
Vulnerability in c (CVE-2018-19211)
vulnerability in c (CVE-2018-19211). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-15756 |
|
Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-10902 |
|
Vulnerability in c (CVE-2018-10902)
vulnerability in c (CVE-2018-10902). Successful exploitation can lead to full system takeover.
|
| CVE-2018-1155 |
|
Cross-Site Scripting (XSS) in tenable (CVE-2018-1155)
cross-site scripting in tenable (CVE-2018-1155). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-12649 |
|
Vulnerability in misp-project (CVE-2018-12649)
vulnerability in misp-project (CVE-2018-12649). Successful exploitation can lead to full system takeover.
|
| CVE-2018-1258 |
|
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
|
| CVE-2018-7192 |
|
Cross-Site Scripting (XSS) in enhancesoft (CVE-2018-7192)
cross-site scripting in enhancesoft (CVE-2018-7192). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-7193 |
|
Cross-Site Scripting (XSS) in enhancesoft (CVE-2018-7193)
cross-site scripting in enhancesoft (CVE-2018-7193). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-7196 |
|
Cross-Site Scripting (XSS) in enhancesoft (CVE-2018-7196)
cross-site scripting in enhancesoft (CVE-2018-7196). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-6926 |
|
OS Command Injection in misp-project (CVE-2018-6926)
OS command injection in misp-project (CVE-2018-6926). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8046 |
|
Vulnerability in spring (CVE-2017-8046)
vulnerability in spring (CVE-2017-8046). Successful exploitation can lead to full system takeover.
|
| CVE-2017-18005 |
|
Vulnerability in cpp (CVE-2017-18005)
vulnerability in cpp (CVE-2017-18005). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12810 |
|
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
|
| CVE-2017-17997 |
|
Vulnerability in c (CVE-2017-17997)
vulnerability in c (CVE-2017-17997). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17981 |
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
|
| CVE-2017-17982 |
|
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
|
| CVE-2017-17983 |
|
SQL Injection in sqli (CVE-2017-17983)
SQL injection in sqli (CVE-2017-17983). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17984 |
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
|
| CVE-2017-17985 |
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
|
| CVE-2017-17986 |
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.
|
| CVE-2017-17987 |
|
Unrestricted File Upload in muslim-matrimonial-script-project (CVE-2017-17987)
vulnerability in muslim-matrimonial-script-project (CVE-2017-17987). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17988 |
|
Cross-Site Scripting (XSS) in muslim-matrimonial-script-project (CVE-2017-17988)
cross-site scripting in muslim-matrimonial-script-project (CVE-2017-17988). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17989 |
|
Cross-Site Scripting (XSS) in iwcnetwork (CVE-2017-17989)
cross-site scripting in iwcnetwork (CVE-2017-17989). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17990 |
|
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
|
| CVE-2017-17991 |
|
Cross-Site Scripting (XSS) in iwcnetwork (CVE-2017-17991)
cross-site scripting in iwcnetwork (CVE-2017-17991). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17992 |
|
Path Traversal in path-traversal (CVE-2017-17992)
path traversal in path-traversal (CVE-2017-17992). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17993 |
|
Cross-Site Scripting (XSS) in iwcnetwork (CVE-2017-17993)
cross-site scripting in iwcnetwork (CVE-2017-17993). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17994 |
|
Cross-Site Scripting (XSS) in iwcnetwork (CVE-2017-17994)
cross-site scripting in iwcnetwork (CVE-2017-17994). Risk of unauthorized operations or information disclosure.
|