Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2020-9281 |
|
Cross-Site Scripting (XSS) in ckeditor (CVE-2020-9281)
cross-site scripting in ckeditor (CVE-2020-9281). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-9548 |
|
Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9546 |
|
Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
|
| CVE-2019-17569 |
|
Vulnerability in apache (CVE-2019-17569)
vulnerability in apache (CVE-2019-17569). Risk of unauthorized operations or information disclosure.
|
| CVE-2011-4088 |
|
ABRT might allow attackers to obtain sensitive information from crash reports.
ABRT might allow attackers to obtain sensitive information from crash reports.
|
| CVE-2019-17571 |
|
Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
|
| CVE-2019-16779 |
|
Vulnerability in excon-project (CVE-2019-16779)
vulnerability in excon-project (CVE-2019-16779). Confidential information can be exposed externally.
|
| CVE-2019-19378 |
|
Out-of-Bounds Write in c (CVE-2019-19378)
out-of-bounds write in c (CVE-2019-19378). Successful exploitation can lead to full system takeover.
|
| CVE-2019-11135 |
|
Vulnerability in opensuse (CVE-2019-11135)
vulnerability in opensuse (CVE-2019-11135). Confidential information can be exposed externally.
|
| CVE-2019-10219 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2019-10219)
cross-site scripting in redhat (CVE-2019-10219). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-18197 |
|
Use-After-Free in nokogiri (CVE-2019-18197)
vulnerability in nokogiri (CVE-2019-18197). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-16910 |
|
Information Disclosure in arm (CVE-2019-16910)
vulnerability in arm (CVE-2019-16910). Confidential information can be exposed externally.
|
| CVE-2019-16230 |
|
Vulnerability in c (CVE-2019-16230)
vulnerability in c (CVE-2019-16230). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-16168 |
|
Vulnerability in c (CVE-2019-16168)
vulnerability in c (CVE-2019-16168). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-15213 |
|
Use-After-Free in c (CVE-2019-15213)
vulnerability in c (CVE-2019-15213). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-13118 |
|
Vulnerability in nokogiri (CVE-2019-13118)
vulnerability in nokogiri (CVE-2019-13118). Confidential information can be exposed externally. Exploitable via ``numbers.c``. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-13117 |
|
Vulnerability in nokogiri (CVE-2019-13117)
vulnerability in nokogiri (CVE-2019-13117). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-11091 |
|
Vulnerability in intel (CVE-2019-11091)
vulnerability in intel (CVE-2019-11091). Confidential information can be exposed externally.
|
| CVE-2018-12126 |
|
Information Disclosure in intel (CVE-2018-12126)
vulnerability in intel (CVE-2018-12126). Confidential information can be exposed externally.
|
| CVE-2018-12127 |
|
Information Disclosure in intel (CVE-2018-12127)
vulnerability in intel (CVE-2018-12127). Confidential information can be exposed externally.
|
| CVE-2018-12130 |
|
Information Disclosure in intel (CVE-2018-12130)
vulnerability in intel (CVE-2018-12130). Confidential information can be exposed externally.
|
| CVE-2019-11840 |
|
Vulnerability in c (CVE-2019-11840)
vulnerability in c (CVE-2019-11840). Confidential information can be exposed externally.
|
| CVE-2019-11068 |
|
Vulnerability in nokogiri (CVE-2019-11068)
vulnerability in nokogiri (CVE-2019-11068). Successful exploitation can lead to full system takeover. Exploitable via ``xsltCheckRead``. Mitigation: upgrade to `1.10.3` or later.
|
| CVE-2019-7317 |
|
Use-After-Free in c (CVE-2019-7317)
vulnerability in c (CVE-2019-7317). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-6109 |
|
Vulnerability in c (CVE-2019-6109)
vulnerability in c (CVE-2019-6109). Confidential information can be exposed externally.
|
| CVE-2018-15756 |
|
Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-10902 |
|
Vulnerability in c (CVE-2018-10902)
vulnerability in c (CVE-2018-10902). Successful exploitation can lead to full system takeover.
|
| CVE-2018-11039 |
|
Vulnerability in spring (CVE-2018-11039)
vulnerability in spring (CVE-2018-11039). Confidential information can be exposed externally.
|
| CVE-2018-3639 |
|
Vulnerability in intel (CVE-2018-3639)
vulnerability in intel (CVE-2018-3639). Confidential information can be exposed externally.
|
| CVE-2018-9988 |
|
Out-of-Bounds Read in arm (CVE-2018-9988)
vulnerability in arm (CVE-2018-9988). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-9989 |
|
Out-of-Bounds Read in arm (CVE-2018-9989)
vulnerability in arm (CVE-2018-9989). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-1862 |
|
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
|
| CVE-2017-5753 |
|
Vulnerability in intel (CVE-2017-5753)
vulnerability in intel (CVE-2017-5753). Confidential information can be exposed externally.
|
| CVE-2017-18005 |
|
Vulnerability in cpp (CVE-2017-18005)
vulnerability in cpp (CVE-2017-18005). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17997 |
|
Vulnerability in c (CVE-2017-17997)
vulnerability in c (CVE-2017-17997). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17975 |
|
Use-After-Free in c (CVE-2017-17975)
vulnerability in c (CVE-2017-17975). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-4978 |
|
Vulnerability in c (CVE-2014-4978)
vulnerability in c (CVE-2014-4978). Data can be tampered with by attackers.
|
| CVE-2014-8119 |
|
Vulnerability in dos (CVE-2014-8119)
vulnerability in dos (CVE-2014-8119). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-8008 |
|
Vulnerability in mediawiki (CVE-2015-8008)
vulnerability in mediawiki (CVE-2015-8008). Confidential information can be exposed externally.
|
| CVE-2017-17760 |
|
Buffer Overflow in cpp (CVE-2017-17760)
vulnerability in cpp (CVE-2017-17760). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-3695 |
|
Vulnerability in c (CVE-2016-3695)
vulnerability in c (CVE-2016-3695). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-16876 |
|
Cross-Site Scripting (XSS) in mistune-project (CVE-2017-16876)
cross-site scripting in mistune-project (CVE-2017-16876). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-4914 |
|
SQL Injection in sqli (CVE-2014-4914)
SQL injection in sqli (CVE-2014-4914). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6914 |
|
Vulnerability in ui (CVE-2016-6914)
vulnerability in ui (CVE-2016-6914). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7156 |
|
Buffer Overflow in dos (CVE-2017-7156)
vulnerability in dos (CVE-2017-7156). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7157 |
|
Buffer Overflow in dos (CVE-2017-7157)
vulnerability in dos (CVE-2017-7157). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7160 |
|
Buffer Overflow in dos (CVE-2017-7160)
vulnerability in dos (CVE-2017-7160). Successful exploitation can lead to full system takeover.
|