Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: products Clear
ID Title
CVE-2020-1064 Vulnerability in microsoft (CVE-2020-1064)
vulnerability in microsoft (CVE-2020-1064). Successful exploitation can lead to full system takeover.
CVE-2020-1066 Privilege Escalation in csharp (CVE-2020-1066)
vulnerability in csharp (CVE-2020-1066). Successful exploitation can lead to full system takeover.
CVE-2020-1056 Vulnerability in microsoft (CVE-2020-1056)
vulnerability in microsoft (CVE-2020-1056). Risk of unauthorized operations or information disclosure.
CVE-2020-1059 Open Redirect in microsoft (CVE-2020-1059)
vulnerability in microsoft (CVE-2020-1059). Risk of unauthorized operations or information disclosure.
CVE-2020-1065 Out-of-Bounds Write in microsoft (CVE-2020-1065)
out-of-bounds write in microsoft (CVE-2020-1065). Risk of unauthorized operations or information disclosure.
CVE-2020-1037 Out-of-Bounds Write in microsoft (CVE-2020-1037)
out-of-bounds write in microsoft (CVE-2020-1037). Risk of unauthorized operations or information disclosure.
CVE-2020-0901 Buffer Overflow in microsoft (CVE-2020-0901)
vulnerability in microsoft (CVE-2020-0901). Successful exploitation can lead to full system takeover.
CVE-2020-1023 Unrestricted File Upload in microsoft (CVE-2020-1023)
vulnerability in microsoft (CVE-2020-1023). Successful exploitation can lead to full system takeover.
CVE-2020-1024 Unrestricted File Upload in microsoft (CVE-2020-1024)
vulnerability in microsoft (CVE-2020-1024). Successful exploitation can lead to full system takeover.
CVE-2020-1035 Buffer Overflow in microsoft (CVE-2020-1035)
vulnerability in microsoft (CVE-2020-1035). Successful exploitation can lead to full system takeover.
CVE-2020-9484 Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
CVE-2020-3315 Vulnerability in cisco (CVE-2020-3315)
vulnerability in cisco (CVE-2020-3315). Risk of unauthorized operations or information disclosure.
CVE-2020-10683 XXE (XML External Entity) in dom4j-project (CVE-2020-10683)
vulnerability in dom4j-project (CVE-2020-10683). Successful exploitation can lead to full system takeover.
CVE-2020-9488 Vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488)
vulnerability in org.apache.logging.log4j:log4j (CVE-2020-9488). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.2` or later.
CVE-2020-11619 Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2020-9548 Unsafe Deserialization in fasterxml (CVE-2020-9548)
vulnerability in fasterxml (CVE-2020-9548). Successful exploitation can lead to full system takeover.
CVE-2020-9546 Unsafe Deserialization in apache (CVE-2020-9546)
vulnerability in apache (CVE-2020-9546). Successful exploitation can lead to full system takeover.
CVE-2019-17569 Vulnerability in apache (CVE-2019-17569)
vulnerability in apache (CVE-2019-17569). Risk of unauthorized operations or information disclosure.
CVE-2019-17571 Unsafe Deserialization in log4j:log4j (CVE-2019-17571)
vulnerability in log4j:log4j (CVE-2019-17571). Successful exploitation can lead to full system takeover.
CVE-2019-19634 Unrestricted File Upload in verot/class.upload.php (CVE-2019-19634)
vulnerability in verot/class.upload.php (CVE-2019-19634). Successful exploitation can lead to full system takeover.
CVE-2019-19576 Unrestricted File Upload in verot/class.upload.php (CVE-2019-19576)
vulnerability in verot/class.upload.php (CVE-2019-19576). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.4` or later.
CVE-2019-13721 Use-After-Free in google (CVE-2019-13721)
vulnerability in google (CVE-2019-13721). Successful exploitation can lead to full system takeover.
CVE-2019-11135 Vulnerability in opensuse (CVE-2019-11135)
vulnerability in opensuse (CVE-2019-11135). Confidential information can be exposed externally.
CVE-2019-10219 Cross-Site Scripting (XSS) in redhat (CVE-2019-10219)
cross-site scripting in redhat (CVE-2019-10219). Risk of unauthorized operations or information disclosure.
CVE-2019-16168 Vulnerability in c (CVE-2019-16168)
vulnerability in c (CVE-2019-16168). Risk of unauthorized operations or information disclosure.
CVE-2019-10086 Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
CVE-2019-14750 Cross-Site Scripting (XSS) in enhancesoft (CVE-2019-14750)
cross-site scripting in enhancesoft (CVE-2019-14750). Risk of unauthorized operations or information disclosure.
CVE-2019-1068 KEV [KEV] Vulnerability in Microsoft sql-server (CVE-2019-1068)
vulnerability in Microsoft sql-server (CVE-2019-1068). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-13118 Vulnerability in nokogiri (CVE-2019-13118)
vulnerability in nokogiri (CVE-2019-13118). Confidential information can be exposed externally. Exploitable via ``numbers.c``. Mitigation: upgrade to `1.10.5` or later.
CVE-2018-16988 Vulnerability in buffalo (CVE-2018-16988)
vulnerability in buffalo (CVE-2018-16988). Successful exploitation can lead to full system takeover.
CVE-2019-11537 Cross-Site Scripting (XSS) in enhancesoft (CVE-2019-11537)
cross-site scripting in enhancesoft (CVE-2019-11537). Risk of unauthorized operations or information disclosure.
CVE-2019-7317 Use-After-Free in c (CVE-2019-7317)
vulnerability in c (CVE-2019-7317). Risk of unauthorized operations or information disclosure.
CVE-2018-15756 Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
CVE-2018-11039 Vulnerability in spring (CVE-2018-11039)
vulnerability in spring (CVE-2018-11039). Confidential information can be exposed externally.
CVE-2018-12649 Vulnerability in misp-project (CVE-2018-12649)
vulnerability in misp-project (CVE-2018-12649). Successful exploitation can lead to full system takeover.
CVE-2018-3639 Vulnerability in intel (CVE-2018-3639)
vulnerability in intel (CVE-2018-3639). Confidential information can be exposed externally.
CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVE-2018-1259 XXE (XML External Entity) in broadcom (CVE-2018-1259)
vulnerability in broadcom (CVE-2018-1259). Confidential information can be exposed externally.
CVE-2018-1274 Vulnerability in dos (CVE-2018-1274)
vulnerability in dos (CVE-2018-1274). Risk of unauthorized operations or information disclosure.
CVE-2018-7192 Cross-Site Scripting (XSS) in enhancesoft (CVE-2018-7192)
cross-site scripting in enhancesoft (CVE-2018-7192). Risk of unauthorized operations or information disclosure.
CVE-2018-7193 Cross-Site Scripting (XSS) in enhancesoft (CVE-2018-7193)
cross-site scripting in enhancesoft (CVE-2018-7193). Risk of unauthorized operations or information disclosure.
CVE-2018-7196 Cross-Site Scripting (XSS) in enhancesoft (CVE-2018-7196)
cross-site scripting in enhancesoft (CVE-2018-7196). Risk of unauthorized operations or information disclosure.
CVE-2017-12174 Vulnerability in apache (CVE-2017-12174)
vulnerability in apache (CVE-2017-12174). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →