Lucene search

K

Server Security Vulnerabilities

cve
cve

CVE-2009-2267

VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VM...

6.6AI Score

0.001EPSS

2009-11-02 03:30 PM
68
cve
cve

CVE-2009-3707

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600...

6.4AI Score

0.47EPSS

2009-10-16 04:30 PM
37
cve
cve

CVE-2009-3731

Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks ...

5.6AI Score

0.003EPSS

2009-12-16 06:30 PM
26
cve
cve

CVE-2009-3732

Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.

6.9AI Score

0.912EPSS

2010-04-12 06:30 PM
37
4
cve
cve

CVE-2009-3733

Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.

6.7AI Score

0.959EPSS

2009-11-02 03:30 PM
143
cve
cve

CVE-2009-4811

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600...

6.4AI Score

0.47EPSS

2010-04-27 03:30 PM
56
cve
cve

CVE-2010-0686

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."

6.5AI Score

0.008EPSS

2010-04-01 07:30 PM
20
cve
cve

CVE-2010-1137

Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual machine.

6AI Score

0.003EPSS

2010-04-01 07:30 PM
43
cve
cve

CVE-2010-1138

The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x ...

6.1AI Score

0.007EPSS

2010-04-12 06:30 PM
28
cve
cve

CVE-2010-1139

Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string s...

6.4AI Score

0.0005EPSS

2010-04-12 06:30 PM
43
cve
cve

CVE-2010-1141

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0...

6.8AI Score

0.028EPSS

2010-04-12 06:30 PM
31
cve
cve

CVE-2010-1142

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0...

6.5AI Score

0.003EPSS

2010-04-12 06:30 PM
38
cve
cve

CVE-2010-1193

Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.

5.5AI Score

0.002EPSS

2010-04-01 07:30 PM
21
cve
cve

CVE-2010-4294

The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x b...

7.8AI Score

0.114EPSS

2010-12-06 09:05 PM
28
cve
cve

CVE-2010-4295

Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via ve...

6.6AI Score

0.001EPSS

2010-12-06 09:05 PM
29
cve
cve

CVE-2010-4296

vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vect...

6.6AI Score

0.001EPSS

2010-12-06 09:05 PM
28
cve
cve

CVE-2011-3825

Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Validate.php and certain other files.

6.3AI Score

0.002EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2017-20113

A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

5.4CVSS

5.7AI Score

0.001EPSS

2022-06-29 05:15 PM
28
12
cve
cve

CVE-2017-20114

A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotel...

5.4CVSS

5.8AI Score

0.001EPSS

2022-06-29 05:15 PM
21
12
cve
cve

CVE-2017-20115

A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown processing of the file /admin/conferences/list/. The manipulation of the argument sort leads to basic cross site scripting (Reflected). The attack may be initiated remotely. The exploit...

5.4CVSS

5.7AI Score

0.001EPSS

2022-06-29 05:15 PM
25
11
cve
cve

CVE-2017-20116

A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). It is possible to launch the attack remotely....

5.4CVSS

5.7AI Score

0.001EPSS

2022-06-29 05:15 PM
21
11
cve
cve

CVE-2017-20117

A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclos...

5.4CVSS

5.7AI Score

0.001EPSS

2022-06-29 05:15 PM
25
7
cve
cve

CVE-2017-20118

A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripting (DOM). The attack may be launched remotely. Th...

5.4CVSS

5.6AI Score

0.001EPSS

2022-06-29 05:15 PM
20
3
cve
cve

CVE-2017-20119

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclose...

6.1CVSS

6.6AI Score

0.001EPSS

2022-06-29 05:15 PM
18
3
cve
cve

CVE-2017-20120

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be...

8.8CVSS

8.7AI Score

0.002EPSS

2022-06-29 05:15 PM
27
5
cve
cve

CVE-2017-7855

In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.

6.1CVSS

5.9AI Score

0.001EPSS

2017-08-31 09:29 PM
26
cve
cve

CVE-2018-1000881

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self...

9.8CVSS

9.6AI Score

0.002EPSS

2022-10-03 04:21 PM
21
cve
cve

CVE-2018-10230

Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.

6.1CVSS

6.2AI Score

0.001EPSS

2018-04-19 04:29 PM
28
cve
cve

CVE-2019-0816

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

5.1CVSS

4.9AI Score

0.001EPSS

2019-04-09 03:29 AM
293
cve
cve

CVE-2019-17393

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and p...

9.8CVSS

9.4AI Score

0.002EPSS

2019-10-18 05:15 PM
127
cve
cve

CVE-2019-19766

The Bitwarden server through 1.32.0 has a potentially unwanted KDF.

7.5CVSS

7.5AI Score

0.001EPSS

2019-12-12 07:15 PM
27
cve
cve

CVE-2019-5748

In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.

9.8CVSS

9.4AI Score

0.002EPSS

2019-01-09 05:29 PM
20
cve
cve

CVE-2020-15879

Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).

7.5CVSS

7.5AI Score

0.002EPSS

2020-07-21 05:15 PM
17
cve
cve

CVE-2020-8512

In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.

6.1CVSS

5.9AI Score

0.007EPSS

2020-02-01 12:15 AM
183
cve
cve

CVE-2021-21432

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the ~/.netrc file. Refer to the referenced GitHub Securit...

7.5CVSS

6.3AI Score

0.001EPSS

2021-04-09 06:15 PM
35
2
cve
cve

CVE-2021-36580

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

6.1CVSS

6.2AI Score

0.002EPSS

2023-07-27 06:15 PM
28
cve
cve

CVE-2021-42972

NoMachine Server is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

8.8CVSS

8.8AI Score

0.0004EPSS

2021-12-07 08:15 PM
18
4
cve
cve

CVE-2021-42973

NoMachine Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

8.8CVSS

8.8AI Score

0.0004EPSS

2021-12-07 08:15 PM
19
4
cve
cve

CVE-2021-43444

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.

7.5CVSS

7.4AI Score

0.001EPSS

2023-01-23 03:15 PM
23
cve
cve

CVE-2021-43445

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.

9.8CVSS

9.4AI Score

0.001EPSS

2023-01-23 03:15 PM
17
cve
cve

CVE-2021-43446

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.

6.1CVSS

5.9AI Score

0.001EPSS

2023-01-23 03:15 PM
16
cve
cve

CVE-2021-43447

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.

7.5CVSS

7.6AI Score

0.001EPSS

2023-01-23 03:15 PM
13
cve
cve

CVE-2021-43448

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.

5.3CVSS

5.1AI Score

0.001EPSS

2023-01-23 03:15 PM
18
cve
cve

CVE-2021-43449

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.

8.1CVSS

7.9AI Score

0.001EPSS

2023-01-23 03:15 PM
15
cve
cve

CVE-2022-39395

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to version 0.16.0 and Vela UI prior to version 0.17.0, some default configurations for Vela allow exploitation and container breakouts. Users should upgrade to...

9.9CVSS

9.3AI Score

0.003EPSS

2022-11-10 06:15 PM
93
4
cve
cve

CVE-2022-46181

Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts if another user opened a link. The attacker could...

6.1CVSS

5.2AI Score

0.001EPSS

2022-12-29 07:15 PM
38
cve
cve

CVE-2022-46763

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

8.8CVSS

9.1AI Score

0.002EPSS

2022-12-27 01:15 AM
46
cve
cve

CVE-2022-46764

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

9.8CVSS

10AI Score

0.006EPSS

2022-12-27 01:15 AM
46
cve
cve

CVE-2023-30222

An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.

7.5CVSS

7.2AI Score

0.002EPSS

2023-06-16 05:15 PM
30
cve
cve

CVE-2023-30223

A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.

7.5CVSS

7.6AI Score

0.002EPSS

2023-06-16 05:15 PM
26
Total number of security vulnerabilities101