Lucene search

K

CA Technologies, A Broadcom Company Security Vulnerabilities

osv
osv

Malicious code in watch-a-fast-x-2023online-watching-at-home-ma (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:19 PM
osv

7.1AI Score

2024-06-25 12:55 PM
osv
osv

Malicious code in w-a-t-c-h-scream-6-online-on-streamings-4k-at-home (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:19 PM
osv
osv

Malicious code in w-a-t-c-h-65-online-free-is-on-streaming-on-home (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:19 PM
osv
osv

Malicious code in w-a-t-c-h-john-wick-4-online-on-streamings-4k-at-home (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:19 PM
osv
osv

Malicious code in w-a-t-c-h-creed-3-online-free-is-on-streaming-on-home (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:19 PM
osv
osv

Malicious code in w-a-t-c-h-scream-6-online-free-is-on-streaming-on-home (npm)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:19 PM
veracode
veracode

Infinite Loop

org.soot-oss: soot is vulnerable to Infinite Loop. The vulnerability is due to the retrieveActiveBody function, which allows an attacker to maliciously craft a method to cause excessive resource consumption that can leads to Denial of...

6.7AI Score

EPSS

2024-05-28 04:55 AM
1
nuclei
nuclei

SysAid Technologies 20.3.64 b14 - Cross-Site Scripting

SysAid 20.3.64 b14 contains a cross-site scripting vulnerability via the /KeepAlive.jsp?stamp=...

6.1CVSS

6AI Score

0.001EPSS

2021-09-17 11:55 AM
6
cve
cve

CVE-2023-31426

The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive...

6.8CVSS

6.2AI Score

0.001EPSS

2023-08-01 10:15 PM
41
cve
cve

CVE-2024-35629

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through...

9.8CVSS

7.4AI Score

0.001EPSS

2024-06-04 02:15 PM
1
cve
cve

CVE-2024-35634

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through...

4.9CVSS

7.2AI Score

0.001EPSS

2024-06-04 02:15 PM
1
cve
cve

CVE-2021-28246

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in the library will be...

7.8CVSS

7.5AI Score

0.0005EPSS

2021-03-26 08:15 AM
20
broadcom
broadcom

Remote code execution (RCE) vulnerability in Brocade Fabric OS (CVE-2023-3454)

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow a remote unauthenticated attacker to execute arbitrary code and use this to gain root access to the...

9.1AI Score

0.0004EPSS

2024-04-04 12:00 AM
6
osv
osv

ws affected by a DoS when handling a request with many HTTP headers

Impact A request with a number of headers exceeding the[server.maxHeadersCount][] threshold could be used to crash a ws server. Proof of concept ```js const http = require('http'); const WebSocket = require('ws'); const wss = new WebSocket.Server({ port: 0 }, function () { const chars =...

7.5CVSS

6.5AI Score

0.0004EPSS

2024-06-17 07:09 PM
2
nessus
nessus

7-Technologies AQUIS Detection

AQUIS is installed on the remote Windows host. It is a tool developed by 7-Technologies for hydraulic modeling of a water...

2.3AI Score

2012-03-23 12:00 AM
12
cve
cve

CVE-2021-28248

CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE:...

7.5CVSS

7.8AI Score

0.003EPSS

2021-03-26 08:15 AM
21
nessus
nessus

RealFlex Technologies RealWin Detection

RealWin, a SCADA server package from RealFlex Technologies to monitor and control real-time applications, is installed on the remote Windows...

2.2AI Score

2011-03-30 12:00 AM
13
nessus
nessus

7-Technologies TERMIS Detection

TERMIS is installed on the remote Windows host. It is a tool developed by 7-Technologies for hydraulic modeling of an energy...

1.4AI Score

2012-03-23 12:00 AM
10
ibm
ibm

Security Bulletin: Multiple security vulnerabilities are addressed with IBM Process Mining 1.14.4 IF001

Summary The following security vulnerabilities are addressed with IBM Process Mining 1.14.4 IF001 Vulnerability Details ** CVEID: CVE-2024-22259 DESCRIPTION: **VMware Tanzu Spring Framework could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in...

9.8CVSS

8.8AI Score

0.005EPSS

2024-05-14 08:42 PM
9
osv
osv

Etcd embed auto compaction retention negative value causing a compaction loop or a crash

Impact Data Validation Detail The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs. References Find out more on this vulnerability in...

7.3AI Score

2024-02-03 12:03 AM
6
cve
cve

CVE-2023-5919

A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched...

7.2CVSS

7AI Score

0.001EPSS

2023-11-02 02:15 PM
22
githubexploit

5.3CVSS

5.5AI Score

0.002EPSS

2022-09-08 09:08 AM
285
github
github

ws affected by a DoS when handling a request with many HTTP headers

Impact A request with a number of headers exceeding the[server.maxHeadersCount][] threshold could be used to crash a ws server. Proof of concept ```js const http = require('http'); const WebSocket = require('ws'); const wss = new WebSocket.Server({ port: 0 }, function () { const chars =...

7.5CVSS

6.7AI Score

0.0004EPSS

2024-06-17 07:09 PM
198
wired
wired

A US Company Enabled a North Korean Scam That Raised Money for WMDs

Wyoming’s secretary of state has proposed ways of “preventing fraud and abuse of corporate filings by commercial registered agents” in the aftermath of the scheme’s...

7.3AI Score

2024-06-05 09:30 AM
9
osv
osv

Company admin role gives excessive privileges in eZ Platform Ibexa

Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect. The role / assign policy is typically only given to.....

7.2CVSS

2.7AI Score

0.002EPSS

2023-03-12 06:30 AM
4
osv
osv

Etcd embed auto compaction retention negative value causing a compaction loop or a crash in go.etcd.io/etcd

Etcd embed auto compaction retention negative value causing a compaction loop or a crash in...

7.1AI Score

2024-06-28 03:28 PM
github
github

Podman publishes a malicious image to public registries

Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman.....

8.8CVSS

3.2AI Score

0.002EPSS

2022-04-30 12:00 AM
11
packetstorm

7.4AI Score

2024-05-28 12:00 AM
79
nessus
nessus

Keysight Technologies Sensor Management Server Detection

The Keysight Sensor Management Server (SMS), a component of the Keysight RF Sensor Software, is running on the remote...

0.7AI Score

2022-07-07 12:00 AM
16
nessus
nessus

7-Technologies / Schneider-Electric IGSS Detection

IGSS (Interactive Graphical SCADA System) is installed on the remote Windows host. It is a SCADA system for process control and supervision developed by 7-Technologies /...

2.5AI Score

2011-03-24 12:00 AM
11
cve
cve

CVE-2024-0651

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has.....

7.2CVSS

7.3AI Score

0.001EPSS

2024-01-18 01:15 AM
10
veracode
veracode

Use Of A Key Past Its Expiration Date

moodle/moodle is vulnerable to Use of a Key Past its Expiration Date. The vulnerability is caused due to improper key generation, as the same key is used interchangeably for a user's QR login key and their auto-login key. This allows an attacker to exploit the same key used interchangeably for a...

6.8AI Score

0.0004EPSS

2024-06-19 06:16 AM
1
osv
osv

kubevirt allows a local attacker to execute arbitrary code via a crafted command

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token...

7.6AI Score

0.0004EPSS

2024-05-02 06:30 PM
4
cve
cve

CVE-2024-0652

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has....

4.8CVSS

4.8AI Score

0.001EPSS

2024-01-18 01:15 AM
6
github
github

CrateDB has a Client initialized Session-Renegotiation DoS

Summary Client-Initiated TLS Renegotiation Denial of Service (DoS) Vulnerability at Port 4200 Details A high-risk vulnerability has been identified where the TLS endpoint (port 4200) permits client-initiated renegotiation. In this scenario, an attacker can exploit this feature to repeatedly...

5.3CVSS

6.9AI Score

0.0004EPSS

2024-06-13 07:39 PM
3
cve
cve

CVE-2009-3588

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products...

6.2AI Score

0.204EPSS

2009-10-13 10:30 AM
67
2
githubexploit

8.6AI Score

2022-06-04 02:18 PM
499
osv
osv

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

Summary Tornado’s curl_httpclient.CurlAsyncHTTPClient class is vulnerable to CRLF (carriage return/line feed) injection in the request headers. Details When an HTTP request is sent using CurlAsyncHTTPClient, Tornado does not reject carriage return (\r) or line feed (\n) characters in the request...

7.5AI Score

2024-06-06 09:46 PM
2
github
github

Magento Insufficient authorization check when adding users to company accounts

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to insufficient authorizations checks. This can be abused by a user with admin privileges to add users to company accounts or modify existing...

6.5CVSS

6.6AI Score

0.001EPSS

2022-05-24 04:52 PM
1
atlassian
atlassian

JIRA puts a user's XSRF token in various resources.

{panel:bgColor=#e7f4fa} NOTE: This bug report is for JIRA Server. Using JIRA Cloud? [See the corresponding bug report|http://jira.atlassian.com/browse/JRACLOUD-61250]. {panel} h5. Steps to Reproduce: # Log into JIRA # Log out from JIRA h5. Expected Results: * The URL shown in the address bar...

0.7AI Score

2016-06-01 06:40 AM
9
githubexploit
githubexploit

Exploit for Externally Controlled Reference to a Resource in Another Sphere in Microsoft

CVE-2022-30190-follina Just another PoC for the new...

7.8CVSS

8.4AI Score

0.961EPSS

2022-06-01 11:37 AM
236
cve
cve

CVE-2005-10001

A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the...

6.1CVSS

6.7AI Score

0.001EPSS

2022-03-28 09:15 PM
27
cve
cve

CVE-2009-3587

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products...

7.4AI Score

0.204EPSS

2009-10-13 10:30 AM
65
2
githubexploit

8AI Score

2022-06-04 02:18 PM
58
githubexploit
githubexploit

Exploit for Externally Controlled Reference to a Resource in Another Sphere in Microsoft

'Follina' MS-MSDT n-day Microsoft Office RCE—修改版 根据...

7.8CVSS

8.7AI Score

0.961EPSS

2022-06-02 12:33 PM
387
githubexploit
githubexploit

Exploit for Externally Controlled Reference to a Resource in Another Sphere in Microsoft

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina...

7.8CVSS

8.5AI Score

0.961EPSS

2022-05-30 06:17 PM
78
osv
osv

Grafana XSS via adding a link in General feature

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for...

6.1CVSS

6.1AI Score

0.001EPSS

2024-01-30 11:47 PM
7
githubexploit
githubexploit

Exploit for Externally Controlled Reference to a Resource in Another Sphere in Microsoft

$ gollina -h gollina Follina MS-MSDT 0-day MS Of...

8.2AI Score

2022-06-01 09:02 AM
296
Total number of security vulnerabilities2914246