Lucene search

K

Yokogawa Test & Measurement Corporation Security Vulnerabilities

almalinux
almalinux

Moderate: ruby:3.1 security, bug fix, and enhancement update

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. The following packages have been upgraded to a later upstream version: ruby (3.1). (AlmaLinux-35449) Security Fix(es): ruby: Buffer overread...

9.4AI Score

EPSS

2024-06-06 12:00 AM
1
almalinux
almalinux

Moderate: ruby:3.1 security, bug fix, and enhancement update

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): ruby: RCE vulnerability with .rdoc_options in RDoc (CVE-2024-27281) ruby: Buffer overread vulnerability in StringIO...

7.2AI Score

EPSS

2024-06-03 12:00 AM
2
cvelist
cvelist

CVE-2023-52836 locking/ww_mutex/test: Fix potential workqueue corruption

In the Linux kernel, the following vulnerability has been resolved: locking/ww_mutex/test: Fix potential workqueue corruption In some cases running with the test-ww_mutex code, I was seeing odd behavior where sometimes it seemed flush_workqueue was returning before all the work threads were...

6.4AI Score

0.0004EPSS

2024-05-21 03:31 PM
cvelist
cvelist

CVE-2023-43054 IBM Engineering Test Management cross-site scripting

IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM...

6.4CVSS

5.9AI Score

0.0004EPSS

2024-03-03 12:15 PM
githubexploit
githubexploit

Exploit for Improper Check for Unusual or Exceptional Conditions in Polkit Project Polkit

PolicyKit CVE-2021-3560 Exploit (Authentication Agent)...

7.8CVSS

7.3AI Score

0.012EPSS

2022-04-29 06:57 PM
170
osv
osv

CVE-2024-29862

The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED...

6.9AI Score

0.0004EPSS

2024-03-21 04:15 AM
5
githubexploit
githubexploit

Exploit for CVE-2024-5084

🚀 HashForm Exploit Script This script demonstrates the...

9.8CVSS

8.6AI Score

0.035EPSS

2024-05-27 08:04 PM
149
vulnrichment
vulnrichment

CVE-2023-52836 locking/ww_mutex/test: Fix potential workqueue corruption

In the Linux kernel, the following vulnerability has been resolved: locking/ww_mutex/test: Fix potential workqueue corruption In some cases running with the test-ww_mutex code, I was seeing odd behavior where sometimes it seemed flush_workqueue was returning before all the work threads were...

6.8AI Score

0.0004EPSS

2024-05-21 03:31 PM
githubexploit
githubexploit

Exploit for OS Command Injection in Php

CVE-2024-4577: PHP CGI Argument Injection (XAMPP) 💀...

9.8CVSS

10AI Score

0.967EPSS

2024-06-09 02:18 PM
145
githubexploit
githubexploit

Exploit for CVE-2023-40477

CVE-2023-4047 PoC By Wild Pointer Read Research:...

7.8CVSS

7.4AI Score

0.001EPSS

2023-08-29 04:29 PM
39
githubexploit
githubexploit

Exploit for Logging of Excessive Data in Salesagility Suitecrm

CVE-2024-36416 Tool for validating CVE-2024-36416 Usage...

8.6CVSS

7.2AI Score

0.0005EPSS

2024-06-09 07:18 AM
19
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Polkit Project Polkit

pkexec-exploit Local Privilege Escalation in polkit's pkexec...

8.2AI Score

2022-01-30 10:34 AM
251
githubexploit
githubexploit

Exploit for Link Following in Git

Poc for CVE-2024-32002, the script made from the developer's...

9CVSS

9.2AI Score

0.002EPSS

2024-05-18 02:42 AM
130
githubexploit
githubexploit

Exploit for CVE-2024-4367

PDF.js Vulnerability Demo Project This project is intended to...

7.2AI Score

2024-05-22 11:18 PM
20
githubexploit
githubexploit

Exploit for Race Condition in Apple Ipados

Pentagram-exploit-tester A test app to check if your device...

7.3AI Score

2022-03-18 12:32 PM
270
githubexploit
githubexploit

Exploit for Path Traversal in Aiohttp

[ CVE-2024-23334 :; 남의 exploit 리뷰 ] Review an exploit...

7.5CVSS

7.6AI Score

0.052EPSS

2024-02-28 10:30 PM
212
githubexploit
githubexploit

Exploit for CVE-2024-21683

CVE-2024-21683-RCE Credit https://x.com/realalphaman_ ...

8.8CVSS

7.1AI Score

0.511EPSS

2024-05-23 09:05 AM
339
vulnrichment
vulnrichment

CVE-2024-36118 Unauthorized viewing of workspace test cases in MeterSphere

MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond their authority. This issue has been addressed in version 2.10.15-lts. Users of MeterSphere are advised to upgrade. There.....

3.5CVSS

6.8AI Score

0.0004EPSS

2024-05-30 04:51 PM
1
cvelist
cvelist

CVE-2024-36118 Unauthorized viewing of workspace test cases in MeterSphere

MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond their authority. This issue has been addressed in version 2.10.15-lts. Users of MeterSphere are advised to upgrade. There.....

3.5CVSS

3.9AI Score

0.0004EPSS

2024-05-30 04:51 PM
2
githubexploit
githubexploit

Exploit for Command Injection in Paloaltonetworks Pan-Os

CVE-2024-3400 CVE-2024-3400 Palo Alto File Write Exploit...

10CVSS

9.9AI Score

0.957EPSS

2024-04-17 04:01 PM
169
githubexploit
githubexploit

Exploit for OS Command Injection in Php

CVE-2024-4577: PHP CGI Argument Injection (XAMPP) 💀...

9.8CVSS

10AI Score

0.967EPSS

2024-06-19 01:50 AM
182
rocky
rocky

ruby:3.1 security, bug fix, and enhancement update

An update is available for module.rubygem-abrt, rubygem-mysql2, module.rubygem-pg, ruby, module.rubygem-mysql2, rubygem-abrt, module.ruby, rubygem-pg. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available...

6AI Score

EPSS

2024-06-14 01:59 PM
2
githubexploit
githubexploit

Exploit for CVE-2021-3129

CVE-2021-3129 PoC for CVE-2021-3129 (Laravel) For...

9.8CVSS

9.8AI Score

0.975EPSS

2021-10-01 09:09 AM
137
osv
osv

CVE-2023-47122

Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor server happened to be compromised, gitsign clients could...

5.3CVSS

5.2AI Score

0.001EPSS

2023-11-10 10:15 PM
2
metasploit
metasploit

rexec Authentication Scanner

This module will test an rexec service on a range of machines and report successful logins. NOTE: This module requires access to bind to privileged ports (below...

7.2AI Score

2010-11-23 01:23 AM
43
metasploit
metasploit

rlogin Authentication Scanner

This module will test an rlogin service on a range of machines and report successful logins. NOTE: This module requires access to bind to privileged ports (below...

7.2AI Score

2010-11-23 01:23 AM
54
metasploit
metasploit

rsh Authentication Scanner

This module will test a shell (rsh) service on a range of machines and report successful logins. NOTE: This module requires access to bind to privileged ports (below...

7.2AI Score

2010-11-23 01:23 AM
50
githubexploit
githubexploit

Exploit for CVE-2024-30043

CVE-2024-30043-XXE Credit The impact of the vulnerability...

6.5CVSS

6.9AI Score

0.001EPSS

2024-06-06 06:31 PM
126
atlassian
atlassian

JIRA Workflow Step Property jira.permission.browse allows you to view issues in issue navigator

{panel:bgColor=#e7f4fa} NOTE: This bug report is for JIRA Server. Using JIRA Cloud? [See the corresponding bug report|http://jira.atlassian.com/browse/JRACLOUD-35917]. {panel} h3. Summary The JIRA Workflow Step Property {{jira.permission.browse}} does not prevent you to view issues in issue...

1AI Score

2013-11-22 03:08 AM
9
githubexploit
githubexploit

Exploit for Link Following in Microsoft

CVE-2023-36874 For demonstration purposes only. Exploit...

7.8CVSS

7.9AI Score

0.059EPSS

2023-08-23 12:07 PM
353
osv
osv

vyper performs multiple eval of `sqrt()` argument built in

Summary Using the sqrt builtin can result in multiple eval evaluation of side effects when the argument has side-effects. The bug is more difficult (but not impossible!) to trigger as of 0.3.4, when the unique symbol fence was introduced (https://github.com/vyperlang/vyper/pull/2914). A contract...

5.3CVSS

5.4AI Score

0.0004EPSS

2024-04-25 07:50 PM
6
redhat
redhat

(RHSA-2024:2987) Moderate: python27:2.7 security update

Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages provide a stable release of Python 2.7 with a number of additional utilities and database connectors for.....

7AI Score

0.005EPSS

2024-05-22 06:35 AM
21
metasploit
metasploit

SMB Login Check Scanner

This module will test a SMB login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your...

7.2AI Score

2017-10-09 09:01 PM
61
githubexploit

8.6CVSS

6.2AI Score

0.945EPSS

2024-05-30 02:41 PM
68
vulnrichment
vulnrichment

CVE-2023-52560 mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions()

In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions() When CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFIG_DEBUG_KMEMLEAK=y and CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y, the below memory leak is detected. Since...

6.8AI Score

0.0004EPSS

2024-03-02 09:59 PM
cvelist
cvelist

CVE-2023-52560 mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions()

In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions() When CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFIG_DEBUG_KMEMLEAK=y and CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y, the below memory leak is detected. Since...

6.7AI Score

0.0004EPSS

2024-03-02 09:59 PM
1
atlassian
atlassian

User with system administrator privilege can search restricted pages.

h3. Issue Summary Starting Confluence 8.5.1 when a user is granted System administrator permission at Global permissions. The user can search for Restricted content and the restricted page gets displayed in search, when tried to access it says "Page can't be found". This behaviour is not...

6.7AI Score

2023-09-25 05:35 PM
4
github
github

malicious container creates symlink "mtab" on the host External

Impact A malicious container can affect the host by taking advantage of code cri-o added to show the container mounts on the host. A workload built from this Dockerfile: ``` FROM docker.io/library/busybox as source RUN mkdir /extra && cd /extra && ln -s ../../../../../../../../root etc FROM...

8.1CVSS

6.7AI Score

0.0004EPSS

2024-06-04 06:12 PM
githubexploit
githubexploit

Exploit for Download of Code Without Integrity Check in Fortinet Fortios

Exploit for CVE-2021-44168 Purpose Exploit CVE-2021-44168...

7.8CVSS

7.4AI Score

0.001EPSS

2023-02-08 07:30 AM
268
cvelist
cvelist

CVE-2023-7202 Fatal Error Notify < 1.5.3 - Subscriber+ Test Error Email Sending

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via...

6.5AI Score

0.0004EPSS

2024-02-27 08:30 AM
githubexploit
githubexploit

Exploit for CVE-2024-23692

TG Join Us https://t.me/WanLiChangChengWanLiChang...

9.8CVSS

9.7AI Score

0.002EPSS

2024-06-13 01:13 PM
85
atlassian
atlassian

Attachment name, in questions/answers, is searchable despite not having Permissions for Questions

h4. Summary The questions plugin allows administrators to restrict its usage to groups/users, similar to Confluence Permissions. Attachments uploaded to these questions/answers can be found by users that do not have Questions Permission. However, while the attachment can be searched and its title.....

0.8AI Score

2021-06-30 03:31 PM
8
osv
osv

CVE-2024-4146

In lunary-ai/lunary version v1.2.13, an improper authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to. Specifically, the vulnerability is located in the checkProjectAccess method within the...

9.8CVSS

9.5AI Score

0.0004EPSS

2024-06-08 08:15 PM
2
osv
osv

malicious container creates symlink "mtab" on the host External

Impact A malicious container can affect the host by taking advantage of code cri-o added to show the container mounts on the host. A workload built from this Dockerfile: ``` FROM docker.io/library/busybox as source RUN mkdir /extra && cd /extra && ln -s ../../../../../../../../root etc FROM...

8.1CVSS

6.7AI Score

0.0004EPSS

2024-06-04 06:12 PM
4
metasploit
metasploit

Telnet Login Check Scanner

This module will test a telnet login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your...

7.2AI Score

2013-10-15 06:51 PM
41
rocky
rocky

new module: ruby:3.3

An update is available for module.rubygem-abrt, rubygem-mysql2, module.rubygem-pg, ruby, module.rubygem-mysql2, rubygem-abrt, module.ruby, rubygem-pg. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available...

6.8AI Score

2024-06-14 01:59 PM
1
githubexploit
githubexploit

Exploit for Out-of-bounds Read in Adobe Bridge

Exploit for CVE-2021-44168 Purpose Exploit CVE-2021-44168...

3.3CVSS

6.2AI Score

0.001EPSS

2023-02-08 07:30 AM
305
metasploit
metasploit

SSH Login Check Scanner

This module will test ssh logins on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your...

7.2AI Score

2017-08-08 08:46 PM
115
githubexploit

8.6CVSS

6.1AI Score

0.945EPSS

2024-06-03 12:18 PM
78
githubexploit
githubexploit

Exploit for CVE-2024-31848

Exploiting CData within Jetty servers -...

9.8CVSS

7AI Score

0.001EPSS

2024-05-07 10:42 AM
201
Total number of security vulnerabilities111912