cved-sources
43 exploits
Active since Feb 2010
Domoticz <4.10579 - Info Disclosure
Apache Struts 2 Namespace Redirect OGNL Injection
OpenSSH < 7.7 - User Enumeration via Authentication Request Timing
Adobe ColdFusion July 12 release (2018.0.0.310739) Update 6 and earlier Update 14 and earlier - Unrestricted File Upload
Spring Data REST < 2.6.9 and Spring Boot < 1.5.9 - Remote Code Execution via Malicious PATCH Request
J2Store 3.3.0-3.3.6 - SQL Injection via product_option[] Parameter
CVSS 9.8
elFinder < 2.1.48 - OS Command Injection in PHP Connector
CVSS 9.8
Social Warfare and Social Warfare Pro < 3.5.3 - Stored Cross-Site Scripting via swp_debug Parameter
CVSS 6.1
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
CVSS 9.8
Drupal 7.0.0-7.61.0 8.5.0-8.5.10 8.6.0-8.6.9 - Remote Code Execution via Unsanitized Field Data
CVSS 8.1
Joomla! 3.7.x - SQL Injection
CVSS 9.8
Spring Data Commons < 1.13.11 - Unauthenticated Remote Code Execution via Property Binder
CVSS 9.8
Plainview Activity Monitor < 20180826 - OS Command Injection via IP Parameter
CVSS 8.8
Wechat Broadcast < 1.2.0 - Path Traversal via Image.php URL Parameter
CVSS 9.8
Artifex Ghostscript <9.24 - Privilege Escalation
CVSS 7.8
Snap Creek Duplicator <1.2.42 - Code Injection
CVSS 9.8
Van Ons WP GDPR Compliance <1.4.3 - RCE
CVSS 9.8
Smart Google Code Inserter < 3.5 - Unauthenticated Arbitrary Code Insertion via sgcgoogleanalytic Parameter
CVSS 9.8
Smart Google Code Inserter < 3.5 - Unauthenticated SQL Injection via oId Parameter
CVSS 9.8
Drupal Drupalgeddon 2 Forms API Property Injection
CVSS 9.8
Blueimp jQuery-File-Upload <=9.22.0 - File Upload
CVSS 9.8
jQuery Upload File <= 4.0.2 - Arbitrary File Upload
CVSS 9.8
jQuery Picture Cut <= 1.1Beta - Unauthenticated Arbitrary File Upload
CVSS 9.8
NTP 4.3.0-4.3.94 - Denial of Service via Crafted MRU List Query
CVSS 7.5
OpenSSH < 7.3 - Denial of Service via Long Password String
CVSS 7.5