Nomisec Exploits

21,865 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-36884 NOMISEC HIGH
Windows Search - RCE
Windows Search Remote Code Execution Vulnerability
by tarraschk
15 stars
CVSS 7.5
CVE-2023-36884 NOMISEC HIGH
Windows Search - RCE
Windows Search Remote Code Execution Vulnerability
by or2me
CVSS 7.5
CVE-2022-44268 NOMISEC MEDIUM
ImageMagick 7.1.0-49 - Info Disclosure
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
by narekkay
2 stars
CVSS 6.5
CVE-2023-32117 NOMISEC CRITICAL
SoftLab Integrate Google Drive - Info Disclosure
Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.
by RandomRobbieBF
6 stars
CVSS 9.8
CVE-2023-3640 NOMISEC HIGH
Linux Kernel - Information Disclosure
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.
by pray77
29 stars
CVSS 7.0
CVE-2021-21311 NOMISEC HIGH
Adminer < 4.7.9 - SSRF
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
by omoknooni
3 stars
CVSS 7.2
CVE-2020-14882 NOMISEC CRITICAL
Oracle WebLogic Server <14.1.1.0.0 - RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
by Danny-LLi
2 stars
CVSS 9.8
CVE-2021-40449 NOMISEC HIGH
Win32k - Privilege Escalation
Win32k Elevation of Privilege Vulnerability
by toanthang1842002
CVSS 7.8
CVE-2019-7609 NOMISEC CRITICAL
Kibana Timelion Prototype Pollution RCE
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
by d0x-awrqxavc
CVSS 10.0
CVE-2019-7609 NOMISEC CRITICAL
Kibana Timelion Prototype Pollution RCE
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
by OliveiraaX
CVSS 10.0
CVE-2018-16763 NOMISEC CRITICAL
FUEL CMS 1.4.1 - RCE
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
by VitoBonetti
CVSS 9.8
CVE-2023-21746 NOMISEC HIGH
Windows NTLM - Privilege Escalation
Windows NTLM Elevation of Privilege Vulnerability
by Muhammad-Ali007
3 stars
CVSS 7.8
CVE-2023-20110 NOMISEC MEDIUM
Cisco SSM On-Prem - SQL Injection
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to read sensitive data on the underlying database.
by redfr0g
16 stars
CVSS 6.5
CVE-2023-33768 NOMISEC MEDIUM
Belkin Wemo Smart Plug WSP080 <1.2 - DoS
Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file.
by purseclab
1 stars
CVSS 6.5
CVE-2023-36884 NOMISEC HIGH
Windows Search - RCE
Windows Search Remote Code Execution Vulnerability
by zerosorai
2 stars
CVSS 7.5
CVE-2022-1026 NOMISEC HIGH
Kyocera Net Viewer - Insufficiently Protected Credentials
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.
by flamebarke
2 stars
CVSS 8.6
CVE-2017-6074 NOMISEC HIGH
Linux Kernel < 3.2.86 - Double Free
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
by toanthang1842002
CVSS 7.8
CVE-2023-23397 NOMISEC CRITICAL
Microsoft Outlook - Privilege Escalation
Microsoft Outlook Elevation of Privilege Vulnerability
by Muhammad-Ali007
22 stars
CVSS 9.8
CVE-2023-30383 NOMISEC HIGH
Tp-link Archer C2 V1 Firmware - Buffer Overflow
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.
by a2ure123
CVSS 7.5
CVE-2023-28121 NOMISEC CRITICAL
Automattic Woocommerce Payments < 4.8.2 - Authentication Bypass
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
by im-hanzou
11 stars
CVSS 9.8
CVE-2022-44268 NOMISEC MEDIUM
ImageMagick 7.1.0-49 - Info Disclosure
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
by Pog-Frog
CVSS 6.5
CVE-2023-25157 NOMISEC CRITICAL
Osgeo Geoserver < 2.18.7 - SQL Injection
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse.
by win3zz
170 stars
CVSS 9.8
CVE-2023-31851 NOMISEC MEDIUM
Cudy LT400 1.13.4 - XSS
Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.
by CalfCrusher
CVSS 6.1
CVE-2023-31852 NOMISEC MEDIUM
Cudy LT400 1.13.4 - XSS
Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter.
by CalfCrusher
CVSS 6.1
CVE-2023-31853 NOMISEC MEDIUM
Cudy LT400 1.13.4 - XSS
Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.
by CalfCrusher
CVSS 6.1