Nomisec Exploits

22,967 exploits tracked across all sources.

Sort: Activity Stars
CVE-2022-22954 NOMISEC CRITICAL
VMware Workspace ONE Access CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
by aniqfakhrul
4 stars
CVSS 9.8
CVE-2022-0482 NOMISEC CRITICAL
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
by Acceis
3 stars
CVSS 9.1
CVE-2021-21972 NOMISEC CRITICAL
VMware vCenter Server and Cloud Foundation - Remote Code Execution via vSphere Client Plugin
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
by user16-et
CVSS 9.8
CVE-2019-9193 NOMISEC HIGH
PostgreSQL 9.3-11.2 - Authenticated OS Command Injection via COPY TO/FROM PROGRAM
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
by b4keSn4ke
20 stars
CVSS 7.2
CVE-2022-22972 NOMISEC CRITICAL
VMware Identity Manager Workspace ONE Access and vRealize Automation - Authentication Bypass
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
by horizon3ai
153 stars
CVSS 9.8
CVE-2022-30781 NOMISEC HIGH
Gitea < 1.16.7 - Remote Code Execution via Git Fetch Remote
Gitea before 1.16.7 does not escape git fetch remote.
by wuhan005
86 stars
CVSS 7.5
CVE-2022-30513 NOMISEC MEDIUM
School Dormitory Management System 1.0 - Reflected Cross-Site Scripting via admin/inc/navigation.php
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125
by bigzooooz
2 stars
CVSS 6.1
CVE-2021-44228 NOMISEC CRITICAL
Log4Shell HTTP Header Injection
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
by r3kind1e
26 stars
CVSS 10.0
CVE-2021-3156 NOMISEC HIGH
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
by q77190858
1 stars
CVSS 7.8
CVE-2017-8046 NOMISEC CRITICAL
Spring Data REST < 2.6.9 and Spring Boot < 1.5.9 - Remote Code Execution via Malicious PATCH Request
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
by sj
1 stars
CVSS 9.8
CVE-2018-6242 NOMISEC MEDIUM
NVIDIA Tegra BootROM RCM - Buffer Overflow via Physical USB Access
Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.
by Swiftloke
CVSS 6.8
CVE-2022-30514 NOMISEC MEDIUM
School Dormitory Management System 1.0 - Reflected Cross-Site Scripting via admin/inc/navigation.php
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.
by bigzooooz
1 stars
CVSS 6.1
CVE-2022-30511 NOMISEC CRITICAL
School Dormitory Management System 1.0 - SQL Injection via accounts/view_details.php
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
by bigzooooz
1 stars
CVSS 9.8
CVE-2022-30510 NOMISEC CRITICAL
School Dormitory Management System 1.0 - SQL Injection via Daily Collection Report
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
by bigzooooz
1 stars
CVSS 9.8
CVE-2022-30512 NOMISEC CRITICAL
School Dormitory Management System 1.0 - SQL Injection via Payment History Page
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
by bigzooooz
1 stars
CVSS 9.8
CVE-2022-0540 NOMISEC CRITICAL
Atlassian Jira <8.13.18, <8.14.0-8.20.5, <8.21.0-8.22.0 - Auth Bypass
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.
by Pear1y
72 stars
CVSS 9.8
CVE-2022-29337 NOMISEC CRITICAL
C-DATA FD702XW-X-R430 v2.1.13_X001 - Command Injection
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
by exploitwritter
3 stars
CVSS 9.8
CVE-2020-0188 NOMISEC HIGH
Android 10 - Local Privilege Escalation via PendingIntent Error in SettingsSliceProvider
In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147355897
by Trinadh465
CVSS 7.8
CVE-2020-0219 NOMISEC HIGH
Android - Local Privilege Escalation via SliceDeepLinkSpringBoard Intent Handling
In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-122836081
by Trinadh465
CVSS 7.8
CVE-2020-0219 NOMISEC HIGH
Android - Local Privilege Escalation via SliceDeepLinkSpringBoard Intent Handling
In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-122836081
by Trinadh465
CVSS 7.8
CVE-2021-45960 NOMISEC HIGH
libexpat < 2.4.3 - Integer Overflow via Left Shift in storeAtts
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
by Trinadh465
CVSS 8.8
CVE-2022-29221 NOMISEC HIGH
Smarty <3.1.45, <4.1.1 - Code Injection
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully trust template authors should upgrade to versions 3.1.45 or 4.1.1 to receive a patch for this issue. There are currently no known workarounds.
by sbani
16 stars
CVSS 8.8
CVE-2021-0308 NOMISEC MEDIUM
Android 8.0-11 - Out-of-bounds Write in ReadLogicalParts
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158063095.
by Trinadh465
CVSS 6.8
CVE-2022-26809 NOMISEC CRITICAL
Microsoft Windows RPC Runtime - Remote Code Execution
Remote Procedure Call Runtime Remote Code Execution Vulnerability
by yuanLink
61 stars
CVSS 9.8
CVE-2021-46422 NOMISEC CRITICAL
Telesquare SDT-CW3B1 1.1.0 - Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
by nobodyatall648
1 stars
CVSS 9.8