Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bootstrap vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-26049
This affects the package com.diffplug.gradle:goomph prior to 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an m...
Diffplug Goomph
4.3
CVSSv2
CVE-2019-11358
jQuery prior to 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Jquery Jquery
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Drupal Drupal
Backdropcms Backdrop
Fedoraproject Fedora 28
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Opensuse Leap 15.1
Opensuse Backports Sle 15.0
Netapp Snapcenter -
Netapp Oncommand System Manager
Redhat Cloudforms 4.7
Redhat Virtualization Manager 4.3
Oracle Service Bus 12.1.3.0.0
Oracle Primavera Unifier 16.2
Oracle Jd Edwards Enterpriseone Tools 9.2
Oracle Weblogic Server 12.1.3.0.0
Oracle Service Bus 11.1.1.9.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Primavera Unifier 16.1
98 Github repositories
4.3
CVSSv2
CVE-2009-2055
Cisco IOS XR 3.4.0 up to and including 3.8.1 allows remote malicious users to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
Cisco Ios Xr 3.4
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.1
Cisco Ios Xr 3.7.3
Cisco Ios Xr 3.8.1
Cisco Ios Xr 3.8.0
Cisco Ios Xr 3.4.3
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.6.2
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.5.2
Cisco Ios Xr 3.5.4
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.6.1
Cisco Ios Xr 3.4.2
Cisco Ios Xr 3.5
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.7.1
5
CVSSv2
CVE-2010-3035
Cisco IOS XR 3.4.0 up to and including 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote malicious users to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in Augus...
Cisco Ios Xr 3.4.2
Cisco Ios Xr 3.4.3
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.8.4
Cisco Ios Xr 3.9.0
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.1
Cisco Ios Xr 3.6.1
Cisco Ios Xr 3.6.2
Cisco Ios Xr 3.8.1
Cisco Ios Xr 3.8.2
Cisco Ios Xr 3.8.3
Cisco Ios Xr 3.5.4
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.7.3
Cisco Ios Xr 3.8.0
Cisco Ios Xr 3.5.2
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.7.1
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.9.1
3.3
CVSSv2
CVE-2009-1154
Cisco IOS XR 3.8.1 and previous versions allows remote malicious users to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
Cisco Ios Xr 3.5
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.5.2
Cisco Ios Xr 3.5.4
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.2
Cisco Ios Xr 3.6.2
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.4
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.7.3
Cisco Ios Xr 3.8.0
Cisco Ios Xr
Cisco Ios Xr 3.4.1
Cisco Ios Xr 3.4.3
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.7.1
Cisco Ios Xr 3.6.1
NA
CVE-2023-2454
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
Postgresql Postgresql
Redhat Enterprise Linux 8.0
Redhat Software Collections -
Redhat Enterprise Linux 9.0
Fedoraproject Fedora 38
4.3
CVSSv2
CVE-2020-11022
In jQuery versions greater than or equal to 1.2 and prior to 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuer...
Jquery Jquery
Drupal Drupal
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Oracle Weblogic Server 12.1.3.0.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Retail Back Office 14.1
Oracle Retail Back Office 14.0
Oracle Peoplesoft Enterprise Peopletools 8.56
Oracle Weblogic Server 10.3.6.0.0
Oracle Communications Webrtc Session Controller 7.2
Oracle Weblogic Server 12.2.1.3.0
Oracle Agile Product Lifecycle Management For Process 6.2.0.0
Oracle Peoplesoft Enterprise Peopletools 8.57
Oracle Application Testing Suite 13.3.0.1
Oracle Retail Returns Management 14.0
Oracle Retail Returns Management 14.1
Oracle Jdeveloper 12.2.1.3.0
Oracle Policy Automation Connector For Siebel 10.4.6
Oracle Financial Services Market Risk Measurement And Management 8.0.6
13 Github repositories
7.8
CVSSv2
CVE-2016-6355
Memory leak in Cisco IOS XR 5.1.x up to and including 5.1.3, 5.2.x up to and including 5.2.5, and 5.3.x up to and including 5.3.2 on ASR 9001 devices allows remote malicious users to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug...
Cisco Ios Xr 5.1.3
Cisco Ios Xr 5.2.0
Cisco Ios Xr 5.3.2
Cisco Ios Xr 5.2.3
Cisco Ios Xr 5.2.1
Cisco Ios Xr 5.2.2
Cisco Ios Xr 5.2.5
Cisco Ios Xr 5.1.1
Cisco Ios Xr 5.1.2
Cisco Ios Xr 5.3.1
Cisco Ios Xr 5.2.4
Cisco Ios Xr 5.1.0
Cisco Ios Xr 5.3.0
Cisco Ios Xr 5.1.1.k9sec
3.3
CVSSv2
CVE-2009-2056
Cisco IOS XR 3.8.1 and previous versions allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
Cisco Ios Xr 3.6.1
Cisco Ios Xr 3.6.0
Cisco Ios Xr 3.6
Cisco Ios Xr 3.5
Cisco Ios Xr 3.2.2
Cisco Ios Xr 3.2.1
Cisco Ios Xr 3.2
Cisco Ios Xr 3.1
Cisco Ios Xr 3.7.2
Cisco Ios Xr 3.6.3
Cisco Ios Xr 3.5.3
Cisco Ios Xr 3.4
Cisco Ios Xr 3.2.4
Cisco Ios Xr 3.2.3
Cisco Ios Xr 3.1.0
Cisco Ios Xr 3.0.1
Cisco Ios Xr 3.8.0
Cisco Ios Xr 3.7
Cisco Ios Xr 3.7.0
Cisco Ios Xr 3.7.1
Cisco Ios Xr 3.4.0
Cisco Ios Xr 3.4.1
6.1
CVSSv2
CVE-2019-1846
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent malicious user to trigger a denial...
Cisco Ios Xr 5.3.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »