Vulnerabilities
42 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-24811 | Vulnerability in root-project root (builtins/zlib modules). Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root. NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2025-8211 | A vulnerability was found in Roothub up to 2.6. A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2024-7824 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll mo Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-7106 | A vulnerability classified as problematic was found in Spina CMS 2.18.0. A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2024-7065 | A vulnerability was found in Spina CMS up to 2.18.0. A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown function of the file /admin/pages/. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272346 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2024-41603 +1 in the same advisory: …41602 | Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout. Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout. NVD description · AI analysis pending | 9.6 group max | <1% |
| — | ||
| CVE-2024-33120 | Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-33121 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. NVD description · AI analysis pending | 6.3 | <1% |
| — | ||
| CVE-2024-27301 | Support App is an opensource application specialized in managing Apple devices. Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang `#!/bin/zsh` is being used. When the installer is executed it asks for the users password to be executed as root. However, it'll still be using the $HOME of the user and therefore loading the file `$HOME/.zshenv` when the `postinstall` script is executed. An attacker could add malicious code to `$HOME/.zshenv` and it will be executed when the app is installed. An attacker may leverage this vulnerability to escalate privilege on the system. This issue has been addressed in version 2.5.1 Rev 2. All users are advised to upgrade. There are no known workarounds for this vulnerability. NVD description · AI analysis pending | 7.3 | <1% | PoC |
| — | |
| CVE-2023-45838 | Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package. NVD description · AI analysis pending | 8.1 | <1% | PoC |
| — | |
| CVE-2023-3445 | Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2023-29819 | An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2022-4524 | A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. Affected is the function language_attributes of the file src/Modules/CleanUpModule.php. The manipulation of the argument language leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.1.0 is able to address this issue. The name of the patch is 0c9151e00ab047da253e5cdbfccb204dd423269d. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215904. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-40425 +1 in the same advisory: …40424 | An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. An IOCTL_B03 request with specific invalid data causes a similar issue in the device driver WRCore_x64. An attacker can issue an ioctl to trigger this vulnerability. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2022-28052 | Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution. NVD description · AI analysis pending | 8.0 | 3% | PoC |
| — | |
| CVE-2022-27473 +1 in the same advisory: …27472 | SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter r SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-46168 | Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2021-29455 | Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform before master deployment as of 2021-04-16 did not properly verify the signature of JSON Web Tokens when refreshing an existing JWT. This allows to forge a valid JWT. The problem has been patched in version 1.3.1 by deprecating the JWT refresh function, which was an overdue deprecation regardless (the "refresh" flow is no longer used). NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2020-7669 | This affects all versions of package github.com/u-root/u-root/pkg/tarutil. This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2020-5754 +1 in the same advisory: …5755 | Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent. NVD description · AI analysis pending | 9.1 group max | 2% | PoC |
| — | |
| CVE-2018-4012 | An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability. NVD description · AI analysis pending | 8.1 | 3% | PoC |
| — | |
| CVE-2018-4015 | An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this vulnerability. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2018-16962 | Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges. Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges. NVD description · AI analysis pending | 7.8 | <1% | PoC ×2 |
| — | |
| CVE-2017-1000215 | ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution NVD description · AI analysis pending | 9.8 | 6% |
| — | ||
| CVE-2017-7480 | rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution. rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution. NVD description · AI analysis pending | 9.8 | 2% |
| — |