<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dominicus In</title><link>https://dominicusin.github.io/</link><description>Recent content on Dominicus In</description><generator>Hugo -- gohugo.io</generator><language>ru</language><copyright>© 2026</copyright><lastBuildDate>Fri, 14 Aug 2026 18:00:00 +0000</lastBuildDate><atom:link href="https://dominicusin.github.io/index.xml" rel="self" type="application/rss+xml"/><item><title>Децентрализованное управление: commit-reveal голосование и таймлоки</title><link>https://dominicusin.github.io/2026/08/14/decentralized-governance-commit-reveal/</link><pubDate>Fri, 14 Aug 2026 18:00:00 +0000</pubDate><guid>https://dominicusin.github.io/2026/08/14/decentralized-governance-commit-reveal/</guid><description>&lt;h2 class="relative group"&gt;Зачем отдельный контур управления
 &lt;div id="зачем-отдельный-контур-управления" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%b7%d0%b0%d1%87%d0%b5%d0%bc-%d0%be%d1%82%d0%b4%d0%b5%d0%bb%d1%8c%d0%bd%d1%8b%d0%b9-%d0%ba%d0%be%d0%bd%d1%82%d1%83%d1%80-%d1%83%d0%bf%d1%80%d0%b0%d0%b2%d0%bb%d0%b5%d0%bd%d0%b8%d1%8f" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Основной сайт — статический Hugo. Но инженерный контур этого репозитория
(&lt;code&gt;contracts/dao/&lt;/code&gt;) содержит набор Solidity-контрактов, которые моделируют
минимальное, но самодостаточное DAO. Три примитива:&lt;/p&gt;</description></item><item><title>Graph</title><link>https://dominicusin.github.io/2025/12/29/graph/</link><pubDate>Mon, 29 Dec 2025 20:01:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/12/29/graph/</guid><description>&lt;p&gt;{% include graph.html %}&lt;/p&gt;</description></item><item><title>Awesome Plan9</title><link>https://dominicusin.github.io/2025/12/23/awesome-plan9/</link><pubDate>Tue, 23 Dec 2025 09:37:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/12/23/awesome-plan9/</guid><description>&lt;h1 class="relative group"&gt;Awesome Plan9
 &lt;div id="awesome-plan9" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#awesome-plan9" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;&lt;a href="https://github.com/henesy/awesome-plan9" target="_blank" rel="noreferrer"&gt;https://github.com/henesy/awesome-plan9&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A curated list of awesome Plan9 (and sometimes 9p) libraries and software.&lt;/p&gt;</description></item><item><title>YA movies's list</title><link>https://dominicusin.github.io/2025/11/02/yet-another-list-of-movies/</link><pubDate>Sun, 02 Nov 2025 01:46:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/11/02/yet-another-list-of-movies/</guid><description>&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;a href="https://www.imdb.com/title/tt7422822/" target="_blank" rel="noreferrer"&gt;Зеленее травы (2019) Greener Grass&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;a href="https://www.imdb.com/title/tt0166924/" target="_blank" rel="noreferrer"&gt;Малхолланд Драйв (2001) Mulholland Dr.&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;a href="https://www.imdb.com/title/tt0114369/" target="_blank" rel="noreferrer"&gt;Семь (1995) Se7en&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;a href="https://www.imdb.com/title/tt0117951/" target="_blank" rel="noreferrer"&gt;На игле (1995) Trainspotting&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&lt;a href="https://www.imdb.com/title/tt0408664/" target="_blank" rel="noreferrer"&gt;Никто не узнает (2004) 誰も知らない Дарэ мо сиранай&lt;/a&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Unrestricted AI Tools</title><link>https://dominicusin.github.io/2025/10/29/unrestricted-ai-tools/</link><pubDate>Wed, 29 Oct 2025 23:04:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/10/29/unrestricted-ai-tools/</guid><description>&lt;h1 class="relative group"&gt;Unrestricted AI Tools
 &lt;div id="unrestricted-ai-tools" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#unrestricted-ai-tools" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;Curated list of AI content generators that do not have any NSFW restrictions&lt;/p&gt;</description></item><item><title>Epistula ad Programmatorum</title><link>https://dominicusin.github.io/2025/10/19/epistula-ad-programmatorum/</link><pubDate>Sun, 19 Oct 2025 21:10:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/10/19/epistula-ad-programmatorum/</guid><description>&lt;p&gt;Хочу не быть программистом, а быть разумным и добродетельным в том, что делаю.&lt;br&gt;
Тогда кодирование становится не профессией, а практикой добродетели — внимательности, умеренности, разума&lt;br&gt;
Хочу упражнять разум и порядок духа через искусство программирования,&lt;br&gt;
быть свободным от страха перед ошибкой и желания похвалы,&lt;br&gt;
и делать своё дело согласно природе разума.&lt;br&gt;
Я не властен над тем, чтобы программа была идеальна;&lt;br&gt;
но я властен над тем, чтобы сохранять разум, терпение и ясность мысли&lt;br&gt;
Так ошибка становится не поражением, а тренировкой атарáксии.&lt;br&gt;
Не желай быть программистом — желай быть разумным в программировании.&lt;br&gt;
Ведь стать кем-то — удел случая,&lt;br&gt;
а быть достойным разума — удел человека.&lt;br&gt;
Не ищи звания программиста, но ищи ума, который пишет ясно,&lt;br&gt;
как природа пишет законы.&lt;br&gt;
Пусть код твой будет отражением порядка в душе,&lt;br&gt;
а не стремлением к похвале людей.&lt;br&gt;
Ты хочешь быть программистом?&lt;br&gt;
Тогда учись владеть не клавиатурой, а собой.&lt;br&gt;
Код исполняет волю машины,&lt;br&gt;
но разум должен исполнять волю природы.&lt;br&gt;
Не важна профессия, но то, каким духом она наполнена.&lt;br&gt;
Один пишет код, чтобы разбогатеть; другой — чтобы понять порядок вещей.&lt;br&gt;
Первый служит прихоти,&lt;br&gt;
второй — Логосу.&lt;br&gt;
Пиши не ради лайков — ради логоса.&lt;br&gt;
Ошибка — не враг, а зеркало твоего рассудка.&lt;br&gt;
Отладь душу, и код пойдёт сам.&lt;/p&gt;</description></item><item><title>λογική</title><link>https://dominicusin.github.io/2025/10/14/logiki/</link><pubDate>Tue, 14 Oct 2025 04:35:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/10/14/logiki/</guid><description>&lt;hr&gt;

&lt;h3 class="relative group"&gt;&lt;strong&gt;Утверждение&lt;/strong&gt;
 &lt;div id="утверждение" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d1%83%d1%82%d0%b2%d0%b5%d1%80%d0%b6%d0%b4%d0%b5%d0%bd%d0%b8%d0%b5" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;Существует множество форм логики, выходящих за рамки классической дедукции, и каждая из них соответствует определённому типу познания, аргументации или практики.&lt;/p&gt;</description></item><item><title>channels.scm</title><link>https://dominicusin.github.io/2025/09/03/gist-channelsscm/</link><pubDate>Wed, 03 Sep 2025 08:08:12 +0000</pubDate><guid>https://dominicusin.github.io/2025/09/03/gist-channelsscm/</guid><description>&lt;p&gt;channels.scm&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/a94364c9e2c9e742d0c94dc58a706361" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-scm" data-lang="scm"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;;; ~/.config/guix/channels.scm&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;(list (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;nonguix&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://gitlab.com/nonguix/nonguix&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;477f283914ca771a8622e16b73d845b87c63335d&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;897c1a470da759236cc11798f4e0a5f7d4d59fbc&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;2A39 3FFF 68F4 EF7A 3D29 12AF 6F51 20A0 22FB B2D5&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://git.guix.gnu.org/guix.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;b377ec079d9ffe8f0f372c43735ad012ea889b6f&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;9edb3f66fd807b096b48283debdcddccfea34bad&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;BBB0 2DDF 2CEA F6A8 0D1D E643 A2A0 6DF2 A33A 54FA&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;pantherx&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://channels.pantherx.org/git/panther.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;236f6a56cb78556eeeb64b4895ce59cdba644b0b&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;54b4056ac571611892c743b65f4c47dc298c49da&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;A36A D41E ECC7 A871 1003 5D24 524F EB1A 9D33 C9CB&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix-gaming-games&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://gitlab.com/guix-gaming-channels/games.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;b943b1e3cacffa8c9b7ea63d49f3f7d8fc3bee85&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;c23d64f1b8cc086659f8781b27ab6c7314c5cca5&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;50F3 3E2E 5B0C 3D90 0424 ABE8 9BDC F497 A4BB CC7F&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;flat&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://github.com/flatwhatson/guix-channel.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;b62ba3214ed0f781e2d6015044ae8a4a1bd5c7d7&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;33f86a4b48205c0dc19d7c036c85393f0766f806&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;736A C00E 1254 378B A982 7AF6 9DBE 8265 81B6 4490&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix-science&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://codeberg.org/guix-science/guix-science.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;6f6b833e7b258251abc33186d2775c333e91d11f&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;b1fe5aaff3ab48e798a4cce02f0212bc91f423dc&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;CA4F 8CF4 37D7 478F DA05 5FD4 4213 7701 1A37 8446&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix-hpc&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://gitlab.inria.fr/guix-hpc/guix-hpc.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;383fd2297febd03401d2b70c29db6eaff8c6384d&amp;#34;&lt;/span&gt;))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix-past&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://codeberg.org/guix-science/guix-past&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;b14d7f997ae8eec788a7c16a7252460cba3aaef8&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;0c119db2ea86a389769f4d2b9c6f5c41c027e336&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;rde&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://git.sr.ht/~abcdw/rde&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;46a2e694a4afc3d1dbce8b751389b566df16d46a&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;257cebd587b66e4d865b3537a9a88cccd7107c95&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;2841 9AC6 5038 7440 C7E9 2FFA 2208 D209 58C1 DEB0&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;rosenthal&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://codeberg.org/hako/rosenthal.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;trunk&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;9e51ad4215461702056e57557b89d56d9123713f&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;7677db76330121a901604dfbad19077893865f35&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;13E7 6CD6 E649 C28C 3385 4DF5 5E5A A665 6149 17F7&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;babelfish&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://codeberg.org/ifitzpat/babelfish.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;2a92e7289d260e21b64b3857dbab980adfc78b42&amp;#34;&lt;/span&gt;))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix-cran&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://github.com/guix-science/guix-cran.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;6ef1a68cb0b4e9949ec667c0fb4cd1c730e2015e&amp;#34;&lt;/span&gt;))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;guix-bioc&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://github.com/guix-science/guix-bioc.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;master&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;7500d208fc1f08abd0a382eba2984e622d814f13&amp;#34;&lt;/span&gt;))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;ajattix&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://git.ajattix.org/hashirama/ajattix.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;main&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;b62401404713cbdfcccb6172e8efab59934c62e5&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;make-channel-introduction&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;5f1904f1a514b89b2d614300d8048577aa717617&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;openpgp-fingerprint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;F164 709E 5FC7 B32B AEC7 9F37 1F2E 76AC E3F5 31C8&amp;#34;&lt;/span&gt;))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;name&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#39;crafted-guix&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;url&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;https://codeberg.org/ifitzpat/crafted-guix.git&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;branch&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;docker-container-service-type-documentation&amp;#34;&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (&lt;span style="color:#a6e22e"&gt;commit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;1eba6117713e06a27b40fc77606b9496fd7fe19b&amp;#34;&lt;/span&gt;)))&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>guix0</title><link>https://dominicusin.github.io/2025/09/01/gist-guix0/</link><pubDate>Mon, 01 Sep 2025 05:56:11 +0000</pubDate><guid>https://dominicusin.github.io/2025/09/01/gist-guix0/</guid><description>&lt;p&gt;guix0&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/ee9fed0beea74d3e265dc93a53772a53" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-txt" data-lang="txt"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;(use-modules (gnu))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;(use-service-modules cups desktop networking ssh xorg)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;(operating-system
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (locale &amp;#34;ru_RU.utf8&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (timezone &amp;#34;Europe/Chisinau&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (keyboard-layout (keyboard-layout &amp;#34;ru,us&amp;#34; #:options &amp;#39;(&amp;#34;grp:alt_shift_toggle&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (host-name &amp;#34;quasar&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (users (cons* (user-account
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (name &amp;#34;domini&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (comment &amp;#34;Domini Montessori&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (group &amp;#34;users&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (home-directory &amp;#34;/home/domini&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (supplementary-groups &amp;#39;(&amp;#34;wheel&amp;#34; &amp;#34;netdev&amp;#34; &amp;#34;audio&amp;#34; &amp;#34;video&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; %base-user-accounts))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (packages (append (list (specification-&amp;gt;package &amp;#34;openbox&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;awesome&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;i3-wm&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;i3status&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;dmenu&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;st&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;ratpoison&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;xterm&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;emacs&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;emacs-exwm&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;emacs-desktop-environment&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (specification-&amp;gt;package &amp;#34;nss-certs&amp;#34;))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; %base-packages))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (services
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (append (list (service gnome-desktop-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (service xfce-desktop-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (service mate-desktop-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (service enlightenment-desktop-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; ;; To configure OpenSSH, pass an &amp;#39;openssh-configuration&amp;#39;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; ;; record as a second argument to &amp;#39;service&amp;#39; below.
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (service openssh-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (service tor-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (service cups-service-type)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (set-xorg-configuration
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (xorg-configuration (keyboard-layout keyboard-layout))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; %desktop-services))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (bootloader (bootloader-configuration
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (bootloader grub-efi-bootloader)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (targets (list &amp;#34;/boot/efi&amp;#34;))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (keyboard-layout keyboard-layout)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (swap-devices (list (swap-space
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (target (uuid
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;3f6e87f7-a8c8-460f-a3db-14ed192c5503&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (swap-space
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (target (uuid
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;ce30c55d-6ae4-402b-aed1-ca2c8ff63fcd&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (swap-space
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (target (uuid
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;0aa2d1fb-09fd-4e82-aceb-4e917e6e2b99&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (swap-space
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (target (uuid
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;91533f62-b7e3-46a4-ba5e-0d49a6ea4c43&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (swap-space
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (target (uuid
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;a365da0a-fd73-4121-8f68-d7ef4dc435b4&amp;#34;)))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (swap-space
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (target (uuid
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &amp;#34;d6f28840-c273-43da-ad7e-f20e65dd7450&amp;#34;)))))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (file-systems (cons* (file-system
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (mount-point &amp;#34;/&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (device &amp;#34;/dev/nvme0n1p6:/dev/nvme1n1p6:/dev/nvme2n1p6:/dev/nvme3n1p6:/dev/nvme4n1p6:/dev/nvme5n1p6:/dev/sda6:/dev/sdb6:/dev/sdc6:/dev/sdd6&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (type &amp;#34;bcachefs&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (options &amp;#34;X-mount.subdir=Guix&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (mount-may-fail? #t) ; TODO temporary hack, otherwise the Guix boot process can be blocked in case of errors on some device
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; )
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (file-system
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (mount-point &amp;#34;/boot/efi&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (device &amp;#34;/dev/nvme1n1p2&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (type &amp;#34;vfat&amp;#34;)) %base-file-systems)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; (file-system
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;		 (mount-point &amp;#34;/tmp&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;		 (device &amp;#34;none&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;		 (type &amp;#34;tmpfs&amp;#34;)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;		 (check? #f))
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; )
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>AI2</title><link>https://dominicusin.github.io/2025/08/29/ai2/</link><pubDate>Fri, 29 Aug 2025 20:55:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/08/29/ai2/</guid><description>&lt;h2 class="relative group"&gt;🦜 LLMs
 &lt;div id="-llms" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#-llms" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;|&lt;img src="https://dominicusin.github.io/assets/openai.png" width="30"&gt;|&lt;a href="https://chatgpt.com" target="_blank" rel="noreferrer"&gt;OpenAI&lt;/a&gt; | GPT-5 is an iPhone in LLM space |&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;|&lt;img src="https://dominicusin.github.io/assets/antropic.png" width="30"&gt;| &lt;a href="https://claude.ai" target="_blank" rel="noreferrer"&gt;Anthropic&lt;/a&gt; | Claude Sonnet 4 and Claude Opus 4.1 |&lt;/p&gt;</description></item><item><title>dns</title><link>https://dominicusin.github.io/2025/08/13/gist-dns/</link><pubDate>Wed, 13 Aug 2025 14:32:08 +0000</pubDate><guid>https://dominicusin.github.io/2025/08/13/gist-dns/</guid><description>&lt;p&gt;dns&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/df6ba9a693aef08b7cca12f751f784c7" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-txt" data-lang="txt"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.comss.one
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.jupitrdns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.surfsharkdns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://family.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://ibksturm.synology.me
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://router.comss.one
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://unfiltered.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://zero.dns0.eu
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://101.101.101.101
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://adblock.dns.mullvad.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://adult-filter-dns.cleanbrowsing.org
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://all.dns.mullvad.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://anycast.censurfridns.dk
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://anycast.dns.nextdns.io
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://base.dns.mullvad.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://child.joindns4.eu
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://child-noads.joindns4.eu
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://common.dot.dns.yandex.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns10.quad9.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns11.quad9.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.alidns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.cmrg.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.digitale-gesellschaft.ch
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns-dot.dnsforfamily.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dnsforge.de
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.google
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dnsguard.pub
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.jupitrdns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.marbledfennec.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.nextdns.io
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.opendns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.quad9.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.surfsharkdns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dns.switch.ch
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot1.applied-privacy.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.360.cn
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.ffmuc.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.la.ahadns.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.libredns.gr
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.onedns.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.pub
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot-pure.onedns.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.sb
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://dot.tiar.app
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://extended.dns.mullvad.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://family.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://family.canadianshield.cira.ca
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://family.cloudflare-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://family.dns.mullvad.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://family.dot.dns.yandex.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://family-filter-dns.cleanbrowsing.org
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://familyshield.opendns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://getdnsapi.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://ibksturm.synology.me
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://jp.tiar.app
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://noads.joindns4.eu
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://odvr.nic.cz
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://one.one.one.one
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://ordns.he.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://p1.freedns.controld.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://p2.freedns.controld.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://p3.freedns.controld.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://private.canadianshield.cira.ca
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://protected.canadianshield.cira.ca
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://protective.joindns4.eu
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://public.dns.iij.jp
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://router.comss.one
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://safe.dot.dns.yandex.net
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://sandbox.opendns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://security.cloudflare-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://security-filter-dns.cleanbrowsing.org
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://unfiltered.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://unicast.censurfridns.dk
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tls://wikimedia-dns.org
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.alidns.com:853
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.comss.one
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.jupitrdns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://dns.surfsharkdns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://doh.tiar.app:784
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://family.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://ibksturm.synology.me
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://router.comss.one
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://unfiltered.adguard-dns.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;quic://zero.dns0.eu
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://adblock.dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://all.dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://anycast.dns.nextdns.io/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://base.dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://basic.rethinkdns.com/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://child.joindns4.eu/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://child-noads.joindns4.eu/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://common.dot.dns.yandex.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns10.quad9.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns11.quad9.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.adguard-dns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.alidns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.caliph.dev/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.cloudflare.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.comss.one/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.digitale-gesellschaft.ch/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dnsforge.de/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.google/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.jupitrdns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.marbledfennec.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.nextdns.io/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.pub/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.quad9.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.rabbitdns.org/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.surfsharkdns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://dns.switch.ch/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.360.cn/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.cleanbrowsing.org/doh/adult-filter/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.cleanbrowsing.org/doh/family-filter/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.cleanbrowsing.org/doh/security-filter/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.dns.sb/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.familyshield.opendns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.ffmuc.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.libredns.gr/ads
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.libredns.gr/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.onedns.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.opendns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh-pure.onedns.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.sandbox.opendns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.tiarap.org/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://doh.tiar.app/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://private.canadianshield.cira.ca/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://protected.canadianshield.cira.ca/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://protective.joindns4.eu/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://public.dns.iij.jp/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://public.ns.nwps.fi/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://resolver.dnsprivacy.org.uk/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://router.comss.one/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://rx.techomespace.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://safe.dot.dns.yandex.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://security.cloudflare-dns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://security.rabbitdns.org/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://sm2.doh.pub/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://unfiltered.adguard-dns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://v.recipes/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://wikimedia-dns.org/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://extended.dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://extended.dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://family.adguard-dns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://family.canadianshield.cira.ca/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://family.cloudflare-dns.com/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://family.dns.mullvad.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://family.dot.dns.yandex.net/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://family.rabbitdns.org/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://ibksturm.synology.me/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://jp.tiarap.org/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://jp.tiar.app/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://kids.ns.nwps.fi/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://noads.joindns4.eu/dns-query
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;https://odvr.nic.cz/doh&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>arch</title><link>https://dominicusin.github.io/2025/07/03/gist-arch/</link><pubDate>Thu, 03 Jul 2025 06:54:46 +0000</pubDate><guid>https://dominicusin.github.io/2025/07/03/gist-arch/</guid><description>&lt;p&gt;arch&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/75dc10649ef1619223938456e2f80458" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-txt" data-lang="txt"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;curl https://mirror.cachyos.org/cachyos-repo.tar.xz -o cachyos-repo.tar.xz
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;tar xvf cachyos-repo.tar.xz &amp;amp;&amp;amp; cd cachyos-repo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ./cachyos-repo.sh
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;curl -O https://blackarch.org/strap.sh
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;chmod +x strap.sh
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ./strap.sh
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;curl -LO git.io/strap.sh
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo sh strap.sh&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>flatpaks</title><link>https://dominicusin.github.io/2025/05/04/gist-flatpaks/</link><pubDate>Sun, 04 May 2025 04:56:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/05/04/gist-flatpaks/</guid><description>&lt;p&gt;flatpaks&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/93445e617b848ab12e5b0a7026f25752" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-txt" data-lang="txt"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --from eos-sdk #http://endlessm.github.io/eos-knowledge-lib/eos-sdk.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --from eos-sdk http://endlessm.github.io/eos-knowledge-lib/eos-sdk.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --from eos-sdk-nightly http://endlessm.github.io/eos-knowledge-lib/eos-sdk-nightly.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --gpg-import=eos-flatpak-keyring.gpg eos-apps https://ostree.endlessm.com/ostree/eos-apps
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --gpg-import=eos-flatpak-keyring.gpg eos-sdk https://ostree.endlessm.com/ostree/eos-sdk
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists dragon-nightly https://cdn.kde.org/flatpak/dragon-nightly/dragon-nightly.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists eclipse-nightly https://download.eclipse.org/linuxtools/flatpak-I-builds/eclipse.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists elementaryos https://flatpak.elementary.io/repo.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists fedora oci+https://registry.fedoraproject.org
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists fedora-testing oci+https://registry.fedoraproject.org#testing
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists flathub-beta https://flathub.org/beta-repo/flathub-beta.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists gnome-nightly https://nightly.gnome.org/gnome-nightly.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists gnome-nightly https://nightly.gnome.org/gnome-nightly.flatpakrepo.
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists igalia https://software.igalia.com/flatpak-refs/igalia.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists kdeapps https://distribute.kde.org/kdeapps.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists kde-runtime-nightly https://cdn.kde.org/flatpak/kde-runtime-nightly/kde-runtime-nightly.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists PureOS https://store.puri.sm/repo/stable/pureos.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists --subset=floss flathub-floss https://dl.flathub.org/repo/flathub.flatpakrepo..
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists --subset=verified flathub-verified https://dl.flathub.org/repo/flathub.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists --subset=verified_floss flathub-verified_floss https://dl.flathub.org/repo/flathub.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists tenacity oci+https://tenacityteam.github.io/tenacity-flatpak-nightly
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists --user appcenter https://flatpak.elementary.io/repo.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --if-not-exists webkit-sdk https://software.igalia.com/flatpak-refs/webkit-sdk.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add rhel https://flatpaks.redhat.io/rhel.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --system elementary https://flatpak.elementary.io/elementary.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --user appcenter https://flatpak.elementary.io/appcenter.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add --user --if-not-exists webkit https://software.igalia.com/flatpak-refs/webkit-sdk.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak remote-add xwaylandvideobridge-nightly https://cdn.kde.org/flatpak/xwaylandvideobridge-nightly/xwaylandvideobridge-nightly.flatpakrepo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; flatpak --system remote-add --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepo&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>ed's</title><link>https://dominicusin.github.io/2025/03/27/gist-eds/</link><pubDate>Thu, 27 Mar 2025 06:15:22 +0000</pubDate><guid>https://dominicusin.github.io/2025/03/27/gist-eds/</guid><description>&lt;p&gt;ed&amp;rsquo;s&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/9b501e765b90f223a969b1617e067222" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Adobe XD
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Android Studio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;AppCode
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Aptana
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Aqua
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Arduino IDE
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Azure Data Studio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Blender
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;BlueJ
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Brackets
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Brave
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;C++ Builder
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;CLion
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Canva
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Chrome
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Cloud9
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Coda
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Code::Blocks
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;CodeLite
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;CodeTasty
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Cursor
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;DBeaver
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;DataGrip
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;DataSpell
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Delphi
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Discord
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Eclipse
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Edge
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;EmEditor
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Emacs
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Eric
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Espresso
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Excel
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Figma
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Firefox
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Flash Builder
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Geany
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Gedit
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GoLand
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;HBuilder X
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Helix
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;IDA Pro
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;IntelliJ IDEA
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Jupyter
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;KDevelop
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Kakoune
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Kate
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Komodo
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Light Table
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;MPS
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Micro
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;MySQL Workbench
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Neovim
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;NetBeans
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Notepad++
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Nova
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Obsidian
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Onivim
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Oxygen
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Photoshop
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;PhpStorm
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Postman
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;PowerPoint
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Processing
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Pulsar
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;PyCharm
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Pymakr
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;QtCreator
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;RStudio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ReClassEx
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Rider
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Roblox Studio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;RubyMine
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;RustRover
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;SQL Server Management Studio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;SQL Server Studio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Safari
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;SiYuan
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Sketch
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;SlickEdit
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Spyder
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Sublime Text
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;TeXstudio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Terminal
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;TextMate
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Unity
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;VS Code
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Vim
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Visual Studio
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;WPS Office
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;WebStorm
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Windsurf
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Wing
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Word
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Xcode
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Zed
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Zotero&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>AI</title><link>https://dominicusin.github.io/2025/03/14/ai/</link><pubDate>Fri, 14 Mar 2025 13:43:00 +0000</pubDate><guid>https://dominicusin.github.io/2025/03/14/ai/</guid><description>&lt;p&gt;&lt;a href="https://dominicusin.github.io/2025/03/14/ai/#conversational-ai" &gt;conversational AI&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#all-in-one-tools" &gt;All-in-one tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#ai-search-engine" &gt;AI Search Engine&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#writing-tools" &gt;writing tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#video-tools" &gt;video tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#audio-tools" &gt;audio tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#images-tools" &gt;images tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#commerce--marketing-tools" &gt;commerce &amp;amp; marketing tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#design-tools" &gt;design tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#coding-tools" &gt;Coding tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#color-tools" &gt;color tools&lt;/a&gt; - &lt;a href="https://dominicusin.github.io/2025/03/14/ai/#miscellaneous" &gt;miscellaneous&lt;/a&gt;&lt;/p&gt;</description></item><item><title>gistfile1 txt</title><link>https://dominicusin.github.io/2025/03/11/gist-gistfile1txt/</link><pubDate>Tue, 11 Mar 2025 06:38:07 +0000</pubDate><guid>https://dominicusin.github.io/2025/03/11/gist-gistfile1txt/</guid><description>&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/09e979be90a5a188026c91453113f5fa" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-txt" data-lang="txt"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;export LANG=C.UTF-8
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;export DEBIAN_FRONTEND=noninteractive
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;export APT_LISTCHANGES_FRONTEND=none
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt -y modernize-sources;apt-mark -y minimize-manual ;apt --allow-change-held-packages --allow-downgrades --allow-remove-essential --allow-unauthenticated --fix-broken --fix-missing --ignore-hold --install-recommends --install-suggests --update --show-progress --color --audit --autoremove --purge --reinstall --fix-broken --fix-missing --ignore-hold -t unstable --option DPkg::Options::=&amp;#34;--force-confnew&amp;#34; --option DPkg::Options::=&amp;#34;--force-all&amp;#34; -fym full-upgrade;aptitude --no-gui --with-recommends -t unstable -vfy full-upgrade;dpkg --configure -a --force-all&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>zpool create</title><link>https://dominicusin.github.io/2025/02/07/gist-zpool-create/</link><pubDate>Fri, 07 Feb 2025 16:29:56 +0000</pubDate><guid>https://dominicusin.github.io/2025/02/07/gist-zpool-create/</guid><description>&lt;p&gt;zpool create&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/64a2951303a20059006c99895f8a35d8" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#!/bin/bash
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;set -e
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Define disk arrays&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;HDD_DISKS&lt;span style="color:#f92672"&gt;=(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/ata-WDC_WD4003FRYZ-01F0DB0_VBGGLSNF&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/ata-WDC_WD4003FRYZ-01F0DB0_VBGGL0RF&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/ata-TOSHIBA_HDWR11A_X1K0A036FB4G&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/ata-TOSHIBA_HDWR11A_X1K0A031FB4G&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;NVME_DISKS&lt;span style="color:#f92672"&gt;=(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/nvme-Samsung_SSD_970_EVO_1TB_S467NX0K822865W&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/nvme-CT2000P3PSSD8_2305E6A607AC&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/nvme-WD_Blue_SN580_2TB_23306X800120&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S6Z2NF0X200223V&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221858P&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;/dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221870V&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Partition type GUIDs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_BIOS_BOOT&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;ef02&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_XBOOTLDR&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;bc13c2ff-59e6-4262-a352-b275fd6f7172&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_APPLE_BOOT&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;426F6F74-0000-11AA-AA11-00306543ECAC&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_MS_RESERVED&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;e3c9e316-0b5c-4db8-817d-f92df00215ae&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_WINDOWS_RECOVERY&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;27d7f88a-c0e4-4640-9bd3-4cfc0e305e6c&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_SWAP&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;8200&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;GUID_ZFS&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;bf00&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Install necessary packages&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#pacman -Sy --noconfirm sgdisk zfs-utils mdadm&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Function to determine swap size based on disk size&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;get_swap_size&lt;span style="color:#f92672"&gt;()&lt;/span&gt; &lt;span style="color:#f92672"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local disk_size_gib&lt;span style="color:#f92672"&gt;=&lt;/span&gt;$1
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#66d9ef"&gt;if&lt;/span&gt; &lt;span style="color:#f92672"&gt;((&lt;/span&gt; &lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$disk_size_gib&lt;span style="color:#e6db74"&gt; &amp;lt;= 1.5&amp;#34;&lt;/span&gt; | bc -l&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt; &lt;span style="color:#f92672"&gt;))&lt;/span&gt;; &lt;span style="color:#66d9ef"&gt;then&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &lt;span style="color:#e6db74"&gt;&amp;#34;32G&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#66d9ef"&gt;elif&lt;/span&gt; &lt;span style="color:#f92672"&gt;((&lt;/span&gt; &lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$disk_size_gib&lt;span style="color:#e6db74"&gt; &amp;lt;= 4&amp;#34;&lt;/span&gt; | bc -l&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt; &lt;span style="color:#f92672"&gt;))&lt;/span&gt;; &lt;span style="color:#66d9ef"&gt;then&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &lt;span style="color:#e6db74"&gt;&amp;#34;64G&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#66d9ef"&gt;elif&lt;/span&gt; &lt;span style="color:#f92672"&gt;((&lt;/span&gt; &lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$disk_size_gib&lt;span style="color:#e6db74"&gt; &amp;lt;= 10&amp;#34;&lt;/span&gt; | bc -l&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt; &lt;span style="color:#f92672"&gt;))&lt;/span&gt;; &lt;span style="color:#66d9ef"&gt;then&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &lt;span style="color:#e6db74"&gt;&amp;#34;128G&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#66d9ef"&gt;else&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &lt;span style="color:#e6db74"&gt;&amp;#34;512G&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#66d9ef"&gt;fi&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Function to partition HDDs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;partition_hdd&lt;span style="color:#f92672"&gt;()&lt;/span&gt; &lt;span style="color:#f92672"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local DISK&lt;span style="color:#f92672"&gt;=&lt;/span&gt;$1
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local SWAP_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;$2
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; partprobe &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; zpool labelclear -f &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; wipefs -af &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --zap-all &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk -og &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# sgdisk --new=1:0:+2M --typecode=1:$GUID_BIOS_BOOT --change-name=1:&amp;#34;BIOS Boot&amp;#34; &amp;#34;$DISK&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk -n 1:2048:4095 -c 1:&lt;span style="color:#e6db74"&gt;&amp;#34;BIOS Boot Partition&amp;#34;&lt;/span&gt; -t 1:ef02 &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;2:0:+4G --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;2:$GUID_XBOOTLDR --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;2:&lt;span style="color:#e6db74"&gt;&amp;#34;XBOOTLDR&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;3:0:+200M --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;3:$GUID_APPLE_BOOT --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;3:&lt;span style="color:#e6db74"&gt;&amp;#34;Apple Boot&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;4:0:+128M --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;4:$GUID_MS_RESERVED --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;4:&lt;span style="color:#e6db74"&gt;&amp;#34;MS Reserved&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;5:0:+450M --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;5:$GUID_WINDOWS_RECOVERY --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;5:&lt;span style="color:#e6db74"&gt;&amp;#34;Windows Recovery&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;6:0:+$SWAP_SIZE --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;6:$GUID_SWAP --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;6:&lt;span style="color:#e6db74"&gt;&amp;#34;Linux Swap&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; ENDSECTOR&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;sgdisk -E &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;7:0:&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$ENDSECTOR&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;7:$GUID_ZFS --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;7:&lt;span style="color:#e6db74"&gt;&amp;#34;ZFS Data&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# sgdisk --new=7:0:0 --typecode=7:$GUID_ZFS --change-name=7:&amp;#34;ZFS Data&amp;#34; &amp;#34;$DISK&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk -p &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; partprobe &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Function to partition NVMe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;partition_nvme&lt;span style="color:#f92672"&gt;()&lt;/span&gt; &lt;span style="color:#f92672"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local DISK&lt;span style="color:#f92672"&gt;=&lt;/span&gt;$1
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#75715e"&gt;# Get disk size in GiB&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local DISK_SIZE_BYTES&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;lsblk -b -dn -o SIZE &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local DISK_SIZE_GIB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;scale=2; &lt;/span&gt;$DISK_SIZE_BYTES&lt;span style="color:#e6db74"&gt; / (1024^3)&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#75715e"&gt;# Calculate sizes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local SLOG_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;scale=2; &lt;/span&gt;$DISK_SIZE_GIB&lt;span style="color:#e6db74"&gt; * 0.02&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt; &lt;span style="color:#75715e"&gt;# 2%&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local L2ARC_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;scale=2; &lt;/span&gt;$DISK_SIZE_GIB&lt;span style="color:#e6db74"&gt; * 0.30&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt; &lt;span style="color:#75715e"&gt;# 30%&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local SPECIAL_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;scale=2; &lt;/span&gt;$DISK_SIZE_GIB&lt;span style="color:#e6db74"&gt; * 0.10&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt; &lt;span style="color:#75715e"&gt;# 10%&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#75715e"&gt;# Convert to GiB with rounding&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; SLOG_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;printf &lt;span style="color:#e6db74"&gt;&amp;#34;%.0f&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$SLOG_SIZE&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; L2ARC_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;printf &lt;span style="color:#e6db74"&gt;&amp;#34;%.0f&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$L2ARC_SIZE&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; SPECIAL_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;printf &lt;span style="color:#e6db74"&gt;&amp;#34;%.0f&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$SPECIAL_SIZE&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#75715e"&gt;# Remaining space after fixed partitions and ZFS components&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#ae81ff"&gt;0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$((&lt;/span&gt;FIXED_SIZE_MB &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;2&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;))&lt;/span&gt; &lt;span style="color:#75715e"&gt;# BIOS Boot&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$((&lt;/span&gt;FIXED_SIZE_MB &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;4096&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;))&lt;/span&gt; &lt;span style="color:#75715e"&gt;# XBOOTLDR&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$((&lt;/span&gt;FIXED_SIZE_MB &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;200&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;))&lt;/span&gt; &lt;span style="color:#75715e"&gt;# Apple Boot&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$((&lt;/span&gt;FIXED_SIZE_MB &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;128&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;))&lt;/span&gt; &lt;span style="color:#75715e"&gt;# MS Reserved&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$((&lt;/span&gt;FIXED_SIZE_MB &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;450&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;))&lt;/span&gt; &lt;span style="color:#75715e"&gt;# Windows Recovery&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local SWAP_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$SWAP_SIZE&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; | sed &lt;span style="color:#e6db74"&gt;&amp;#39;s/G/*1024/&amp;#39;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; FIXED_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$FIXED_SIZE_MB&lt;span style="color:#e6db74"&gt; + &lt;/span&gt;$SWAP_SIZE_MB&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local TOTAL_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK_SIZE_GIB&lt;span style="color:#e6db74"&gt; * 1024&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local REMAINING_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$TOTAL_SIZE_MB&lt;span style="color:#e6db74"&gt; - &lt;/span&gt;$FIXED_SIZE_MB&lt;span style="color:#e6db74"&gt; - (&lt;/span&gt;$SLOG_SIZE&lt;span style="color:#e6db74"&gt; * 1024) - (&lt;/span&gt;$L2ARC_SIZE&lt;span style="color:#e6db74"&gt; * 1024) - (&lt;/span&gt;$SPECIAL_SIZE&lt;span style="color:#e6db74"&gt; * 1024)&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#75715e"&gt;# Assign remaining to ZFS Data&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; local ZFS_DATA_SIZE_MB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$REMAINING_MB&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#75715e"&gt;# Create partitions&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; partprobe &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; zpool labelclear -f &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; wipefs -af &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --zap-all &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk -o &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# sgdisk --new=1:0:+2M --typecode=1:$GUID_BIOS_BOOT --change-name=1:&amp;#34;BIOS Boot&amp;#34; &amp;#34;$DISK&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk -n 1:2048:4095 -c 1:&lt;span style="color:#e6db74"&gt;&amp;#34;BIOS Boot Partition&amp;#34;&lt;/span&gt; -t 1:ef02 &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;2:0:+4G --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;2:$GUID_XBOOTLDR --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;2:&lt;span style="color:#e6db74"&gt;&amp;#34;XBOOTLDR&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;3:0:+200M --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;3:$GUID_APPLE_BOOT --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;3:&lt;span style="color:#e6db74"&gt;&amp;#34;Apple Boot&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;4:0:+128M --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;4:$GUID_MS_RESERVED --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;4:&lt;span style="color:#e6db74"&gt;&amp;#34;MS Reserved&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;5:0:+450M --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;5:$GUID_WINDOWS_RECOVERY --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;5:&lt;span style="color:#e6db74"&gt;&amp;#34;Windows Recovery&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;6:0:+&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;SWAP_SIZE&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;G --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;6:$GUID_SWAP --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;6:&lt;span style="color:#e6db74"&gt;&amp;#34;Linux Swap&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;7:0:+&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;SLOG_SIZE&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;G --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;7:$GUID_ZFS --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;7:&lt;span style="color:#e6db74"&gt;&amp;#34;ZFS SLOG&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;8:0:+&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;L2ARC_SIZE&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;G --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;8:$GUID_ZFS --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;8:&lt;span style="color:#e6db74"&gt;&amp;#34;ZFS L2ARC&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;9:0:+&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;SPECIAL_SIZE&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;G --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;9:$GUID_ZFS --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;9:&lt;span style="color:#e6db74"&gt;&amp;#34;ZFS Special&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; ENDSECTOR&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;sgdisk -E &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk --new&lt;span style="color:#f92672"&gt;=&lt;/span&gt;10:0:&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$ENDSECTOR&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; --typecode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;10:$GUID_ZFS --change-name&lt;span style="color:#f92672"&gt;=&lt;/span&gt;10:&lt;span style="color:#e6db74"&gt;&amp;#34;ZFS Dedup&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# sgdisk --new=10:0:0 --typecode=10:$GUID_ZFS --change-name=10:&amp;#34;ZFS Data&amp;#34; &amp;#34;$DISK&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; sgdisk -p &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; partprobe &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Partition HDDs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;for&lt;/span&gt; DISK in &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;HDD_DISKS[@]&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;; &lt;span style="color:#66d9ef"&gt;do&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; DISK_SIZE_BYTES&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;lsblk -b -dn -o SIZE &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; DISK_SIZE_GIB&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;scale=2; &lt;/span&gt;$DISK_SIZE_BYTES&lt;span style="color:#e6db74"&gt; / (1024^3)&amp;#34;&lt;/span&gt; | bc&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; SWAP_SIZE&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;get_swap_size &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK_SIZE_GIB&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; partition_hdd &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$SWAP_SIZE&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;done&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Partition NVMe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;for&lt;/span&gt; DISK in &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;NVME_DISKS[@]&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;; &lt;span style="color:#66d9ef"&gt;do&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; partition_nvme &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;$DISK&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;done&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Inform kernel of partition changes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo partprobe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Format swap partitions and enable&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;for&lt;/span&gt; DISK in &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;HDD_DISKS[@]&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt; &lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;NVME_DISKS[@]&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;; &lt;span style="color:#66d9ef"&gt;do&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; SWAP_PART&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;&lt;/span&gt;&lt;span style="color:#e6db74"&gt;${&lt;/span&gt;DISK&lt;span style="color:#e6db74"&gt;}&lt;/span&gt;&lt;span style="color:#e6db74"&gt;-part6&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo mkswap &amp;#34;$SWAP_PART&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo swapon &amp;#34;$SWAP_PART&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;done&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Create RAID0 arrays for log, cache, special on NVMe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo mdadm --create --verbose /dev/md0 --level=0 --raid-devices=3 &amp;#34;${NVME_DISKS[0]}-part7&amp;#34; &amp;#34;${NVME_DISKS[1]}-part7&amp;#34; &amp;#34;${NVME_DISKS[2]}-part7 ${NVME_DISKS[3]}-part7&amp;#34; &amp;#34;${NVME_DISKS[4]}-part7&amp;#34; &amp;#34;${NVME_DISKS[5]}-part7&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo mdadm --create --verbose /dev/md1 --level=0 --raid-devices=3 &amp;#34;${NVME_DISKS[0]}-part8&amp;#34; &amp;#34;${NVME_DISKS[1]}-part8&amp;#34; &amp;#34;${NVME_DISKS[2]}-part8 ${NVME_DISKS[3]}-part8&amp;#34; &amp;#34;${NVME_DISKS[4]}-part8&amp;#34; &amp;#34;${NVME_DISKS[5]}-part8&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo mdadm --create --verbose /dev/md2 --level=0 --raid-devices=3 &amp;#34;${NVME_DISKS[0]}-part9&amp;#34; &amp;#34;${NVME_DISKS[1]}-part9&amp;#34; &amp;#34;${NVME_DISKS[2]}-part9 ${NVME_DISKS[3]}-part9&amp;#34; &amp;#34;${NVME_DISKS[4]}-part9&amp;#34; &amp;#34;${NVME_DISKS[5]}-part9&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Wait for RAID arrays to initialize&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#sleep 10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Create ZFS pool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo zpool create zfs_pool raidz0 &amp;#34;${HDD_DISKS[@]/%/-part7}&amp;#34; log &amp;#34;${NVME_DISKS[0]}-part7&amp;#34; &amp;#34;${NVME_DISKS[1]}-part7&amp;#34; &amp;#34;${NVME_DISKS[2]}-part7 ${NVME_DISKS[3]}-part7&amp;#34; &amp;#34;${NVME_DISKS[4]}-part7&amp;#34; &amp;#34;${NVME_DISKS[5]}-part7&amp;#34; cache &amp;#34;${NVME_DISKS[0]}-part8&amp;#34; &amp;#34;${NVME_DISKS[1]}-part8&amp;#34; &amp;#34;${NVME_DISKS[2]}-part8 ${NVME_DISKS[3]}-part8&amp;#34; &amp;#34;${NVME_DISKS[4]}-part8&amp;#34; &amp;#34;${NVME_DISKS[5]}-part8&amp;#34; special &amp;#34;${NVME_DISKS[0]}-part9&amp;#34; &amp;#34;${NVME_DISKS[1]}-part9&amp;#34; &amp;#34;${NVME_DISKS[2]}-part9 ${NVME_DISKS[3]}-part9&amp;#34; &amp;#34;${NVME_DISKS[4]}-part9&amp;#34; &amp;#34;${NVME_DISKS[5]}-part9&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#echo &amp;#34;ZFS pool &amp;#39;zfs_pool&amp;#39; created successfully with log, cache, and special on RAID0 arrays.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/ata-WDC_WD4003FRYZ-01F0DB0_VBGGLSNF-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/ata-WDC_WD4003FRYZ-01F0DB0_VBGGL0RF-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/ata-TOSHIBA_HDWR11A_X1K0A036FB4G-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/ata-TOSHIBA_HDWR11A_X1K0A031FB4G-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_1TB_S467NX0K822865W-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/nvme-CT2000P3PSSD8_2305E6A607AC-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/nvme-WD_Blue_SN580_2TB_23306X800120-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S6Z2NF0X200223V-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221858P-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#mkswap /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221870V-part6&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#zpool destroy -f mypool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;zpool create &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -f &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -m none &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -R /mnt &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -t mypool &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o ashift&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#ae81ff"&gt;12&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o autoexpand&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o autoreplace&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o autotrim&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o cachefile&lt;span style="color:#f92672"&gt;=&lt;/span&gt;/etc/zfs/zpool.cache &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o comment&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;&amp;#34;My zfs pool&amp;#34;&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o delegation&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o failmode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;continue&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@allocation_classes&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@async_destroy&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@bookmarks&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@bookmark_v2&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@bookmark_written&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@device_rebuild&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@device_removal&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@draid&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@edonr&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@embedded_data&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@empty_bpobj&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@enabled_txg&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@encryption&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@extensible_dataset&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@filesystem_limits&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@hole_birth&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@large_blocks&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@large_dnode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@livelist&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@log_spacemap&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@lz4_compress&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@multi_vdev_crash_dump&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@obsolete_counts&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@project_quota&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@redacted_datasets&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@redaction_bookmarks&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@resilver_defer&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@sha512&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@skein&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@spacemap_histogram&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@spacemap_v2&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@userobj_accounting&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@zpool_checkpoint&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o feature@zstd_compress&lt;span style="color:#f92672"&gt;=&lt;/span&gt;enabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o listsnapshots&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -o multihost&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O aclinherit&lt;span style="color:#f92672"&gt;=&lt;/span&gt;restricted &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O aclmode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;groupmask &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O acltype&lt;span style="color:#f92672"&gt;=&lt;/span&gt;posixacl &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O atime&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O canmount&lt;span style="color:#f92672"&gt;=&lt;/span&gt;noauto &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O casesensitivity&lt;span style="color:#f92672"&gt;=&lt;/span&gt;sensitive &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O checksum&lt;span style="color:#f92672"&gt;=&lt;/span&gt;sha256 &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O compression&lt;span style="color:#f92672"&gt;=&lt;/span&gt;lz4 &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O copies&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#ae81ff"&gt;1&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O dedup&lt;span style="color:#f92672"&gt;=&lt;/span&gt;sha256,verify &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O devices&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O dnodesize&lt;span style="color:#f92672"&gt;=&lt;/span&gt;auto &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O encryption&lt;span style="color:#f92672"&gt;=&lt;/span&gt;off &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O exec&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O filesystem_limit&lt;span style="color:#f92672"&gt;=&lt;/span&gt;none &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O logbias&lt;span style="color:#f92672"&gt;=&lt;/span&gt;throughput &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O mountpoint&lt;span style="color:#f92672"&gt;=&lt;/span&gt;legacy &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O nbmand&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O normalization&lt;span style="color:#f92672"&gt;=&lt;/span&gt;formD &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O overlay&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O primarycache&lt;span style="color:#f92672"&gt;=&lt;/span&gt;all &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O quota&lt;span style="color:#f92672"&gt;=&lt;/span&gt;none &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O readonly&lt;span style="color:#f92672"&gt;=&lt;/span&gt;off &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O recordsize&lt;span style="color:#f92672"&gt;=&lt;/span&gt;1M &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O redundant_metadata&lt;span style="color:#f92672"&gt;=&lt;/span&gt;some &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O refquota&lt;span style="color:#f92672"&gt;=&lt;/span&gt;none &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O relatime&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O reservation&lt;span style="color:#f92672"&gt;=&lt;/span&gt;none &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O secondarycache&lt;span style="color:#f92672"&gt;=&lt;/span&gt;all &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O setuid&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O sharenfs&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O sharesmb&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O snapdev&lt;span style="color:#f92672"&gt;=&lt;/span&gt;visible &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O snapdir&lt;span style="color:#f92672"&gt;=&lt;/span&gt;visible &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O snapshot_limit&lt;span style="color:#f92672"&gt;=&lt;/span&gt;none &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O sync&lt;span style="color:#f92672"&gt;=&lt;/span&gt;disabled &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O version&lt;span style="color:#f92672"&gt;=&lt;/span&gt;current &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O volmode&lt;span style="color:#f92672"&gt;=&lt;/span&gt;full &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O vscan&lt;span style="color:#f92672"&gt;=&lt;/span&gt;on &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; -O xattr&lt;span style="color:#f92672"&gt;=&lt;/span&gt;sa &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; zfs_pool draid &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; /dev/disk/by-id/ata-WDC_WD4003FRYZ-01F0DB0_VBGGLSNF-part7 /dev/disk/by-id/ata-WDC_WD4003FRYZ-01F0DB0_VBGGL0RF-part7 /dev/disk/by-id/ata-TOSHIBA_HDWR11A_X1K0A036FB4G-part7 /dev/disk/by-id/ata-TOSHIBA_HDWR11A_X1K0A031FB4G-part7 &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; log /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_1TB_S467NX0K822865W-part7 /dev/disk/by-id/nvme-CT2000P3PSSD8_2305E6A607AC-part7 /dev/disk/by-id/nvme-WD_Blue_SN580_2TB_23306X800120-part7 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S6Z2NF0X200223V-part7 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221858P-part7 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221870V-part7 &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; cache /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_1TB_S467NX0K822865W-part8 /dev/disk/by-id/nvme-CT2000P3PSSD8_2305E6A607AC-part8 /dev/disk/by-id/nvme-WD_Blue_SN580_2TB_23306X800120-part8 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S6Z2NF0X200223V-part8 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221858P-part8 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221870V-part8 &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; special /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_1TB_S467NX0K822865W-part9 /dev/disk/by-id/nvme-CT2000P3PSSD8_2305E6A607AC-part9 /dev/disk/by-id/nvme-WD_Blue_SN580_2TB_23306X800120-part9 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S6Z2NF0X200223V-part9 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221858P-part9 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221870V-part9 &lt;span style="color:#ae81ff"&gt;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; dedup /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_1TB_S467NX0K822865W-part10 /dev/disk/by-id/nvme-CT2000P3PSSD8_2305E6A607AC-part10 /dev/disk/by-id/nvme-WD_Blue_SN580_2TB_23306X800120-part10 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S6Z2NF0X200223V-part10 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221858P-part10 /dev/disk/by-id/nvme-Samsung_SSD_990_PRO_2TB_S7DNNJ0X221870V-part10 
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>chroot</title><link>https://dominicusin.github.io/2025/01/24/gist-chroot/</link><pubDate>Fri, 24 Jan 2025 09:46:30 +0000</pubDate><guid>https://dominicusin.github.io/2025/01/24/gist-chroot/</guid><description>&lt;p&gt;chroot&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/8402abedb4df49c2852ce150f03a5372" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;dnf --releasever=&amp;#39;rawhide&amp;#39; --repofrompath=&amp;#39;rawhide,http://mirrors.dotsrc.org/fedora-enchilada/linux/development/rawhide/Everything/x86_64/os/&amp;#39; --repofrompath=&amp;#39;rawhide-modular,https://mirrors.huaweicloud.com/repository/fedora/development/rawhide/Modular/x86_64/os/&amp;#39; --installroot=&amp;#39;/chroot/fedora&amp;#39; --enablerepo=&amp;#39;rawhide,rawhide-modular&amp;#39; --setopt=install_weak_deps=True --nogpgcheck install dnf @core 
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;##dnf install --nogpgcheck --repofrompath &amp;#39;terra,https://repos.fyralabs.com/terra$releasever&amp;#39; terra-release
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;debootstrap --verbose --no-check-gpg --no-merged-usr --components=&amp;#34;main,contrib,non-free,non-free-firmware&amp;#34; ceres /chroot/devuan http://deb.devuan.org/merged
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;debootstrap --verbose --components=main,contrib,non-free-firmware,non-free --variant=minbase --merged-usr --force-check-gpg --log-extra-deps stable /chroot/debian https://deb.debian.org/debian
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ARCH=amd64 debootstrap --arch=amd64 --verbose --components=main,multiverse,restricted,universe --extra-suites=plucky,plucky-backports,plucky-proposed,plucky-security,plucky-updates,devel-backports,devel-proposed,devel-security,devel-updates,devel --variant=minbase --merged-usr --force-check-sig --force-check-gpg --log-extra-deps --include=build-essential,tasksel,aptitude,mc,htop,most,mosh,screen,tmux plucky /mnt/Ubuntu http://archive.ubuntu.com/ubuntu/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;zypper --root /chroot/suse install --allow-vendor-change --allow-arch-change --allow-name-change --allow-downgrade --recommends --force-resolution --auto-agree-with-licenses --replacefiles --no-confirm --force --allow-unsigned-rpm --oldpackage --details zypper
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;pacman -r /chroot/arch --cachedir=/chroot/arch/var/cache/pacman/pkg --config=/chroot/arch/etc/pacman.conf -Syyuu base base-devel
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;nixos-generate-config --root /mnt/NixOS; nixos-install --root /mnt/NixOS
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;guix time-machine -C /mnt/Guix/etc/channels.scm -- system init /mnt/Guix/etc/config.scm /mnt/Guix/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>lists</title><link>https://dominicusin.github.io/2024/10/23/gist-lists/</link><pubDate>Wed, 23 Oct 2024 11:15:44 +0000</pubDate><guid>https://dominicusin.github.io/2024/10/23/gist-lists/</guid><description>&lt;p&gt;lists&lt;/p&gt;
&lt;p&gt;&lt;a href="https://gist.github.com/dominicusin/4d2dd71dbda592ec3e974f895d9629b6" target="_blank" rel="noreferrer"&gt;View on GitHub Gist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=all,amd64 signed-by=/usr/share/keyrings/prebuilt-mpr-archive-keyring.gpg] https://proget.makedeb.org prebuilt-mpr bookworm
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64,arm64,armhf] https://packages.microsoft.com/repos/code stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64] http://dl.google.com/linux/earth/deb/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64] https://dl.google.com/linux/chrome/deb/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64] https://packages.microsoft.com/repos/edge/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64] https://repo.vivaldi.com/snapshot/deb/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64] https://repo.vivaldi.com/stable/deb/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64,i386 signed-by=/usr/share/keyrings/steam.gpg] https://repo.steampowered.com/steam/ beta steam
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64,i386 signed-by=/usr/share/keyrings/steam.gpg] https://repo.steampowered.com/steam/ stable steam
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/etc/apt/keyrings/liquorix-keyring.gpg] https://liquorix.net/debian sid main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/etc/apt/keyrings/liquorix-keyring.gpg] https://liquorix.net/debian stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/etc/apt/keyrings/liquorix-keyring.gpg] https://liquorix.net/debian testing main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/etc/apt/keyrings/liquorix-keyring.gpg] https://liquorix.net/debian unstable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/keybase.gpg] http://prerelease.keybase.io/deb stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/proxmox-release-bookworm.gpg] http://download.proxmox.com/debian/pve bookworm pvetest pve-no-subscription
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/usr/share/keyrings/brave-browser-archive-keyring.gpg] https://brave-browser-apt-release.s3.brave.com/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/usr/share/keyrings/brave-browser-nightly-archive-keyring.gpg] https://brave-browser-apt-nightly.s3.brave.com/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/usr/share/keyrings/oracle-virtualbox-2016.gpg] https://download.virtualbox.org/virtualbox/debian bookworm contrib
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [arch=amd64 signed-by=/usr/share/keyrings/seafile-keyring.asc] https://linux-clients.seafile.com/seafile-deb/bookworm/ stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ bookworm-proposed-updates main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ bullseye-backports main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ experimental main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldoldstable main contrib non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldoldstable-proposed-updates main contrib non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldoldstable-updates main contrib non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldstable-backports-sloppy main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldstable main contrib non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldstable-proposed-updates main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ oldstable-updates main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ rc-buggy main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ sid main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ stable-backports main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ stable-backports-sloppy main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ stable main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ stable-updates main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ testing-backports main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ testing main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ testing-proposed-updates main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ testing-updates main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.debian.org/debian/ unstable main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.opera.com/opera-beta/ stable non-free #Opera Browser (final releases)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.opera.com/opera-developer/ stable non-free #Opera Browser (final releases)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://deb.opera.com/opera-stable/ stable non-free #Opera Browser (final releases)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://download.sublimetext.com/ apt/dev/
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://ftp.gwdg.de/pub/linux/siduction/extra unstable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://ftp.gwdg.de/pub/linux/siduction/fixes unstable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://incoming.debian.org/debian-buildd buildd-unstable main contrib non-free-firmware non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.bchemnet.com/suldr/ debian extra
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org experimental main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org oldoldstable-backports main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org oldoldstable main non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org sid main non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org stable-backports main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org stable main non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb https://www.deb-multimedia.org testing main non-free
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/etc/apt/trusted.gpg.d/agp-debian-key.gpg] http://ag-projects.com/debian stable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/etc/apt/trusted.gpg.d/agp-debian-key.gpg] http://ag-projects.com/debian unstable main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/cuda-archive-keyring.gpg] https://developer.download.nvidia.com/compute/cuda/repos/debian12/x86_64/ /
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/indexdata.gpg] https://ftp.indexdata.com/debian bullseye main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/jetbrains-ppa-archive-keyring.gpg] http://jetbrains-ppa.s3-website.eu-central-1.amazonaws.com any main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/makedeb-archive-keyring.gpg arch=all] https://proget.makedeb.org makedeb main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/meganz-archive-keyring.gpg] https://mega.nz/linux/repo/Debian_testing/ ./
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/xanmod-archive-keyring.gpg] http://deb.xanmod.org releases main
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb [signed-by=/usr/share/keyrings/zotero-archive-keyring.gpg by-hash=force] https://zotero.retorque.re/file/apt-package-archive ./
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;deb-src [arch=amd64 signed-by=/etc/apt/keyrings/liquorix-keyring.gpg] https://liquorix.net/debian sid main&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>Alternative Internet</title><link>https://dominicusin.github.io/2023/12/16/alternative-internet/</link><pubDate>Sat, 16 Dec 2023 02:40:00 +0000</pubDate><guid>https://dominicusin.github.io/2023/12/16/alternative-internet/</guid><description>&lt;h1 class="relative group"&gt;Alternative Internet
 &lt;div id="alternative-internet" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#alternative-internet" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;A collection of interesting networks and technology aiming at re-decentralizing the Internet. If you would like to help in categorising these projects, please submit a PR to this README.md file.&lt;/p&gt;</description></item><item><title>Three Virtues</title><link>https://dominicusin.github.io/2023/08/26/three-virtues/</link><pubDate>Sat, 26 Aug 2023 03:27:00 +0000</pubDate><guid>https://dominicusin.github.io/2023/08/26/three-virtues/</guid><description>&lt;p&gt;According to Larry Wall, There are three great virtues of a programmer: Laziness, Impatience and Hubris&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Laziness: The quality that makes you go to great effort to reduce overall energy expenditure. It makes you write labor-saving programs that other people will find useful and document what you wrote so you don&amp;rsquo;t have to answer so many questions about it.&lt;/p&gt;</description></item><item><title>Awesome tunneling</title><link>https://dominicusin.github.io/2023/06/25/awesome-tunneling/</link><pubDate>Sun, 25 Jun 2023 08:09:00 +0000</pubDate><guid>https://dominicusin.github.io/2023/06/25/awesome-tunneling/</guid><description>&lt;p&gt;forked from anderspitman/awesome-tunneling&lt;/p&gt;
&lt;p&gt;The purpose of this list is to track and compare tunneling solutions. This is
primarily targeted toward self-hosters and developers who want to do things
like exposing a local webserver via a public domain name, with automatic HTTPS,
even if behind a NAT or other restricted network.&lt;/p&gt;</description></item><item><title>Dark Web Links</title><link>https://dominicusin.github.io/2023/05/18/dark-web-links/</link><pubDate>Thu, 18 May 2023 06:02:00 +0000</pubDate><guid>https://dominicusin.github.io/2023/05/18/dark-web-links/</guid><description>&lt;h1 class="relative group"&gt;Dark Web Links v3
 &lt;div id="dark-web-links-v3" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#dark-web-links-v3" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;

&lt;h2 class="relative group"&gt;New v3 Hidden Services
 &lt;div id="new-v3-hidden-services" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#new-v3-hidden-services" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;V3 Onion Hidden Services Links And Deprecation Of Old V2 Onion Sites
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;The short version 2 onion services will deprecated, after 15 years the Tor Project is going to switch to the new and more secore, and also longer version 3 .onion links.
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Make sure to have a site like this repo bookmarked where you can find the new v3 dark web links.
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;The following list are the first sites which are available as a v3 .onion hidden service, when more sites switch to the new protocol, we will update the homepage with a bigger list of up to date links.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;blockquote&gt;&lt;p&gt;Recommendet to use &lt;a href="https://tails.boum.org/" title="Tails" target="_blank" rel="noreferrer"&gt;Tails&lt;/a&gt; as a live usb&lt;/p&gt;</description></item><item><title>Awesome Piracy</title><link>https://dominicusin.github.io/2023/01/20/awesome-piracy/</link><pubDate>Fri, 20 Jan 2023 05:45:00 +0000</pubDate><guid>https://dominicusin.github.io/2023/01/20/awesome-piracy/</guid><description>&lt;h1 class="relative group"&gt;Awesome Piracy &lt;a href="https://awesome.re" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Awesome"
 src="https://awesome.re/badge.svg"
 &gt;&lt;/figure&gt;
&lt;/a&gt;
 &lt;div id="awesome-piracy-awesome" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#awesome-piracy-awesome" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;blockquote&gt;&lt;p&gt;A curated list of arrrrrrrrr! ! !&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 class="relative group"&gt;Contents
 &lt;div id="contents" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#contents" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://dominicusin.github.io/2023/01/20/awesome-piracy/#preamble" &gt;Preamble&lt;/a&gt;&lt;/p&gt;</description></item><item><title>A Collection of Awesome AI Applications</title><link>https://dominicusin.github.io/2023/01/14/a-collection-of-awesome-ai-applications/</link><pubDate>Sat, 14 Jan 2023 13:26:00 +0000</pubDate><guid>https://dominicusin.github.io/2023/01/14/a-collection-of-awesome-ai-applications/</guid><description>&lt;p&gt;&lt;a href="https://github.com/ai-collection/ai-collection/blob/main/README.md" target="_blank" rel="noreferrer"&gt;https://github.com/ai-collection/ai-collection/blob/main/README.md&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="white_check_mark"
 src="https://github.githubassets.com/images/icons/emoji/unicode/2705.png"
 &gt;&lt;/figure&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="grey_question"
 src="https://github.githubassets.com/images/icons/emoji/unicode/2754.png"
 &gt;&lt;/figure&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="x"
 src="https://github.githubassets.com/images/icons/emoji/unicode/274c.png"
 &gt;&lt;/figure&gt;
&lt;/p&gt;

&lt;h2 class="relative group"&gt;Index
 &lt;div id="index" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#index" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://dominicusin.github.io/2023/01/14/a-collection-of-awesome-ai-applications/#Architecture--interior-design" &gt;Architecture &amp;amp; Interior Design&lt;/a&gt;&lt;/p&gt;</description></item><item><title>old programmers</title><link>https://dominicusin.github.io/2022/07/16/old-programmers/</link><pubDate>Sat, 16 Jul 2022 22:50:00 +0000</pubDate><guid>https://dominicusin.github.io/2022/07/16/old-programmers/</guid><description>&lt;p&gt;The old programmers never die&amp;hellip;&lt;/p&gt;
&lt;p&gt;they gosub without return&lt;/p&gt;
&lt;p&gt;they never even had life&lt;/p&gt;
&lt;p&gt;they just decompile&lt;/p&gt;
&lt;p&gt;they just cast to void&lt;/p&gt;
&lt;p&gt;They just lose their memory. They just byte it.&lt;/p&gt;</description></item><item><title>Awesome-Selfhosted</title><link>https://dominicusin.github.io/2022/05/16/awesome-selfhosted/</link><pubDate>Mon, 16 May 2022 19:52:00 +0000</pubDate><guid>https://dominicusin.github.io/2022/05/16/awesome-selfhosted/</guid><description>&lt;h1 class="relative group"&gt;Awesome-Selfhosted
 &lt;div id="awesome-selfhosted" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#awesome-selfhosted" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;from&lt;a href="https://github.com/awesome-selfhosted/awesome-selfhosted" target="_blank" rel="noreferrer"&gt; https://github.com/awesome-selfhosted/awesome-selfhosted&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/sindresorhus/awesome" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Awesome"
 src="https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg"
 &gt;&lt;/figure&gt;
&lt;/a&gt; &lt;a href="https://github.com/awesome-selfhosted/awesome-selfhosted/issues/2266" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt=""
 src="https://img.shields.io/travis/awesome-selfhosted/awesome-selfhosted/master?label=link%20checks"
 &gt;&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Self-hosting is the practice of hosting and managing applications on your own server(s) instead of consuming from &lt;a href="https://www.gnu.org/philosophy/who-does-that-server-really-serve.html" target="_blank" rel="noreferrer"&gt;SaaSS&lt;/a&gt; providers.&lt;/p&gt;</description></item><item><title>Lua Neovim</title><link>https://dominicusin.github.io/2022/03/15/lua-neovim/</link><pubDate>Tue, 15 Mar 2022 01:33:00 +0000</pubDate><guid>https://dominicusin.github.io/2022/03/15/lua-neovim/</guid><description>&lt;h1 class="relative group"&gt;Начало работы с Lua в Neovim
 &lt;div id="начало-работы-с-lua-в-neovim" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%bd%d0%b0%d1%87%d0%b0%d0%bb%d0%be-%d1%80%d0%b0%d0%b1%d0%be%d1%82%d1%8b-%d1%81-lua-%d0%b2-neovim" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;

&lt;h2 class="relative group"&gt;Содержание
 &lt;div id="содержание" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d1%81%d0%be%d0%b4%d0%b5%d1%80%d0%b6%d0%b0%d0%bd%d0%b8%d0%b5" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b2%d0%b2%d0%b5%d0%b4%d0%b5%d0%bd%d0%b8%d0%b5" &gt;Введение&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d0%b7%d1%83%d1%87%d0%b5%d0%bd%d0%b8%d0%b5-lua" &gt;Изучение языка Lua&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d0%bc%d0%b5%d1%8e%d1%89%d0%b8%d0%b5%d1%81%d1%8f-%d1%82%d1%83%d1%82%d0%be%d1%80%d0%b8%d0%b0%d0%bb%d1%8b-%d0%bf%d0%be-%d0%bd%d0%b0%d0%bf%d0%b8%d1%81%d0%b0%d0%bd%d0%b8%d1%8e-%d0%bf%d0%bb%d0%b0%d0%b3%d0%b8%d0%bd%d0%be%d0%b2-%d0%bd%d0%b0-lua-%d0%b4%d0%bb%d1%8f-neovim" &gt;Имеющиеся туториалы по написанию плагинов на Lua для Neovim&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%81%d0%b2%d1%8f%d0%b7%d0%b0%d0%bd%d0%bd%d1%8b%d0%b5-%d0%bf%d0%bb%d0%b0%d0%b3%d0%b8%d0%bd%d1%8b" &gt;Связанные плагины&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%ba%d1%83%d0%b4%d0%b0-%d0%ba%d0%bb%d0%b0%d1%81%d1%82%d1%8c-%d1%84%d0%b0%d0%b9%d0%bb%d1%8b-lua" &gt;Куда класть файлы Lua&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#initlua" &gt;init.lua&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b4%d1%80%d1%83%d0%b3%d0%b8%d0%b5-%d1%84%d0%b0%d0%b9%d0%bb%d1%8b-lua" &gt;Другие файлы Lua&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%b5%d0%b4%d0%be%d1%81%d1%82%d0%b5%d1%80%d0%b5%d0%b6%d0%b5%d0%bd%d0%b8%d1%8f" &gt;Предостережения&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%81%d0%be%d0%b2%d0%b5%d1%82%d1%8b" &gt;Советы&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b7%d0%b0%d0%bc%d0%b5%d1%82%d0%ba%d0%b0-%d0%be%d1%82%d0%bd%d0%be%d1%81%d0%b8%d1%82%d0%b5%d0%bb%d1%8c%d0%bd%d0%be-%d0%bf%d0%b0%d0%ba%d0%b5%d1%82%d0%be%d0%b2" &gt;Заметка относительно пакетов&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d1%81%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-lua-%d0%b2-vimscript" &gt;Использование Lua в Vimscript&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#lua" &gt;:lua&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#luado" &gt;:luado&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#luafile" &gt;:luafile&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#luafile-vs-require" &gt;luafile vs require():&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#luaeval" &gt;luaeval()&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vlua" &gt;v:lua&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%b5%d0%b4%d0%be%d1%81%d1%82%d0%b5%d1%80%d0%b5%d0%b6%d0%b5%d0%bd%d0%b8%d1%8f-1" &gt;Предостережения&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%81%d0%be%d0%b2%d0%b5%d1%82%d1%8b-1" &gt;Советы&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%be%d1%81%d1%82%d1%80%d0%b0%d0%bd%d1%81%d1%82%d0%b2%d0%be-%d0%b8%d0%bc%d1%91%d0%bd-vim" &gt;Пространство имён vim&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%81%d0%be%d0%b2%d0%b5%d1%82%d1%8b-2" &gt;Советы&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%98%d1%81%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-Vimscript-%d0%b8%d0%b7-Lua" &gt;Использование Vimscript из Lua&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimapinvim_eval" &gt;vim.api.nvim_eval()&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%b5%d0%b4%d0%be%d1%81%d1%82%d0%b5%d1%80%d0%b5%d0%b6%d0%b5%d0%bd%d0%b8%d1%8f-2" &gt;Предостережения&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimapinvim_exec" &gt;vim.api.nvim_exec()&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimapinvim_command" &gt;vim.api.nvim_command()&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%81%d0%be%d0%b2%d0%b5%d1%82%d1%8b-3" &gt;Советы&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%83%d0%bf%d1%80%d0%b0%d0%b2%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d0%be%d0%bf%d1%86%d0%b8%d0%b8-vim" &gt;Управление опции vim&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d1%81%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-%d1%84%d1%83%d0%bd%d0%ba%d1%86%d0%b8%d0%b9-api" &gt;Использование функций API&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d1%81%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-%d0%bc%d0%b5%d1%82%d0%b0-%d0%b0%d0%ba%d1%81%d0%b5%d1%81%d1%81%d0%be%d1%80%d0%be%d0%b2" &gt;Использование мета-аксессоров&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%b5%d0%b4%d0%be%d1%81%d1%82%d0%b5%d1%80%d0%b5%d0%b6%d0%b5%d0%bd%d0%b8%d1%8f-3" &gt;Предостережения&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%83%d0%bf%d1%80%d0%b0%d0%b2%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d0%b2%d0%bd%d1%83%d1%82%d1%80%d0%b5%d0%bd%d0%bd%d0%b8%d0%bc%d0%b8-%d0%bf%d0%b5%d1%80%d0%b5%d0%bc%d0%b5%d0%bd%d0%bd%d1%8b%d0%bc%d0%b8-vim" &gt;Управление внутренними переменными vim&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d1%81%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-%d1%84%d1%83%d0%bd%d0%ba%d1%86%d0%b8%d0%b9-api-1" &gt;Использование функций API&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b8%d1%81%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-%d0%bc%d0%b5%d1%82%d0%b0-%d0%b0%d0%ba%d1%81%d0%b5%d1%81%d1%81%d0%be%d1%80%d0%be%d0%b2-1" &gt;Использование мета-аксессоров&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%b5%d0%b4%d0%be%d1%81%d1%82%d0%b5%d1%80%d0%b5%d0%b6%d0%b5%d0%bd%d0%b8%d1%8f-4" &gt;Предостережения&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%b2%d1%8b%d0%b7%d0%be%d0%b2-%d1%84%d1%83%d0%bd%d0%ba%d1%86%d0%b8%d0%b9-vimscript" &gt;Вызов функций Vimscript&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimcall" &gt;vim.call()&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimfnfunction" &gt;vim.fn.{function}()&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%81%d0%be%d0%b2%d0%b5%d1%82%d1%8b-4" &gt;Советы&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bf%d1%80%d0%b5%d0%b4%d0%be%d1%81%d1%82%d0%b5%d1%80%d0%b5%d0%b6%d0%b5%d0%bd%d0%b8%d1%8f-5" &gt;Предостережения&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%be%d0%bf%d1%80%d0%b5%d0%b4%d0%b5%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d1%81%d0%be%d0%bf%d0%be%d1%81%d1%82%d0%b0%d0%b2%d0%bb%d0%b5%d0%bd%d0%b8%d0%b9-%d0%ba%d0%bb%d0%b0%d0%b2%d0%b8%d1%88" &gt;Определение сопоставлений клавиш&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%be%d0%bf%d1%80%d0%b5%d0%b4%d0%b5%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d0%bf%d0%be%d0%bb%d1%8c%d0%b7%d0%be%d0%b2%d0%b0%d1%82%d0%b5%d0%bb%d1%8c%d1%81%d0%ba%d0%b8%d1%85-%d0%ba%d0%be%d0%bc%d0%b0%d0%bd%d0%b4" &gt;Определение пользовательских команд&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%be%d0%bf%d1%80%d0%b5%d0%b4%d0%b5%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d0%b0%d0%b2%d1%82%d0%be%d0%ba%d0%be%d0%bc%d0%b0%d0%bd%d0%b4" &gt;Определение автокоманд&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%be%d0%bf%d1%80%d0%b5%d0%b4%d0%b5%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d1%81%d0%b8%d0%bd%d1%82%d0%b0%d0%ba%d1%81%d0%b8%d1%81%d0%b0%d0%bf%d0%be%d0%b4%d1%81%d0%b2%d0%b5%d1%82%d0%ba%d0%b8" &gt;Определение синтаксиса/подсветки&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%be%d0%b1%d1%89%d0%b8%d0%b5-%d1%81%d0%be%d0%b2%d0%b5%d1%82%d1%8b-%d0%b8-%d1%80%d0%b5%d0%ba%d0%be%d0%bc%d0%b5%d0%bd%d0%b4%d0%b0%d1%86%d0%b8%d0%b8" &gt;Общие советы и рекомендации&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d0%bd%d0%b0%d1%81%d1%82%d1%80%d0%be%d0%b9%d0%ba%d0%b0-%d0%bb%d0%b8%d0%bd%d1%82%d0%b5%d1%80%d0%be%d0%b2%d1%8f%d0%b7%d1%8b%d0%ba%d0%be%d0%b2%d1%8b%d1%85-%d1%81%d0%b5%d1%80%d0%b2%d0%b5%d1%80%d0%be%d0%b2" &gt;Настройка линтеров/языковых серверов&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#luacheck" &gt;luacheck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#sumnekolua-language-server" &gt;sumneko/lua-language-server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#cocnvim" &gt;coc.nvim&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#%d1%80%d0%b0%d0%b7%d0%bd%d0%be%d0%b5" &gt;Разное&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimloop" &gt;vim.loop&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimlsp" &gt;vim.lsp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#vimtreesitter" &gt;vim.treesitter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2022/03/15/lua-neovim/#transpilers" &gt;Transpilers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Created by &lt;a href="https://github.com/ekalinin/github-markdown-toc" target="_blank" rel="noreferrer"&gt;gh-md-toc&lt;/a&gt;&lt;/p&gt;</description></item><item><title>macOS-Security-and-Privacy-Guide</title><link>https://dominicusin.github.io/2021/09/06/macos-security-and-privacy-guide/</link><pubDate>Mon, 06 Sep 2021 06:01:00 +0000</pubDate><guid>https://dominicusin.github.io/2021/09/06/macos-security-and-privacy-guide/</guid><description>&lt;p&gt;This guide is a collection of techniques for improving the security and privacy of a modern Apple Macintosh computer (&amp;ldquo;MacBook&amp;rdquo;) running a recent version of macOS (formerly known as &amp;ldquo;OS X&amp;rdquo;).&lt;/p&gt;</description></item><item><title>free-for.dev</title><link>https://dominicusin.github.io/2021/08/29/free-for-dev/</link><pubDate>Sun, 29 Aug 2021 15:14:00 +0000</pubDate><guid>https://dominicusin.github.io/2021/08/29/free-for-dev/</guid><description>&lt;h1 class="relative group"&gt;free-for.dev
 &lt;div id="free-fordev" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#free-fordev" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;Developers and Open Source authors now have a massive amount of services offering free tiers, but it can be hard to find them all to make informed decisions.&lt;/p&gt;</description></item><item><title>PoC in GitHub</title><link>https://dominicusin.github.io/2020/05/21/poc-in-github/</link><pubDate>Thu, 21 May 2020 01:05:00 +0000</pubDate><guid>https://dominicusin.github.io/2020/05/21/poc-in-github/</guid><description>&lt;h1 class="relative group"&gt;PoC in GitHub
 &lt;div id="poc-in-github" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#poc-in-github" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;

&lt;h2 class="relative group"&gt;2020
 &lt;div id="2020" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2020" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0022
 &lt;div id="cve-2020-0022" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0022" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/CVE-2020-0022" target="_blank" rel="noreferrer"&gt;marcinguy/CVE-2020-0022&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leommxj/cve-2020-0022" target="_blank" rel="noreferrer"&gt;leommxj/cve-2020-0022&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0041
 &lt;div id="cve-2020-0041" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0041" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bluefrostsecurity/CVE-2020-0041" target="_blank" rel="noreferrer"&gt;bluefrostsecurity/CVE-2020-0041&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0069
 &lt;div id="cve-2020-0069" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0069" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/R0rt1z2/AutomatedRoot" target="_blank" rel="noreferrer"&gt;R0rt1z2/AutomatedRoot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TheRealJunior/mtk-su-reverse-cve-2020-0069" target="_blank" rel="noreferrer"&gt;TheRealJunior/mtk-su-reverse-cve-2020-0069&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yanglingxi1993/CVE-2020-0069" target="_blank" rel="noreferrer"&gt;yanglingxi1993/CVE-2020-0069&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/quarkslab/CVE-2020-0069_poc" target="_blank" rel="noreferrer"&gt;quarkslab/CVE-2020-0069_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0551
 &lt;div id="cve-2020-0551" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0551" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bitdefender/lvi-lfb-attack-poc" target="_blank" rel="noreferrer"&gt;bitdefender/lvi-lfb-attack-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0557
 &lt;div id="cve-2020-0557" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0557" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hessandrew/CVE-2020-0557_INTEL-SA-00338" target="_blank" rel="noreferrer"&gt;hessandrew/CVE-2020-0557_INTEL-SA-00338&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0568
 &lt;div id="cve-2020-0568" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0568" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to potentially enable denial of service via local access.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hessandrew/CVE-2020-0568_INTEL-SA-00344" target="_blank" rel="noreferrer"&gt;hessandrew/CVE-2020-0568_INTEL-SA-00344&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0601
 &lt;div id="cve-2020-0601" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0601" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nissan-sudo/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;nissan-sudo/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xxon/cve-2020-0601" target="_blank" rel="noreferrer"&gt;0xxon/cve-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SherlockSec/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;SherlockSec/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JPurrier/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;JPurrier/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xxon/cve-2020-0601-plugin" target="_blank" rel="noreferrer"&gt;0xxon/cve-2020-0601-plugin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ollypwn/CurveBall" target="_blank" rel="noreferrer"&gt;ollypwn/CurveBall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kudelskisecurity/chainoffools" target="_blank" rel="noreferrer"&gt;kudelskisecurity/chainoffools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RrUZi/Awesome-CVE-2020-0601" target="_blank" rel="noreferrer"&gt;RrUZi/Awesome-CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BleepSec/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;BleepSec/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/apmunch/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;apmunch/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/saleemrashid/badecparams" target="_blank" rel="noreferrer"&gt;saleemrashid/badecparams&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xxon/cve-2020-0601-utils" target="_blank" rel="noreferrer"&gt;0xxon/cve-2020-0601-utils&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Doug-Moody/Windows10_Cumulative_Updates_PowerShell" target="_blank" rel="noreferrer"&gt;Doug-Moody/Windows10_Cumulative_Updates_PowerShell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MarkusZehnle/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;MarkusZehnle/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/YoannDqr/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;YoannDqr/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thimelp/cve-2020-0601-Perl" target="_blank" rel="noreferrer"&gt;thimelp/cve-2020-0601-Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dlee35/curveball_lua" target="_blank" rel="noreferrer"&gt;dlee35/curveball_lua&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/IIICTECH/-CVE-2020-0601-ECC---EXPLOIT" target="_blank" rel="noreferrer"&gt;IIICTECH/-CVE-2020-0601-ECC&amp;mdash;EXPLOIT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cosmicifint/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;cosmicifint/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gentilkiwi/curveball" target="_blank" rel="noreferrer"&gt;gentilkiwi/curveball&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Hans-MartinHannibalLauridsen/CurveBall" target="_blank" rel="noreferrer"&gt;Hans-MartinHannibalLauridsen/CurveBall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/apodlosky/PoC_CurveBall" target="_blank" rel="noreferrer"&gt;apodlosky/PoC_CurveBall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ioncodes/Curveball" target="_blank" rel="noreferrer"&gt;ioncodes/Curveball&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/amlweems/gringotts" target="_blank" rel="noreferrer"&gt;amlweems/gringotts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aloswoya/CVE-2020-0601" target="_blank" rel="noreferrer"&gt;aloswoya/CVE-2020-0601&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/talbeerysec/CurveBallDetection" target="_blank" rel="noreferrer"&gt;talbeerysec/CurveBallDetection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/david4599/CurveballCertTool" target="_blank" rel="noreferrer"&gt;david4599/CurveballCertTool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eastmountyxz/CVE-2020-0601-EXP" target="_blank" rel="noreferrer"&gt;eastmountyxz/CVE-2020-0601-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eastmountyxz/CVE-2018-20250-WinRAR" target="_blank" rel="noreferrer"&gt;eastmountyxz/CVE-2018-20250-WinRAR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gremwell/cve-2020-0601_poc" target="_blank" rel="noreferrer"&gt;gremwell/cve-2020-0601_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bsides-rijeka/meetup-2-curveball" target="_blank" rel="noreferrer"&gt;bsides-rijeka/meetup-2-curveball&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TechHexagon/CVE-2020-0601-spoofkey" target="_blank" rel="noreferrer"&gt;TechHexagon/CVE-2020-0601-spoofkey&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ShayNehmad/twoplustwo" target="_blank" rel="noreferrer"&gt;ShayNehmad/twoplustwo&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0609
 &lt;div id="cve-2020-0609" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0609" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/2d4d/rdg_scanner_cve-2020-0609" target="_blank" rel="noreferrer"&gt;2d4d/rdg_scanner_cve-2020-0609&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ollypwn/BlueGate" target="_blank" rel="noreferrer"&gt;ollypwn/BlueGate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MalwareTech/RDGScanner" target="_blank" rel="noreferrer"&gt;MalwareTech/RDGScanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Bechsen/CVE-2020-0609" target="_blank" rel="noreferrer"&gt;Bechsen/CVE-2020-0609&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ioncodes/BlueGate" target="_blank" rel="noreferrer"&gt;ioncodes/BlueGate&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0618
 &lt;div id="cve-2020-0618" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0618" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/euphrat1ca/CVE-2020-0618" target="_blank" rel="noreferrer"&gt;euphrat1ca/CVE-2020-0618&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wortell/cve-2020-0618" target="_blank" rel="noreferrer"&gt;wortell/cve-2020-0618&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0624
 &lt;div id="cve-2020-0624" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0624" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/james0x40/CVE-2020-0624" target="_blank" rel="noreferrer"&gt;james0x40/CVE-2020-0624&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0668
 &lt;div id="cve-2020-0668" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0668" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/itm4n/SysTracingPoc" target="_blank" rel="noreferrer"&gt;itm4n/SysTracingPoc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RedCursorSecurityConsulting/CVE-2020-0668" target="_blank" rel="noreferrer"&gt;RedCursorSecurityConsulting/CVE-2020-0668&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Nan3r/CVE-2020-0668" target="_blank" rel="noreferrer"&gt;Nan3r/CVE-2020-0668&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0674
 &lt;div id="cve-2020-0674" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0674" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/binaryfigments/CVE-2020-0674" target="_blank" rel="noreferrer"&gt;binaryfigments/CVE-2020-0674&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0683
 &lt;div id="cve-2020-0683" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0683" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/padovah4ck/CVE-2020-0683" target="_blank" rel="noreferrer"&gt;padovah4ck/CVE-2020-0683&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0688
 &lt;div id="cve-2020-0688" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0688" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/random-robbie/cve-2020-0688" target="_blank" rel="noreferrer"&gt;random-robbie/cve-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jumbo-WJB/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;Jumbo-WJB/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/cve-2020-0688" target="_blank" rel="noreferrer"&gt;Ridter/cve-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Yt1g3r/CVE-2020-0688_EXP" target="_blank" rel="noreferrer"&gt;Yt1g3r/CVE-2020-0688_EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/righter83/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;righter83/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/truongtn/cve-2020-0688" target="_blank" rel="noreferrer"&gt;truongtn/cve-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/onSec-fr/CVE-2020-0688-Scanner" target="_blank" rel="noreferrer"&gt;onSec-fr/CVE-2020-0688-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/youncyb/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;youncyb/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zcgonvh/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;zcgonvh/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/justin-p/PSForgot2kEyXCHANGE" target="_blank" rel="noreferrer"&gt;justin-p/PSForgot2kEyXCHANGE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cert-lv/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;cert-lv/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ravinacademy/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;ravinacademy/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mahyarx/Exploit_CVE-2020-0688" target="_blank" rel="noreferrer"&gt;mahyarx/Exploit_CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ktpdpro/CVE-2020-0688" target="_blank" rel="noreferrer"&gt;ktpdpro/CVE-2020-0688&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0692
 &lt;div id="cve-2020-0692" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0692" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/githubassets/CVE-2020-0692" target="_blank" rel="noreferrer"&gt;githubassets/CVE-2020-0692&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0728
 &lt;div id="cve-2020-0728" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0728" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/irsl/CVE-2020-0728" target="_blank" rel="noreferrer"&gt;irsl/CVE-2020-0728&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0753
 &lt;div id="cve-2020-0753" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0753" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/afang5472/CVE-2020-0753-and-CVE-2020-0754" target="_blank" rel="noreferrer"&gt;afang5472/CVE-2020-0753-and-CVE-2020-0754&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/VikasVarshney/CVE-2020-0753-and-CVE-2020-0754" target="_blank" rel="noreferrer"&gt;VikasVarshney/CVE-2020-0753-and-CVE-2020-0754&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0796
 &lt;div id="cve-2020-0796" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0796" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Aekras1a/CVE-2020-0796-PoC" target="_blank" rel="noreferrer"&gt;Aekras1a/CVE-2020-0796-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/technion/DisableSMBCompression" target="_blank" rel="noreferrer"&gt;technion/DisableSMBCompression&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/T13nn3s/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;T13nn3s/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ollypwn/SMBGhost" target="_blank" rel="noreferrer"&gt;ollypwn/SMBGhost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/joaozietolie/CVE-2020-0796-Checker" target="_blank" rel="noreferrer"&gt;joaozietolie/CVE-2020-0796-Checker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pr4jwal/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;pr4jwal/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ButrintKomoni/cve-2020-0796" target="_blank" rel="noreferrer"&gt;ButrintKomoni/cve-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dickens88/cve-2020-0796-scanner" target="_blank" rel="noreferrer"&gt;dickens88/cve-2020-0796-scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kn6869610/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;kn6869610/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/awareseven/eternalghosttest" target="_blank" rel="noreferrer"&gt;awareseven/eternalghosttest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/weidutech/CVE-2020-0796-PoC" target="_blank" rel="noreferrer"&gt;weidutech/CVE-2020-0796-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/OfJAAH/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;OfJAAH/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xax007/CVE-2020-0796-Scanner" target="_blank" rel="noreferrer"&gt;xax007/CVE-2020-0796-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Dhoomralochana/Scanners-for-CVE-2020-0796-Testing" target="_blank" rel="noreferrer"&gt;Dhoomralochana/Scanners-for-CVE-2020-0796-Testing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/UraSecTeam/smbee" target="_blank" rel="noreferrer"&gt;UraSecTeam/smbee&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xtobu/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;0xtobu/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/netscylla/SMBGhost" target="_blank" rel="noreferrer"&gt;netscylla/SMBGhost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eerykitty/CVE-2020-0796-PoC" target="_blank" rel="noreferrer"&gt;eerykitty/CVE-2020-0796-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wneessen/SMBCompScan" target="_blank" rel="noreferrer"&gt;wneessen/SMBCompScan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ioncodes/SMBGhost" target="_blank" rel="noreferrer"&gt;ioncodes/SMBGhost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/laolisafe/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;laolisafe/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gabimarti/SMBScanner" target="_blank" rel="noreferrer"&gt;gabimarti/SMBScanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Almorabea/SMBGhost-WorkaroundApplier" target="_blank" rel="noreferrer"&gt;Almorabea/SMBGhost-WorkaroundApplier&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/IAreKyleW00t/SMBGhosts" target="_blank" rel="noreferrer"&gt;IAreKyleW00t/SMBGhosts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vysecurity/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;vysecurity/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;marcinguy/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/plorinquer/cve-2020-0796" target="_blank" rel="noreferrer"&gt;plorinquer/cve-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BinaryShadow94/SMBv3.1.1-scan---CVE-2020-0796" target="_blank" rel="noreferrer"&gt;BinaryShadow94/SMBv3.1.1-scan&amp;mdash;CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x1n5h3n/SMBGhost" target="_blank" rel="noreferrer"&gt;x1n5h3n/SMBGhost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wsfengfan/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;wsfengfan/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/miraizeroday/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;miraizeroday/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GuoKerS/aioScan_CVE-2020-0796" target="_blank" rel="noreferrer"&gt;GuoKerS/aioScan_CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/CVE-2020-0796-Scanner" target="_blank" rel="noreferrer"&gt;jiansiting/CVE-2020-0796-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/maxpl0it/Unauthenticated-CVE-2020-0796-PoC" target="_blank" rel="noreferrer"&gt;maxpl0it/Unauthenticated-CVE-2020-0796-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ran-sama/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;ran-sama/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sujitawake/smbghost" target="_blank" rel="noreferrer"&gt;sujitawake/smbghost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/julixsalas/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;julixsalas/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/insightglacier/SMBGhost_Crash_Poc" target="_blank" rel="noreferrer"&gt;insightglacier/SMBGhost_Crash_Poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/5l1v3r1/CVE-2020-0796-PoC-and-Scan" target="_blank" rel="noreferrer"&gt;5l1v3r1/CVE-2020-0796-PoC-and-Scan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cory-zajicek/CVE-2020-0796-DoS" target="_blank" rel="noreferrer"&gt;cory-zajicek/CVE-2020-0796-DoS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tripledd/cve-2020-0796-vuln" target="_blank" rel="noreferrer"&gt;tripledd/cve-2020-0796-vuln&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/danigargu/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;danigargu/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ZecOps/CVE-2020-0796-LPE-POC" target="_blank" rel="noreferrer"&gt;ZecOps/CVE-2020-0796-LPE-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TinToSer/CVE-2020-0796-LPE" target="_blank" rel="noreferrer"&gt;TinToSer/CVE-2020-0796-LPE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/f1tz/CVE-2020-0796-LPE-EXP" target="_blank" rel="noreferrer"&gt;f1tz/CVE-2020-0796-LPE-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tango-j/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;tango-j/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;jiansiting/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eastmountyxz/CVE-2020-0796-SMB" target="_blank" rel="noreferrer"&gt;eastmountyxz/CVE-2020-0796-SMB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LabDookhtegan/CVE-2020-0796-EXP" target="_blank" rel="noreferrer"&gt;LabDookhtegan/CVE-2020-0796-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Rvn0xsy/CVE_2020_0796_CNA" target="_blank" rel="noreferrer"&gt;Rvn0xsy/CVE_2020_0796_CNA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xeb-bp/cve-2020-0796" target="_blank" rel="noreferrer"&gt;0xeb-bp/cve-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/intelliroot-tech/cve-2020-0796-Scanner" target="_blank" rel="noreferrer"&gt;intelliroot-tech/cve-2020-0796-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thelostworldFree/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;thelostworldFree/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/syadg123/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;syadg123/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/section-c/CVE-2020-0796" target="_blank" rel="noreferrer"&gt;section-c/CVE-2020-0796&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0798
 &lt;div id="cve-2020-0798" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0798" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0779, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/githubassets/CVE-2020-0798" target="_blank" rel="noreferrer"&gt;githubassets/CVE-2020-0798&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0814
 &lt;div id="cve-2020-0814" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0814" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0779, CVE-2020-0798, CVE-2020-0842, CVE-2020-0843.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/klinix5/CVE-2020-0814" target="_blank" rel="noreferrer"&gt;klinix5/CVE-2020-0814&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0883
 &lt;div id="cve-2020-0883" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0883" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/githubassets/CVE-2020-0883" target="_blank" rel="noreferrer"&gt;githubassets/CVE-2020-0883&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thelostworldFree/CVE-2020-0883" target="_blank" rel="noreferrer"&gt;thelostworldFree/CVE-2020-0883&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/syadg123/CVE-2020-0883" target="_blank" rel="noreferrer"&gt;syadg123/CVE-2020-0883&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0905
 &lt;div id="cve-2020-0905" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0905" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/githubassets/CVE-2020-0905" target="_blank" rel="noreferrer"&gt;githubassets/CVE-2020-0905&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0910
 &lt;div id="cve-2020-0910" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0910" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/inetshell/CVE-2020-0910" target="_blank" rel="noreferrer"&gt;inetshell/CVE-2020-0910&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-0976
 &lt;div id="cve-2020-0976" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-0976" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0975, CVE-2020-0977.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ericzhong2010/GUI-Check-CVE-2020-0976" target="_blank" rel="noreferrer"&gt;ericzhong2010/GUI-Check-CVE-2020-0976&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10199
 &lt;div id="cve-2020-10199" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10199" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zhzyker/exphub" target="_blank" rel="noreferrer"&gt;zhzyker/exphub&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wsfengfan/CVE-2020-10199-10204" target="_blank" rel="noreferrer"&gt;wsfengfan/CVE-2020-10199-10204&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2020-10199" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2020-10199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/magicming200/CVE-2020-10199_CVE-2020-10204" target="_blank" rel="noreferrer"&gt;magicming200/CVE-2020-10199_CVE-2020-10204&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhzyker/CVE-2020-10199_POC-EXP" target="_blank" rel="noreferrer"&gt;zhzyker/CVE-2020-10199_POC-EXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10204
 &lt;div id="cve-2020-10204" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10204" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/duolaoa333/CVE-2020-10204" target="_blank" rel="noreferrer"&gt;duolaoa333/CVE-2020-10204&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10238
 &lt;div id="cve-2020-10238" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10238" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HoangKien1020/CVE-2020-10238" target="_blank" rel="noreferrer"&gt;HoangKien1020/CVE-2020-10238&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10239
 &lt;div id="cve-2020-10239" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10239" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HoangKien1020/CVE-2020-10239" target="_blank" rel="noreferrer"&gt;HoangKien1020/CVE-2020-10239&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10551
 &lt;div id="cve-2020-10551" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10551" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/seqred-s-a/CVE-2020-10551" target="_blank" rel="noreferrer"&gt;seqred-s-a/CVE-2020-10551&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10558
 &lt;div id="cve-2020-10558" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10558" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other miscellaneous functions from the main screen.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nuzzl/CVE-2020-10558" target="_blank" rel="noreferrer"&gt;nuzzl/CVE-2020-10558&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10560
 &lt;div id="cve-2020-10560" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10560" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/LucidUnicorn/CVE-2020-10560-Key-Recovery" target="_blank" rel="noreferrer"&gt;LucidUnicorn/CVE-2020-10560-Key-Recovery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kevthehermit/CVE-2020-10560" target="_blank" rel="noreferrer"&gt;kevthehermit/CVE-2020-10560&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10663
 &lt;div id="cve-2020-10663" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10663" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rails-lts/json_cve_2020_10663" target="_blank" rel="noreferrer"&gt;rails-lts/json_cve_2020_10663&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-10673
 &lt;div id="cve-2020-10673" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-10673" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0nise/CVE-2020-10673" target="_blank" rel="noreferrer"&gt;0nise/CVE-2020-10673&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-11107
 &lt;div id="cve-2020-11107" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-11107" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/S1lkys/CVE-2020-11107" target="_blank" rel="noreferrer"&gt;S1lkys/CVE-2020-11107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andripwn/CVE-2020-11107" target="_blank" rel="noreferrer"&gt;andripwn/CVE-2020-11107&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-11539
 &lt;div id="cve-2020-11539" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-11539" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band doesn't have any authentication or signature verification. Thus, any attacker can control a parameter of the device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/the-girl-who-lived/CVE-2020-11539" target="_blank" rel="noreferrer"&gt;the-girl-who-lived/CVE-2020-11539&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-11650
 &lt;div id="cve-2020-11650" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-11650" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/weinull/CVE-2020-11650" target="_blank" rel="noreferrer"&gt;weinull/CVE-2020-11650&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-11651
 &lt;div id="cve-2020-11651" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-11651" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chef-cft/salt-vulnerabilities" target="_blank" rel="noreferrer"&gt;chef-cft/salt-vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-11890
 &lt;div id="cve-2020-11890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-11890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HoangKien1020/CVE-2020-11890" target="_blank" rel="noreferrer"&gt;HoangKien1020/CVE-2020-11890&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-12078
 &lt;div id="cve-2020-12078" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-12078" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip value is passed to the exec function in the discoveries_helper.php file (inside the all_ip_list function) without being filtered, which means that the attacker can provide a payload instead of a valid IP address.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2020-12078" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2020-12078&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-12112
 &lt;div id="cve-2020-12112" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-12112" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tchenu/CVE-2020-12112" target="_blank" rel="noreferrer"&gt;tchenu/CVE-2020-12112&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-12122
 &lt;div id="cve-2020-12122" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-12122" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FULLSHADE/CVE-2020-12122" target="_blank" rel="noreferrer"&gt;FULLSHADE/CVE-2020-12122&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-1611
 &lt;div id="cve-2020-1611" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-1611" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Local File Inclusion vulnerability in Juniper Networks Junos Space allows an attacker to view all files on the target when the device receives malicious HTTP packets. This issue affects: Juniper Networks Junos Space versions prior to 19.4R1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ibonok/CVE-2020-1611" target="_blank" rel="noreferrer"&gt;Ibonok/CVE-2020-1611&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-1938
 &lt;div id="cve-2020-1938" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-1938" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0nise/CVE-2020-1938" target="_blank" rel="noreferrer"&gt;0nise/CVE-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xindongzhuaizhuai/CVE-2020-1938" target="_blank" rel="noreferrer"&gt;xindongzhuaizhuai/CVE-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nibiwodong/CNVD-2020-10487-Tomcat-ajp-POC" target="_blank" rel="noreferrer"&gt;nibiwodong/CNVD-2020-10487-Tomcat-ajp-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Kit4y/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner" target="_blank" rel="noreferrer"&gt;Kit4y/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/laolisafe/CVE-2020-1938" target="_blank" rel="noreferrer"&gt;laolisafe/CVE-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DaemonShao/CVE-2020-1938" target="_blank" rel="noreferrer"&gt;DaemonShao/CVE-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read" target="_blank" rel="noreferrer"&gt;sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fairyming/CVE-2020-1938" target="_blank" rel="noreferrer"&gt;fairyming/CVE-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dacade/cve-2020-1938" target="_blank" rel="noreferrer"&gt;dacade/cve-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/woaiqiukui/CVE-2020-1938TomcatAjpScanner" target="_blank" rel="noreferrer"&gt;woaiqiukui/CVE-2020-1938TomcatAjpScanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fatal0/tomcat-cve-2020-1938-check" target="_blank" rel="noreferrer"&gt;fatal0/tomcat-cve-2020-1938-check&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/GhostCat-LFI-exp" target="_blank" rel="noreferrer"&gt;ze0r/GhostCat-LFI-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/delsadan/CNVD-2020-10487-Bulk-verification" target="_blank" rel="noreferrer"&gt;delsadan/CNVD-2020-10487-Bulk-verification&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/00theway/Ghostcat-CNVD-2020-10487" target="_blank" rel="noreferrer"&gt;00theway/Ghostcat-CNVD-2020-10487&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shaunmclernon/ghostcat-verification" target="_blank" rel="noreferrer"&gt;shaunmclernon/ghostcat-verification&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Zaziki1337/Ghostcat-CVE-2020-1938" target="_blank" rel="noreferrer"&gt;Zaziki1337/Ghostcat-CVE-2020-1938&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/w4fz5uck5/CVE-2020-1938-Clean-Version" target="_blank" rel="noreferrer"&gt;w4fz5uck5/CVE-2020-1938-Clean-Version&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/syncxx/CVE-2020-1938-Tool" target="_blank" rel="noreferrer"&gt;syncxx/CVE-2020-1938-Tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ZhengHaoCHeng/CNVD-2020-10487" target="_blank" rel="noreferrer"&gt;ZhengHaoCHeng/CNVD-2020-10487&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-1947
 &lt;div id="cve-2020-1947" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-1947" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. Unmarshalling untrusted data can lead to security flaws of RCE.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Imanfeng/CVE-2020-1947" target="_blank" rel="noreferrer"&gt;Imanfeng/CVE-2020-1947&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2020-1947" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2020-1947&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wsfengfan/CVE-2020-1947" target="_blank" rel="noreferrer"&gt;wsfengfan/CVE-2020-1947&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shadowsock5/ShardingSphere_CVE-2020-1947" target="_blank" rel="noreferrer"&gt;shadowsock5/ShardingSphere_CVE-2020-1947&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-1958
 &lt;div id="cve-2020-1958" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-1958" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. They are still subject to role-based authorization checks, if configured. Callers of Druid APIs can also retrieve any LDAP attribute values of users that exist on the LDAP server, so long as that information is visible to the Druid server. This information disclosure does not require the caller itself to be a valid LDAP user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ggolawski/CVE-2020-1958" target="_blank" rel="noreferrer"&gt;ggolawski/CVE-2020-1958&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-1967
 &lt;div id="cve-2020-1967" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-1967" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;quot;signature_algorithms_cert&amp;quot; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/irsl/CVE-2020-1967" target="_blank" rel="noreferrer"&gt;irsl/CVE-2020-1967&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-2333
 &lt;div id="cve-2020-2333" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-2333" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/section-c/CVE-2020-2333" target="_blank" rel="noreferrer"&gt;section-c/CVE-2020-2333&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-2546
 &lt;div id="cve-2020-2546" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-2546" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hktalent/CVE_2020_2546" target="_blank" rel="noreferrer"&gt;hktalent/CVE_2020_2546&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-2551
 &lt;div id="cve-2020-2551" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-2551" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xn0ne/weblogicScanner" target="_blank" rel="noreferrer"&gt;0xn0ne/weblogicScanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2020-2551" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2020-2551&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hktalent/CVE-2020-2551" target="_blank" rel="noreferrer"&gt;hktalent/CVE-2020-2551&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0nise/CVE-2020-2551" target="_blank" rel="noreferrer"&gt;0nise/CVE-2020-2551&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Y4er/CVE-2020-2551" target="_blank" rel="noreferrer"&gt;Y4er/CVE-2020-2551&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Gspider7/rmi-iiop" target="_blank" rel="noreferrer"&gt;Gspider7/rmi-iiop&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cnsimo/CVE-2020-2551" target="_blank" rel="noreferrer"&gt;cnsimo/CVE-2020-2551&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fa1c0n1/test-poc-weblogic" target="_blank" rel="noreferrer"&gt;fa1c0n1/test-poc-weblogic&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-2555
 &lt;div id="cve-2020-2555" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-2555" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Hu3sky/CVE-2020-2555" target="_blank" rel="noreferrer"&gt;Hu3sky/CVE-2020-2555&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wsfengfan/CVE-2020-2555" target="_blank" rel="noreferrer"&gt;wsfengfan/CVE-2020-2555&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0nise/CVE-2020-2555" target="_blank" rel="noreferrer"&gt;0nise/CVE-2020-2555&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Y4er/CVE-2020-2555" target="_blank" rel="noreferrer"&gt;Y4er/CVE-2020-2555&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Maskhe/cve-2020-2555" target="_blank" rel="noreferrer"&gt;Maskhe/cve-2020-2555&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-2655
 &lt;div id="cve-2020-2655" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-2655" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RUB-NDS/CVE-2020-2655-DemoServer" target="_blank" rel="noreferrer"&gt;RUB-NDS/CVE-2020-2655-DemoServer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-3766
 &lt;div id="cve-2020-3766" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-3766" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hessandrew/CVE-2020-3766_APSB20-12" target="_blank" rel="noreferrer"&gt;hessandrew/CVE-2020-3766_APSB20-12&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-3833
 &lt;div id="cve-2020-3833" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-3833" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0d3G33k/Safari-Address-Bar-Spoof-CVE-2020-3833-" target="_blank" rel="noreferrer"&gt;c0d3G33k/Safari-Address-Bar-Spoof-CVE-2020-3833-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-3952
 &lt;div id="cve-2020-3952" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-3952" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/commandermoon/CVE-2020-3952" target="_blank" rel="noreferrer"&gt;commandermoon/CVE-2020-3952&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/frustreated/CVE-2020-3952" target="_blank" rel="noreferrer"&gt;frustreated/CVE-2020-3952&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/guardicore/vmware_vcenter_cve_2020_3952" target="_blank" rel="noreferrer"&gt;guardicore/vmware_vcenter_cve_2020_3952&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gelim/CVE-2020-3952" target="_blank" rel="noreferrer"&gt;gelim/CVE-2020-3952&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Fa1c0n35/vmware_vcenter_cve_2020_3952" target="_blank" rel="noreferrer"&gt;Fa1c0n35/vmware_vcenter_cve_2020_3952&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-4276
 &lt;div id="cve-2020-4276" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-4276" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mekoko/CVE-2020-4276" target="_blank" rel="noreferrer"&gt;mekoko/CVE-2020-4276&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5236
 &lt;div id="cve-2020-5236" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5236" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like &amp;quot;Bad-header: xxxxxxxxxxxxxxx\x10&amp;quot; is received, it will cause the regular expression engine to catastrophically backtrack causing the process to use 100% CPU time and blocking any other interactions. This allows an attacker to send a single request with an invalid header and take the service offline. This issue was introduced in version 1.4.2 when the regular expression was updated to attempt to match the behaviour required by errata associated with RFC7230. The regular expression that is used to validate incoming headers has been updated in version 1.4.3, it is recommended that people upgrade to the new version of Waitress as soon as possible.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/motikan2010/CVE-2020-5236" target="_blank" rel="noreferrer"&gt;motikan2010/CVE-2020-5236&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5250
 &lt;div id="cve-2020-5250" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5250" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change all information of all accounts. The problem is patched in version 1.7.6.4.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/drkbcn/lblfixer_cve2020_5250" target="_blank" rel="noreferrer"&gt;drkbcn/lblfixer_cve2020_5250&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5254
 &lt;div id="cve-2020-5254" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5254" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dpmdpm2/CVE-2020-5254" target="_blank" rel="noreferrer"&gt;dpmdpm2/CVE-2020-5254&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5260
 &lt;div id="cve-2020-5260" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5260" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external &amp;quot;credential helper&amp;quot; programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that contain an encoded newline can inject unintended values into the credential helper protocol stream, causing the credential helper to retrieve the password for one server (e.g., good.example.com) for an HTTP request being made to another server (e.g., evil.example.com), resulting in credentials for the former being sent to the latter. There are no restrictions on the relationship between the two, meaning that an attacker can craft a URL that will present stored credentials for any host to a host of their choosing. The vulnerability can be triggered by feeding a malicious URL to git clone. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The problem has been patched in the versions published on April 14th, 2020, going back to v2.17.x. Anyone wishing to backport the change further can do so by applying commit 9a6bbee (the full release includes extra checks for git fsck, but that commit is sufficient to protect clients against the vulnerability). The patched versions are: 2.17.4, 2.18.3, 2.19.4, 2.20.3, 2.21.2, 2.22.3, 2.23.2, 2.24.2, 2.25.3, 2.26.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brompwnie/cve-2020-5260" target="_blank" rel="noreferrer"&gt;brompwnie/cve-2020-5260&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Asgavar/CVE-2020-5260" target="_blank" rel="noreferrer"&gt;Asgavar/CVE-2020-5260&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sv3nbeast/CVE-2020-5260" target="_blank" rel="noreferrer"&gt;sv3nbeast/CVE-2020-5260&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5267
 &lt;div id="cve-2020-5267" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5267" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GUI/legacy-rails-CVE-2020-5267-patch" target="_blank" rel="noreferrer"&gt;GUI/legacy-rails-CVE-2020-5267-patch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5398
 &lt;div id="cve-2020-5398" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5398" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a &amp;quot;Content-Disposition&amp;quot; header in the response where the filename attribute is derived from user supplied input.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/motikan2010/CVE-2020-5398" target="_blank" rel="noreferrer"&gt;motikan2010/CVE-2020-5398&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5509
 &lt;div id="cve-2020-5509" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5509" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FULLSHADE/CVE-2020-5509" target="_blank" rel="noreferrer"&gt;FULLSHADE/CVE-2020-5509&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-5844
 &lt;div id="cve-2020-5844" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-5844" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
index.php?sec=godmode/extensions&amp;amp;sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheCyberGeek/CVE-2020-5844" target="_blank" rel="noreferrer"&gt;TheCyberGeek/CVE-2020-5844&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-6418
 &lt;div id="cve-2020-6418" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-6418" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ChoKyuWon/CVE-2020-6418" target="_blank" rel="noreferrer"&gt;ChoKyuWon/CVE-2020-6418&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-6650
 &lt;div id="cve-2020-6650" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-6650" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
UPS companion software v1.05 &amp;amp; Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RavSS/Eaton-UPS-Companion-Exploit" target="_blank" rel="noreferrer"&gt;RavSS/Eaton-UPS-Companion-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-6861
 &lt;div id="cve-2020-6861" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-6861" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ph4r05/ledger-app-monero-1.42-vuln" target="_blank" rel="noreferrer"&gt;ph4r05/ledger-app-monero-1.42-vuln&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-6888
 &lt;div id="cve-2020-6888" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-6888" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/section-c/CVE-2020-6888" target="_blank" rel="noreferrer"&gt;section-c/CVE-2020-6888&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-72381
 &lt;div id="cve-2020-72381" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-72381" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jdordonezn/CVE-2020-72381" target="_blank" rel="noreferrer"&gt;jdordonezn/CVE-2020-72381&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7246
 &lt;div id="cve-2020-7246" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7246" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lnxcrew/CVE-2020-7246" target="_blank" rel="noreferrer"&gt;lnxcrew/CVE-2020-7246&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7247
 &lt;div id="cve-2020-7247" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7247" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the &amp;quot;uncommented&amp;quot; default configuration. The issue exists because of an incorrect return value upon failure of input validation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FiroSolutions/cve-2020-7247-exploit" target="_blank" rel="noreferrer"&gt;FiroSolutions/cve-2020-7247-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/superzerosec/cve-2020-7247" target="_blank" rel="noreferrer"&gt;superzerosec/cve-2020-7247&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r0lh/CVE-2020-7247" target="_blank" rel="noreferrer"&gt;r0lh/CVE-2020-7247&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7471
 &lt;div id="cve-2020-7471" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7471" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Saferman/CVE-2020-7471" target="_blank" rel="noreferrer"&gt;Saferman/CVE-2020-7471&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/secoba/DjVul_StringAgg" target="_blank" rel="noreferrer"&gt;secoba/DjVul_StringAgg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SNCKER/CVE-2020-7471" target="_blank" rel="noreferrer"&gt;SNCKER/CVE-2020-7471&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7799
 &lt;div id="cve-2020-7799" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7799" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -&amp;gt; Settings -&amp;gt; Email Templates) or themes (Home -&amp;gt; Settings -&amp;gt; Themes), can execute commands on the underlying operating system by abusing freemarker.template.utility.Execute in the Apache FreeMarker engine that processes custom templates.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Pikaqi/cve-2020-7799" target="_blank" rel="noreferrer"&gt;Pikaqi/cve-2020-7799&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2020-7799" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2020-7799&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7931
 &lt;div id="cve-2020-7931" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7931" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gquere/CVE-2020-7931" target="_blank" rel="noreferrer"&gt;gquere/CVE-2020-7931&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7961
 &lt;div id="cve-2020-7961" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7961" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mzer0one/CVE-2020-7961-POC" target="_blank" rel="noreferrer"&gt;mzer0one/CVE-2020-7961-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Thisisfarhadzadeh/CVE-2020-7961-payloads" target="_blank" rel="noreferrer"&gt;Thisisfarhadzadeh/CVE-2020-7961-payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wcxxxxx/CVE-2020-7961" target="_blank" rel="noreferrer"&gt;wcxxxxx/CVE-2020-7961&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-7980
 &lt;div id="cve-2020-7980" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-7980" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Xh4H/Satellian-CVE-2020-7980" target="_blank" rel="noreferrer"&gt;Xh4H/Satellian-CVE-2020-7980&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8012
 &lt;div id="cve-2020-8012" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8012" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CA Unified Infrastructure Management (Nimsoft/UIM) 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wetw0rk/Exploit-Development" target="_blank" rel="noreferrer"&gt;wetw0rk/Exploit-Development&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8417
 &lt;div id="cve-2020-8417" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8417" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vulncrate/wp-codesnippets-cve-2020-8417" target="_blank" rel="noreferrer"&gt;vulncrate/wp-codesnippets-cve-2020-8417&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/waleweewe12/CVE-2020-8417" target="_blank" rel="noreferrer"&gt;waleweewe12/CVE-2020-8417&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8515
 &lt;div id="cve-2020-8515" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8515" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/imjdl/CVE-2020-8515-PoC" target="_blank" rel="noreferrer"&gt;imjdl/CVE-2020-8515-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/truerandom/nmap_draytek_rce" target="_blank" rel="noreferrer"&gt;truerandom/nmap_draytek_rce&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8597
 &lt;div id="cve-2020-8597" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8597" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/CVE-2020-8597" target="_blank" rel="noreferrer"&gt;marcinguy/CVE-2020-8597&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mentalburden/MrsEAPers" target="_blank" rel="noreferrer"&gt;mentalburden/MrsEAPers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/WinMin/CVE-2020-8597" target="_blank" rel="noreferrer"&gt;WinMin/CVE-2020-8597&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8809
 &lt;div id="cve-2020-8809" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8809" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the contents of downloaded files. In the case of add-ins (if the user is using those), this will lead to code execution. In case of OBIS codes (which the user is always using as they are needed to communicate with the energy meters), this can lead to code execution when combined with CVE-2020-8810.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/seqred-s-a/gxdlmsdirector-cve" target="_blank" rel="noreferrer"&gt;seqred-s-a/gxdlmsdirector-cve&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8813
 &lt;div id="cve-2020-8813" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8813" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2020-8813" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2020-8813&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8825
 &lt;div id="cve-2020-8825" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8825" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hacky1997/CVE-2020-8825" target="_blank" rel="noreferrer"&gt;hacky1997/CVE-2020-8825&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8840
 &lt;div id="cve-2020-8840" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8840" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2020-8840" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2020-8840&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Wfzsec/FastJson1.2.62-RCE" target="_blank" rel="noreferrer"&gt;Wfzsec/FastJson1.2.62-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fairyming/CVE-2020-8840" target="_blank" rel="noreferrer"&gt;fairyming/CVE-2020-8840&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0nise/CVE-2020-8840" target="_blank" rel="noreferrer"&gt;0nise/CVE-2020-8840&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-88888
 &lt;div id="cve-2020-88888" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-88888" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tdcoming/CVE-2020-88888" target="_blank" rel="noreferrer"&gt;tdcoming/CVE-2020-88888&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-8950
 &lt;div id="cve-2020-8950" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-8950" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary folder with an arbitrary file name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sailay1996/amd_eop_poc" target="_blank" rel="noreferrer"&gt;sailay1996/amd_eop_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9008
 &lt;div id="cve-2020-9008" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9008" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kyletimmermans/blackboard-xss" target="_blank" rel="noreferrer"&gt;kyletimmermans/blackboard-xss&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9038
 &lt;div id="cve-2020-9038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JavierOlmedo/CVE-2020-9038" target="_blank" rel="noreferrer"&gt;JavierOlmedo/CVE-2020-9038&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9375
 &lt;div id="cve-2020-9375" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9375" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/thewhiteh4t/cve-2020-9375" target="_blank" rel="noreferrer"&gt;thewhiteh4t/cve-2020-9375&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9380
 &lt;div id="cve-2020-9380" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9380" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/migueltarga/CVE-2020-9380" target="_blank" rel="noreferrer"&gt;migueltarga/CVE-2020-9380&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9442
 &lt;div id="cve-2020-9442" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9442" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hessandrew/CVE-2020-9442" target="_blank" rel="noreferrer"&gt;hessandrew/CVE-2020-9442&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9453
 &lt;div id="cve-2020-9453" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9453" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FULLSHADE/CVE-2020-9453_-_CVE-2020-9014" target="_blank" rel="noreferrer"&gt;FULLSHADE/CVE-2020-9453_-_CVE-2020-9014&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9460
 &lt;div id="cve-2020-9460" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9460" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Guilherme-Rubert/CVE-2020-9460" target="_blank" rel="noreferrer"&gt;Guilherme-Rubert/CVE-2020-9460&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9461
 &lt;div id="cve-2020-9461" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9461" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Guilherme-Rubert/CVE-2020-9461" target="_blank" rel="noreferrer"&gt;Guilherme-Rubert/CVE-2020-9461&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9547
 &lt;div id="cve-2020-9547" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9547" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fairyming/CVE-2020-9547" target="_blank" rel="noreferrer"&gt;fairyming/CVE-2020-9547&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9548
 &lt;div id="cve-2020-9548" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9548" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fairyming/CVE-2020-9548" target="_blank" rel="noreferrer"&gt;fairyming/CVE-2020-9548&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9758
 &lt;div id="cve-2020-9758" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9758" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from unauthenticated to user-level access, leading to full account takeover. The attack fetches multiple credentials because they are stored in the database (stored XSS). This affects the mobile/chat URI via the lgn and psswrd parameters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ari034/CVE-2020-9758" target="_blank" rel="noreferrer"&gt;ari034/CVE-2020-9758&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9768
 &lt;div id="cve-2020-9768" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9768" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to execute arbitrary code with system privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MrKris99/CVE-2020-9768" target="_blank" rel="noreferrer"&gt;MrKris99/CVE-2020-9768&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9781
 &lt;div id="cve-2020-9781" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9781" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0d3G33k/Safari-Video-Permission-Spoof-CVE-2020-9781" target="_blank" rel="noreferrer"&gt;c0d3G33k/Safari-Video-Permission-Spoof-CVE-2020-9781&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-98989
 &lt;div id="cve-2020-98989" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-98989" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tdcoming/CVE-2020-98989" target="_blank" rel="noreferrer"&gt;tdcoming/CVE-2020-98989&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-9999
 &lt;div id="cve-2020-9999" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-9999" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tdcoming/CVE-2020-9999" target="_blank" rel="noreferrer"&gt;tdcoming/CVE-2020-9999&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2020-99999999
 &lt;div id="cve-2020-99999999" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2020-99999999" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tdcoming/CVE-2020-99999999" target="_blank" rel="noreferrer"&gt;tdcoming/CVE-2020-99999999&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2019
 &lt;div id="2019" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2019" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0053
 &lt;div id="cve-2019-0053" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0053" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS. A stack-based overflow is present in the handling of environment variables when connecting via the telnet client to remote telnet servers. This issue only affects the telnet client — accessible from the CLI or shell — in Junos OS. Inbound telnet services are not affected by this issue. This issue affects: Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S13; 12.3X48 versions prior to 12.3X48-D80; 14.1X53 versions prior to 14.1X53-D130, 14.1X53-D49; 15.1 versions prior to 15.1F6-S12, 15.1R7-S4; 15.1X49 versions prior to 15.1X49-D170; 15.1X53 versions prior to 15.1X53-D237, 15.1X53-D496, 15.1X53-D591, 15.1X53-D69; 16.1 versions prior to 16.1R3-S11, 16.1R7-S4; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R2-S7, 17.2R3-S1; 17.3 versions prior to 17.3R3-S4; 17.4 versions prior to 17.4R1-S6, 17.4R2-S3, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S3; 18.2 versions prior to 18.2R1-S5, 18.2R2-S2, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S3, 18.3R2; 18.4 versions prior to 18.4R1-S2, 18.4R2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dreamsmasher/inetutils-CVE-2019-0053-Patched-PKGBUILD" target="_blank" rel="noreferrer"&gt;dreamsmasher/inetutils-CVE-2019-0053-Patched-PKGBUILD&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0192
 &lt;div id="cve-2019-0192" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0192" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-0192" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-0192&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Rapidsafeguard/Solr-RCE-CVE-2019-0192" target="_blank" rel="noreferrer"&gt;Rapidsafeguard/Solr-RCE-CVE-2019-0192&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0193
 &lt;div id="cve-2019-0193" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0193" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's &amp;quot;dataConfig&amp;quot; parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property &amp;quot;enable.dih.dataConfigParam&amp;quot; to true.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xConsoIe/CVE-2019-0193" target="_blank" rel="noreferrer"&gt;xConsoIe/CVE-2019-0193&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-0193" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-0193&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1135/solr_exploit" target="_blank" rel="noreferrer"&gt;1135/solr_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jaychouzzk/CVE-2019-0193-exp" target="_blank" rel="noreferrer"&gt;jaychouzzk/CVE-2019-0193-exp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0211
 &lt;div id="cve-2019-0211" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0211" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ozkanbilge/Apache-Exploit-2019" target="_blank" rel="noreferrer"&gt;ozkanbilge/Apache-Exploit-2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0227
 &lt;div id="cve-2019-0227" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0227" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/cve-2019-0227" target="_blank" rel="noreferrer"&gt;ianxtianxt/cve-2019-0227&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0232
 &lt;div id="cve-2019-0232" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0232" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2019-0232" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2019-0232&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-0232" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-0232&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CherishHair/CVE-2019-0232-EXP" target="_blank" rel="noreferrer"&gt;CherishHair/CVE-2019-0232-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/setrus/CVE-2019-0232" target="_blank" rel="noreferrer"&gt;setrus/CVE-2019-0232&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0539
 &lt;div id="cve-2019-0539" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0539" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka &amp;quot;Chakra Scripting Engine Memory Corruption Vulnerability.&amp;quot; This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0567, CVE-2019-0568.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x43434343/CVE-2019-0539" target="_blank" rel="noreferrer"&gt;0x43434343/CVE-2019-0539&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0604
 &lt;div id="cve-2019-0604" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0604" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/linhlhq/CVE-2019-0604" target="_blank" rel="noreferrer"&gt;linhlhq/CVE-2019-0604&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2019-0604_sharepoint_CVE" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2019-0604_sharepoint_CVE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/k8gege/CVE-2019-0604" target="_blank" rel="noreferrer"&gt;k8gege/CVE-2019-0604&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/m5050/CVE-2019-0604" target="_blank" rel="noreferrer"&gt;m5050/CVE-2019-0604&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/boxhg/CVE-2019-0604" target="_blank" rel="noreferrer"&gt;boxhg/CVE-2019-0604&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0678
 &lt;div id="cve-2019-0678" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0678" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0d3G33k/CVE-2019-0678" target="_blank" rel="noreferrer"&gt;c0d3G33k/CVE-2019-0678&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0708
 &lt;div id="cve-2019-0708" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0708" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hook-s3c/CVE-2019-0708-poc" target="_blank" rel="noreferrer"&gt;hook-s3c/CVE-2019-0708-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SherlockSec/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;SherlockSec/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yetiddbb/CVE-2019-0708-PoC" target="_blank" rel="noreferrer"&gt;yetiddbb/CVE-2019-0708-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/p0p0p0/CVE-2019-0708-exploit" target="_blank" rel="noreferrer"&gt;p0p0p0/CVE-2019-0708-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rockmelodies/CVE-2019-0708-Exploit" target="_blank" rel="noreferrer"&gt;rockmelodies/CVE-2019-0708-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/matengfei000/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;matengfei000/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xiyangzuishuai/Dark-Network-CVE-2019-0708" target="_blank" rel="noreferrer"&gt;xiyangzuishuai/Dark-Network-CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/temp-user-2014/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;temp-user-2014/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/areusecure/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;areusecure/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pry0cc/cve-2019-0708-2" target="_blank" rel="noreferrer"&gt;pry0cc/cve-2019-0708-2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sbkcbig/CVE-2019-0708-EXPloit" target="_blank" rel="noreferrer"&gt;sbkcbig/CVE-2019-0708-EXPloit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sbkcbig/CVE-2019-0708-EXPloit-3389" target="_blank" rel="noreferrer"&gt;sbkcbig/CVE-2019-0708-EXPloit-3389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/YSheldon/MS_T120" target="_blank" rel="noreferrer"&gt;YSheldon/MS_T120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/k8gege/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;k8gege/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hotdog777714/RDS_CVE-2019-0708" target="_blank" rel="noreferrer"&gt;hotdog777714/RDS_CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;jiansiting/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NullByteSuiteDevs/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;NullByteSuiteDevs/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/heaphopopotamus/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;heaphopopotamus/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thugcrowd/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;thugcrowd/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/omaidf/CVE-2019-0708-PoC" target="_blank" rel="noreferrer"&gt;omaidf/CVE-2019-0708-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/blacksunwen/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;blacksunwen/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/infenet/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;infenet/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/n0auth/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;n0auth/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gildaaa/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;gildaaa/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sbkcbig/CVE-2019-0708-Poc-exploit" target="_blank" rel="noreferrer"&gt;sbkcbig/CVE-2019-0708-Poc-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HackerJ0e/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;HackerJ0e/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/syriusbughunt/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;syriusbughunt/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Barry-McCockiner/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;Barry-McCockiner/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ShadowBrokers-ExploitLeak/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;ShadowBrokers-ExploitLeak/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shumtheone/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;shumtheone/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/safly/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;safly/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jaky5155/cve-2019-0708-exp" target="_blank" rel="noreferrer"&gt;Jaky5155/cve-2019-0708-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status" target="_blank" rel="noreferrer"&gt;fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/303sec/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;303sec/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/f8al/CVE-2019-0708-POC" target="_blank" rel="noreferrer"&gt;f8al/CVE-2019-0708-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/blockchainguard/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;blockchainguard/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/haoge8090/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;haoge8090/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/branbot1000/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;branbot1000/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yushiro/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;yushiro/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bilawalzardaer/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;bilawalzardaer/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/skyshell20082008/CVE-2019-0708-PoC-Hitting-Path" target="_blank" rel="noreferrer"&gt;skyshell20082008/CVE-2019-0708-PoC-Hitting-Path&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ttsite/CVE-2019-0708-" target="_blank" rel="noreferrer"&gt;ttsite/CVE-2019-0708-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ttsite/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;ttsite/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/biggerwing/CVE-2019-0708-poc" target="_blank" rel="noreferrer"&gt;biggerwing/CVE-2019-0708-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/n1xbyte/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;n1xbyte/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/freeide/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;freeide/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/edvacco/CVE-2019-0708-POC" target="_blank" rel="noreferrer"&gt;edvacco/CVE-2019-0708-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pry0cc/BlueKeepTracker" target="_blank" rel="noreferrer"&gt;pry0cc/BlueKeepTracker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zjw88282740/CVE-2019-0708-win7" target="_blank" rel="noreferrer"&gt;zjw88282740/CVE-2019-0708-win7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zerosum0x0/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;zerosum0x0/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/herhe/CVE-2019-0708poc" target="_blank" rel="noreferrer"&gt;herhe/CVE-2019-0708poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/l9c/rdp0708scanner" target="_blank" rel="noreferrer"&gt;l9c/rdp0708scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/major203/cve-2019-0708-scan" target="_blank" rel="noreferrer"&gt;major203/cve-2019-0708-scan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SugiB3o/Check-vuln-CVE-2019-0708" target="_blank" rel="noreferrer"&gt;SugiB3o/Check-vuln-CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gobysec/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;gobysec/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/adalenv/CVE-2019-0708-Tool" target="_blank" rel="noreferrer"&gt;adalenv/CVE-2019-0708-Tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/smallFunction/CVE-2019-0708-POC" target="_blank" rel="noreferrer"&gt;smallFunction/CVE-2019-0708-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/freeide/CVE-2019-0708-PoC-Exploit" target="_blank" rel="noreferrer"&gt;freeide/CVE-2019-0708-PoC-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/robertdavidgraham/rdpscan" target="_blank" rel="noreferrer"&gt;robertdavidgraham/rdpscan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/closethe/CVE-2019-0708-POC" target="_blank" rel="noreferrer"&gt;closethe/CVE-2019-0708-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/krivegasa/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit" target="_blank" rel="noreferrer"&gt;krivegasa/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Rostelecom-CERT/bluekeepscan" target="_blank" rel="noreferrer"&gt;Rostelecom-CERT/bluekeepscan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Leoid/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;Leoid/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ht0Ruial/CVE-2019-0708Poc-BatchScanning" target="_blank" rel="noreferrer"&gt;ht0Ruial/CVE-2019-0708Poc-BatchScanning&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oneoy/BlueKeep" target="_blank" rel="noreferrer"&gt;oneoy/BlueKeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/infiniti-team/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;infiniti-team/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/haishanzheng/CVE-2019-0708-generate-hosts" target="_blank" rel="noreferrer"&gt;haishanzheng/CVE-2019-0708-generate-hosts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ekultek/BlueKeep" target="_blank" rel="noreferrer"&gt;Ekultek/BlueKeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/UraSecTeam/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;UraSecTeam/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Gh0st0ne/rdpscan-BlueKeep" target="_blank" rel="noreferrer"&gt;Gh0st0ne/rdpscan-BlueKeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/algo7/bluekeep_CVE-2019-0708_poc_to_exploit" target="_blank" rel="noreferrer"&gt;algo7/bluekeep_CVE-2019-0708_poc_to_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JasonLOU/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;JasonLOU/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shun-gg/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;shun-gg/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AdministratorGithub/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;AdministratorGithub/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/umarfarook882/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;umarfarook882/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HynekPetrak/detect_bluekeep.py" target="_blank" rel="noreferrer"&gt;HynekPetrak/detect_bluekeep.py&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Wileysec/CVE-2019-0708-Batch-Blue-Screen" target="_blank" rel="noreferrer"&gt;Wileysec/CVE-2019-0708-Batch-Blue-Screen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Pa55w0rd/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;Pa55w0rd/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/at0mik/CVE-2019-0708-PoC" target="_blank" rel="noreferrer"&gt;at0mik/CVE-2019-0708-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cream492/CVE-2019-0708-Msf--" target="_blank" rel="noreferrer"&gt;cream492/CVE-2019-0708-Msf&amp;ndash;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wdfcc/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;wdfcc/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cvencoder/cve-2019-0708" target="_blank" rel="noreferrer"&gt;cvencoder/cve-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/CVE-2019-0708-exp" target="_blank" rel="noreferrer"&gt;ze0r/CVE-2019-0708-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mekhalleh/cve-2019-0708" target="_blank" rel="noreferrer"&gt;mekhalleh/cve-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cve-2019-0708-poc/cve-2019-0708" target="_blank" rel="noreferrer"&gt;cve-2019-0708-poc/cve-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andripwn/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;andripwn/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xeb-bp/bluekeep" target="_blank" rel="noreferrer"&gt;0xeb-bp/bluekeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ntkernel0/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;ntkernel0/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-" target="_blank" rel="noreferrer"&gt;dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/turingcompl33t/bluekeep" target="_blank" rel="noreferrer"&gt;turingcompl33t/bluekeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fade-vivida/CVE-2019-0708-test" target="_blank" rel="noreferrer"&gt;fade-vivida/CVE-2019-0708-test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/skommando/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;skommando/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RickGeex/msf-module-CVE-2019-0708" target="_blank" rel="noreferrer"&gt;RickGeex/msf-module-CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wqsemc/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;wqsemc/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mai-lang-chai/CVE-2019-0708-RCE" target="_blank" rel="noreferrer"&gt;mai-lang-chai/CVE-2019-0708-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Micr067/CVE-2019-0708RDP-MSF" target="_blank" rel="noreferrer"&gt;Micr067/CVE-2019-0708RDP-MSF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/adkinguzi/CVE-2019-0708-BlueKeep" target="_blank" rel="noreferrer"&gt;adkinguzi/CVE-2019-0708-BlueKeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FrostsaberX/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;FrostsaberX/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qinggegeya/CVE-2019-0708-EXP-MSF-" target="_blank" rel="noreferrer"&gt;qinggegeya/CVE-2019-0708-EXP-MSF-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/distance-vector/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;distance-vector/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xFlag/CVE-2019-0708-test" target="_blank" rel="noreferrer"&gt;0xFlag/CVE-2019-0708-test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1aa87148377/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;1aa87148377/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/coolboy4me/cve-2019-0708_bluekeep_rce" target="_blank" rel="noreferrer"&gt;coolboy4me/cve-2019-0708_bluekeep_rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cyb0r9/ispy" target="_blank" rel="noreferrer"&gt;Cyb0r9/ispy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shishibabyq/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;shishibabyq/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwnhacker0x18/Wincrash" target="_blank" rel="noreferrer"&gt;pwnhacker0x18/Wincrash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/R4v3nG/CVE-2019-0708-DOS" target="_blank" rel="noreferrer"&gt;R4v3nG/CVE-2019-0708-DOS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ulisesrc/-2-CVE-2019-0708" target="_blank" rel="noreferrer"&gt;ulisesrc/-2-CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/worawit/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;worawit/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cbwang505/CVE-2019-0708-EXP-Windows" target="_blank" rel="noreferrer"&gt;cbwang505/CVE-2019-0708-EXP-Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eastmountyxz/CVE-2019-0708-Windows" target="_blank" rel="noreferrer"&gt;eastmountyxz/CVE-2019-0708-Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JSec1337/Scanner-CVE-2019-0708" target="_blank" rel="noreferrer"&gt;JSec1337/Scanner-CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wanghuohuobutailao/cve-2019-0708" target="_blank" rel="noreferrer"&gt;wanghuohuobutailao/cve-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0709
 &lt;div id="cve-2019-0709" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0709" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0620, CVE-2019-0722.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/YHZX2013/CVE-2019-0709" target="_blank" rel="noreferrer"&gt;YHZX2013/CVE-2019-0709&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qq431169079/CVE-2019-0709" target="_blank" rel="noreferrer"&gt;qq431169079/CVE-2019-0709&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0768
 &lt;div id="cve-2019-0768" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0768" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ruthlezs/ie11_vbscript_exploit" target="_blank" rel="noreferrer"&gt;ruthlezs/ie11_vbscript_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0785
 &lt;div id="cve-2019-0785" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0785" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Jaky5155/CVE-2019-0785" target="_blank" rel="noreferrer"&gt;Jaky5155/CVE-2019-0785&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0803
 &lt;div id="cve-2019-0803" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0803" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ExpLife0011/CVE-2019-0803" target="_blank" rel="noreferrer"&gt;ExpLife0011/CVE-2019-0803&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0808
 &lt;div id="cve-2019-0808" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0808" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/cve-2019-0808-poc" target="_blank" rel="noreferrer"&gt;ze0r/cve-2019-0808-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rakesh143/CVE-2019-0808" target="_blank" rel="noreferrer"&gt;rakesh143/CVE-2019-0808&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/exodusintel/CVE-2019-0808" target="_blank" rel="noreferrer"&gt;exodusintel/CVE-2019-0808&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0841
 &lt;div id="cve-2019-0841" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0841" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rogue-kdc/CVE-2019-0841" target="_blank" rel="noreferrer"&gt;rogue-kdc/CVE-2019-0841&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2019-0841" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2019-0841&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2019-0841-BYPASS" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2019-0841-BYPASS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0859
 &lt;div id="cve-2019-0859" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0859" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Sheisback/CVE-2019-0859-1day-Exploit" target="_blank" rel="noreferrer"&gt;Sheisback/CVE-2019-0859-1day-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0888
 &lt;div id="cve-2019-0888" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0888" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory, aka 'ActiveX Data Objects (ADO) Remote Code Execution Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sophoslabs/CVE-2019-0888" target="_blank" rel="noreferrer"&gt;sophoslabs/CVE-2019-0888&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-0986
 &lt;div id="cve-2019-0986" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-0986" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/padovah4ck/CVE-2019-0986" target="_blank" rel="noreferrer"&gt;padovah4ck/CVE-2019-0986&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10008
 &lt;div id="cve-2019-10008" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10008" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FlameOfIgnis/CVE-2019-10008" target="_blank" rel="noreferrer"&gt;FlameOfIgnis/CVE-2019-10008&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1002101
 &lt;div id="cve-2019-1002101" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1002101" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user’s machine when kubectl cp is called, limited only by the system permissions of the local user. The untar function can both create and follow symbolic links. The issue is resolved in kubectl v1.11.9, v1.12.7, v1.13.5, and v1.14.0.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brompwnie/CVE-2019-1002101-Helpers" target="_blank" rel="noreferrer"&gt;brompwnie/CVE-2019-1002101-Helpers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1003000
 &lt;div id="cve-2019-1003000" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1003000" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wetw0rk/Exploit-Development" target="_blank" rel="noreferrer"&gt;wetw0rk/Exploit-Development&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/adamyordan/cve-2019-1003000-jenkins-rce-poc" target="_blank" rel="noreferrer"&gt;adamyordan/cve-2019-1003000-jenkins-rce-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xtavian/CVE-2019-1003000-and-CVE-2018-1999002-Pre-Auth-RCE-Jenkins" target="_blank" rel="noreferrer"&gt;0xtavian/CVE-2019-1003000-and-CVE-2018-1999002-Pre-Auth-RCE-Jenkins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1NTheKut/CVE-2019-1003000_RCE-DETECTION" target="_blank" rel="noreferrer"&gt;1NTheKut/CVE-2019-1003000_RCE-DETECTION&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10086
 &lt;div id="cve-2019-10086" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10086" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/evilangelplus/CVE-2019-10086" target="_blank" rel="noreferrer"&gt;evilangelplus/CVE-2019-10086&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10092
 &lt;div id="cve-2019-10092" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10092" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/motikan2010/CVE-2019-10092_Docker" target="_blank" rel="noreferrer"&gt;motikan2010/CVE-2019-10092_Docker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1010054
 &lt;div id="cve-2019-1010054" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1010054" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chaizeg/CSRF-breach" target="_blank" rel="noreferrer"&gt;chaizeg/CSRF-breach&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1010298
 &lt;div id="cve-2019-1010298" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1010298" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RKX1209/CVE-2019-1010298" target="_blank" rel="noreferrer"&gt;RKX1209/CVE-2019-1010298&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10149
 &lt;div id="cve-2019-10149" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10149" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bananaphones/exim-rce-quickfix" target="_blank" rel="noreferrer"&gt;bananaphones/exim-rce-quickfix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cowbe0x004/eximrce-CVE-2019-10149" target="_blank" rel="noreferrer"&gt;cowbe0x004/eximrce-CVE-2019-10149&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MNEMO-CERT/PoC--CVE-2019-10149_Exim" target="_blank" rel="noreferrer"&gt;MNEMO-CERT/PoC&amp;ndash;CVE-2019-10149_Exim&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aishee/CVE-2019-10149-quick" target="_blank" rel="noreferrer"&gt;aishee/CVE-2019-10149-quick&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AzizMea/CVE-2019-10149-privilege-escalation" target="_blank" rel="noreferrer"&gt;AzizMea/CVE-2019-10149-privilege-escalation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Brets0150/StickyExim" target="_blank" rel="noreferrer"&gt;Brets0150/StickyExim&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ChrissHack/exim.exp" target="_blank" rel="noreferrer"&gt;ChrissHack/exim.exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/darsigovrustam/CVE-2019-10149" target="_blank" rel="noreferrer"&gt;darsigovrustam/CVE-2019-10149&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Diefunction/CVE-2019-10149" target="_blank" rel="noreferrer"&gt;Diefunction/CVE-2019-10149&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10207
 &lt;div id="cve-2019-10207" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10207" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/butterflyhack/CVE-2019-10207" target="_blank" rel="noreferrer"&gt;butterflyhack/CVE-2019-10207&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10392
 &lt;div id="cve-2019-10392" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10392" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-10392" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-10392&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ftk-sostupid/CVE-2019-10392_EXP" target="_blank" rel="noreferrer"&gt;ftk-sostupid/CVE-2019-10392_EXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1040
 &lt;div id="cve-2019-1040" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1040" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/CVE-2019-1040" target="_blank" rel="noreferrer"&gt;Ridter/CVE-2019-1040&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lazaars/UltraRealy_with_CVE-2019-1040" target="_blank" rel="noreferrer"&gt;lazaars/UltraRealy_with_CVE-2019-1040&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fox-it/cve-2019-1040-scanner" target="_blank" rel="noreferrer"&gt;fox-it/cve-2019-1040-scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wzxmt/CVE-2019-1040" target="_blank" rel="noreferrer"&gt;wzxmt/CVE-2019-1040&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10475
 &lt;div id="cve-2019-10475" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10475" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vesche/CVE-2019-10475" target="_blank" rel="noreferrer"&gt;vesche/CVE-2019-10475&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1064
 &lt;div id="cve-2019-1064" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1064" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RythmStick/CVE-2019-1064" target="_blank" rel="noreferrer"&gt;RythmStick/CVE-2019-1064&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2019-1064" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2019-1064&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/attackgithub/CVE-2019-1064" target="_blank" rel="noreferrer"&gt;attackgithub/CVE-2019-1064&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10678
 &lt;div id="cve-2019-10678" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10678" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2019-10678" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2019-10678&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10685
 &lt;div id="cve-2019-10685" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10685" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2019-10685" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2019-10685&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1069
 &lt;div id="cve-2019-1069" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1069" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations, aka 'Task Scheduler Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/S3cur3Th1sSh1t/SharpPolarBear" target="_blank" rel="noreferrer"&gt;S3cur3Th1sSh1t/SharpPolarBear&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10708
 &lt;div id="cve-2019-10708" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10708" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/stavhaygn/CVE-2019-10708" target="_blank" rel="noreferrer"&gt;stavhaygn/CVE-2019-10708&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10758
 &lt;div id="cve-2019-10758" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10758" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/masahiro331/CVE-2019-10758" target="_blank" rel="noreferrer"&gt;masahiro331/CVE-2019-10758&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lp008/CVE-2019-10758" target="_blank" rel="noreferrer"&gt;lp008/CVE-2019-10758&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10869
 &lt;div id="cve-2019-10869" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10869" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KTN1990/CVE-2019-10869" target="_blank" rel="noreferrer"&gt;KTN1990/CVE-2019-10869&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10915
 &lt;div id="cve-2019-10915" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10915" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability has been identified in TIA Administrator (All versions &amp;lt; V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper authentication. The vulnerability could be exploited by an attacker with local access to the affected system. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality and integrity and availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/CVE-2019-10915" target="_blank" rel="noreferrer"&gt;jiansiting/CVE-2019-10915&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1096
 &lt;div id="cve-2019-1096" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1096" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/cve-2019-1096-poc" target="_blank" rel="noreferrer"&gt;ze0r/cve-2019-1096-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-10999
 &lt;div id="cve-2019-10999" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-10999" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fuzzywalls/CVE-2019-10999" target="_blank" rel="noreferrer"&gt;fuzzywalls/CVE-2019-10999&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11043
 &lt;div id="cve-2019-11043" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11043" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/neex/phuip-fpizdam" target="_blank" rel="noreferrer"&gt;neex/phuip-fpizdam&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/B1gd0g/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;B1gd0g/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tinker-li/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;tinker-li/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-" target="_blank" rel="noreferrer"&gt;AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fairyming/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;fairyming/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/akamajoris/CVE-2019-11043-Docker" target="_blank" rel="noreferrer"&gt;akamajoris/CVE-2019-11043-Docker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/theMiddleBlue/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;theMiddleBlue/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shadow-horse/cve-2019-11043" target="_blank" rel="noreferrer"&gt;shadow-horse/cve-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/huowen/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;huowen/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ypereirareis/docker-CVE-2019-11043" target="_blank" rel="noreferrer"&gt;ypereirareis/docker-CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MRdoulestar/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;MRdoulestar/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0th3rs-Security-Team/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;0th3rs-Security-Team/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/k8gege/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;k8gege/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/moniik/CVE-2019-11043_env" target="_blank" rel="noreferrer"&gt;moniik/CVE-2019-11043_env&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/scgs66/CVE-2019-11043" target="_blank" rel="noreferrer"&gt;scgs66/CVE-2019-11043&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11061
 &lt;div id="cve-2019-11061" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11061" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tim124058/ASUS-SmartHome-Exploit" target="_blank" rel="noreferrer"&gt;tim124058/ASUS-SmartHome-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11076
 &lt;div id="cve-2019-11076" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11076" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/livehybrid/poc-cribl-rce" target="_blank" rel="noreferrer"&gt;livehybrid/poc-cribl-rce&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1108
 &lt;div id="cve-2019-1108" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1108" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Lanph3re/cve-2019-1108" target="_blank" rel="noreferrer"&gt;Lanph3re/cve-2019-1108&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11157
 &lt;div id="cve-2019-11157" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11157" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zkenjar/v0ltpwn" target="_blank" rel="noreferrer"&gt;zkenjar/v0ltpwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11223
 &lt;div id="cve-2019-11223" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11223" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AngelCtulhu/CVE-2019-11223" target="_blank" rel="noreferrer"&gt;AngelCtulhu/CVE-2019-11223&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1125
 &lt;div id="cve-2019-1125" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1125" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bitdefender/swapgs-attack-poc" target="_blank" rel="noreferrer"&gt;bitdefender/swapgs-attack-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1132
 &lt;div id="cve-2019-1132" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1132" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Vlad-tri/CVE-2019-1132" target="_blank" rel="noreferrer"&gt;Vlad-tri/CVE-2019-1132&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/petercc/CVE-2019-1132" target="_blank" rel="noreferrer"&gt;petercc/CVE-2019-1132&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11358
 &lt;div id="cve-2019-11358" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11358" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bitnesswise/jquery-prototype-pollution-fix" target="_blank" rel="noreferrer"&gt;bitnesswise/jquery-prototype-pollution-fix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11477
 &lt;div id="cve-2019-11477" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11477" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Jonathan Looney discovered that the TCP_SKB_CB(skb)-&amp;gt;tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sasqwatch/cve-2019-11477-poc" target="_blank" rel="noreferrer"&gt;sasqwatch/cve-2019-11477-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11510
 &lt;div id="cve-2019-11510" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11510" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/projectzeroindia/CVE-2019-11510" target="_blank" rel="noreferrer"&gt;projectzeroindia/CVE-2019-11510&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ladyleet1337/Pulse" target="_blank" rel="noreferrer"&gt;ladyleet1337/Pulse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/imjdl/CVE-2019-11510-poc" target="_blank" rel="noreferrer"&gt;imjdl/CVE-2019-11510-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/es0/CVE-2019-11510_poc" target="_blank" rel="noreferrer"&gt;es0/CVE-2019-11510_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r00tpgp/http-pulse_ssl_vpn.nse" target="_blank" rel="noreferrer"&gt;r00tpgp/http-pulse_ssl_vpn.nse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-11510-1" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-11510-1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jason3e7/CVE-2019-11510" target="_blank" rel="noreferrer"&gt;jason3e7/CVE-2019-11510&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BishopFox/pwn-pulse" target="_blank" rel="noreferrer"&gt;BishopFox/pwn-pulse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aqhmal/pulsexploit" target="_blank" rel="noreferrer"&gt;aqhmal/pulsexploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cisagov/check-your-pulse" target="_blank" rel="noreferrer"&gt;cisagov/check-your-pulse&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11523
 &lt;div id="cve-2019-11523" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11523" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the &amp;quot;open door&amp;quot; command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wizlab-it/anviz-m3-rfid-cve-2019-11523-poc" target="_blank" rel="noreferrer"&gt;wizlab-it/anviz-m3-rfid-cve-2019-11523-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11539
 &lt;div id="cve-2019-11539" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11539" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xDezzy/CVE-2019-11539" target="_blank" rel="noreferrer"&gt;0xDezzy/CVE-2019-11539&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11580
 &lt;div id="cve-2019-11580" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11580" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-11580" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-11580&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shelld3v/CVE-2019-11580" target="_blank" rel="noreferrer"&gt;shelld3v/CVE-2019-11580&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11581
 &lt;div id="cve-2019-11581" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11581" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-11581" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-11581&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kobs0N/CVE-2019-11581" target="_blank" rel="noreferrer"&gt;kobs0N/CVE-2019-11581&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11687
 &lt;div id="cve-2019-11687" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11687" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b. The preamble of a DICOM file that complies with this specification can contain the header for an executable file, such as Portable Executable (PE) malware. This space is left unspecified so that dual-purpose files can be created. (For example, dual-purpose TIFF/DICOM files are used in digital whole slide imaging for applications in medicine.) To exploit this vulnerability, someone must execute a maliciously crafted file that is encoded in the DICOM Part 10 File Format. PE/DICOM files are executable even with the .dcm file extension. Anti-malware configurations at healthcare facilities often ignore medical imagery. Also, anti-malware tools and business processes could violate regulatory frameworks (such as HIPAA) when processing suspicious DICOM files.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kosmokato/bad-dicom" target="_blank" rel="noreferrer"&gt;kosmokato/bad-dicom&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11707
 &lt;div id="cve-2019-11707" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11707" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR &amp;lt; 60.7.1, Firefox &amp;lt; 67.0.3, and Thunderbird &amp;lt; 60.7.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vigneshsrao/CVE-2019-11707" target="_blank" rel="noreferrer"&gt;vigneshsrao/CVE-2019-11707&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tunnelshade/cve-2019-11707" target="_blank" rel="noreferrer"&gt;tunnelshade/cve-2019-11707&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11708
 &lt;div id="cve-2019-11708" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11708" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR &amp;lt; 60.7.2, Firefox &amp;lt; 67.0.4, and Thunderbird &amp;lt; 60.7.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0vercl0k/CVE-2019-11708" target="_blank" rel="noreferrer"&gt;0vercl0k/CVE-2019-11708&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11730
 &lt;div id="cve-2019-11730" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11730" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR &amp;lt; 60.8, Firefox &amp;lt; 68, and Thunderbird &amp;lt; 60.8.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alidnf/CVE-2019-11730" target="_blank" rel="noreferrer"&gt;alidnf/CVE-2019-11730&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1181
 &lt;div id="cve-2019-1181" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1181" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Remote Desktop Services â€“ formerly known as Terminal Services â€“ when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop ServicesÂ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1182, CVE-2019-1222, CVE-2019-1226.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/major203/cve-2019-1181" target="_blank" rel="noreferrer"&gt;major203/cve-2019-1181&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11881
 &lt;div id="cve-2019-11881" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11881" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability exists in Rancher 2.1.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a &amp;quot;This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading&amp;quot; message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MauroEldritch/VanCleef" target="_blank" rel="noreferrer"&gt;MauroEldritch/VanCleef&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11931
 &lt;div id="cve-2019-11931" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11931" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prior to 2.19.100, Enterprise Client versions prior to 2.25.3, Business for Android versions prior to 2.19.104 and Business for iOS versions prior to 2.19.100.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kasif-dekel/whatsapp-rce-patched" target="_blank" rel="noreferrer"&gt;kasif-dekel/whatsapp-rce-patched&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nop-team/CVE-2019-11931" target="_blank" rel="noreferrer"&gt;nop-team/CVE-2019-11931&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-11932
 &lt;div id="cve-2019-11932" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-11932" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dorkerdevil/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;dorkerdevil/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KeepWannabe/WhatsRCE" target="_blank" rel="noreferrer"&gt;KeepWannabe/WhatsRCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/awakened1712/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;awakened1712/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TulungagungCyberLink/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;TulungagungCyberLink/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/infiniteLoopers/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;infiniteLoopers/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/alexanderstonec/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;alexanderstonec/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/valbrux/CVE-2019-11932-SupportApp" target="_blank" rel="noreferrer"&gt;valbrux/CVE-2019-11932-SupportApp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fastmo/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;fastmo/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mRanonyMousTZ/CVE-2019-11932-whatsApp-exploit" target="_blank" rel="noreferrer"&gt;mRanonyMousTZ/CVE-2019-11932-whatsApp-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SmoZy92/CVE-2019-11932" target="_blank" rel="noreferrer"&gt;SmoZy92/CVE-2019-11932&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dashtic172/https-github.com-awakened171" target="_blank" rel="noreferrer"&gt;dashtic172/https-github.com-awakened171&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Err0r-ICA/WhatsPayloadRCE" target="_blank" rel="noreferrer"&gt;Err0r-ICA/WhatsPayloadRCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12086
 &lt;div id="cve-2019-12086" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12086" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/codeplutos/CVE-2019-12086-jackson-databind-file-read" target="_blank" rel="noreferrer"&gt;codeplutos/CVE-2019-12086-jackson-databind-file-read&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1215
 &lt;div id="cve-2019-1215" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1215" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bluefrostsecurity/CVE-2019-1215" target="_blank" rel="noreferrer"&gt;bluefrostsecurity/CVE-2019-1215&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12169
 &lt;div id="cve-2019-12169" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12169" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a &amp;quot;..&amp;quot; pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fuzzlove/ATutor-2.2.4-Language-Exploit" target="_blank" rel="noreferrer"&gt;fuzzlove/ATutor-2.2.4-Language-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12170
 &lt;div id="cve-2019-12170" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12170" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker can use the instructor account to fully compromise the system using a crafted backup ZIP archive. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fuzzlove/ATutor-Instructor-Backup-Arbitrary-File" target="_blank" rel="noreferrer"&gt;fuzzlove/ATutor-Instructor-Backup-Arbitrary-File&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1218
 &lt;div id="cve-2019-1218" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1218" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages, aka 'Outlook iOS Spoofing Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/d0gukank/CVE-2019-1218" target="_blank" rel="noreferrer"&gt;d0gukank/CVE-2019-1218&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12180
 &lt;div id="cve-2019-12180" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12180" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy &amp;quot;Load Script&amp;quot; is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious Project. The same issue is present in the &amp;quot;Save Script&amp;quot; function, which is executed automatically when saving a project.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x-nope/CVE-2019-12180" target="_blank" rel="noreferrer"&gt;0x-nope/CVE-2019-12180&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12181
 &lt;div id="cve-2019-12181" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12181" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guywhataguy/CVE-2019-12181" target="_blank" rel="noreferrer"&gt;guywhataguy/CVE-2019-12181&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12185
 &lt;div id="cve-2019-12185" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12185" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fuzzlove/eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE" target="_blank" rel="noreferrer"&gt;fuzzlove/eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12189
 &lt;div id="cve-2019-12189" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12189" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/falconz/CVE-2019-12189" target="_blank" rel="noreferrer"&gt;falconz/CVE-2019-12189&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tuyenhva/CVE-2019-12189" target="_blank" rel="noreferrer"&gt;tuyenhva/CVE-2019-12189&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12190
 &lt;div id="cve-2019-12190" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12190" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tuyenhva/CVE-2019-12190" target="_blank" rel="noreferrer"&gt;tuyenhva/CVE-2019-12190&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12252
 &lt;div id="cve-2019-12252" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12252" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&amp;amp;mode=E-Mail&amp;amp;notifyTo=SOLFORWARD&amp;amp;id= substring.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tuyenhva/CVE-2019-12252" target="_blank" rel="noreferrer"&gt;tuyenhva/CVE-2019-12252&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12255
 &lt;div id="cve-2019-12255" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12255" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sud0woodo/Urgent11-Suricata-LUA-scripts" target="_blank" rel="noreferrer"&gt;sud0woodo/Urgent11-Suricata-LUA-scripts&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12272
 &lt;div id="cve-2019-12272" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12272" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HACHp1/LuCI_RCE_exp" target="_blank" rel="noreferrer"&gt;HACHp1/LuCI_RCE_exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/roguedream/lede-17.01.3" target="_blank" rel="noreferrer"&gt;roguedream/lede-17.01.3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12314
 &lt;div id="cve-2019-12314" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12314" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ras313/CVE-2019-12314" target="_blank" rel="noreferrer"&gt;ras313/CVE-2019-12314&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12384
 &lt;div id="cve-2019-12384" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12384" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-12384" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-12384&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MagicZer0/Jackson_RCE-CVE-2019-12384" target="_blank" rel="noreferrer"&gt;MagicZer0/Jackson_RCE-CVE-2019-12384&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12409
 &lt;div id="cve-2019-12409" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12409" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-12409" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-12409&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12453
 &lt;div id="cve-2019-12453" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12453" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/undefinedmode/CVE-2019-12453" target="_blank" rel="noreferrer"&gt;undefinedmode/CVE-2019-12453&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12460
 &lt;div id="cve-2019-12460" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12460" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EmreOvunc/WebPort-v1.19.1-Reflected-XSS" target="_blank" rel="noreferrer"&gt;EmreOvunc/WebPort-v1.19.1-Reflected-XSS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12475
 &lt;div id="cve-2019-12475" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12475" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/undefinedmode/CVE-2019-12475" target="_blank" rel="noreferrer"&gt;undefinedmode/CVE-2019-12475&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12476
 &lt;div id="cve-2019-12476" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12476" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0katz/CVE-2019-12476" target="_blank" rel="noreferrer"&gt;0katz/CVE-2019-12476&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1253
 &lt;div id="cve-2019-1253" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1253" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rogue-kdc/CVE-2019-1253" target="_blank" rel="noreferrer"&gt;rogue-kdc/CVE-2019-1253&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2019-1253" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2019-1253&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/padovah4ck/CVE-2019-1253" target="_blank" rel="noreferrer"&gt;padovah4ck/CVE-2019-1253&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sgabe/CVE-2019-1253" target="_blank" rel="noreferrer"&gt;sgabe/CVE-2019-1253&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12538
 &lt;div id="cve-2019-12538" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12538" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-12538" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-12538&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12541
 &lt;div id="cve-2019-12541" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12541" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-12541" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-12541&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12542
 &lt;div id="cve-2019-12542" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12542" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-12542" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-12542&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12543
 &lt;div id="cve-2019-12543" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12543" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-12543" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-12543&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12562
 &lt;div id="cve-2019-12562" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12562" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MAYASEVEN/CVE-2019-12562" target="_blank" rel="noreferrer"&gt;MAYASEVEN/CVE-2019-12562&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12586
 &lt;div id="cve-2019-12586" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12586" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Matheus-Garbelini/esp32_esp8266_attacks" target="_blank" rel="noreferrer"&gt;Matheus-Garbelini/esp32_esp8266_attacks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12594
 &lt;div id="cve-2019-12594" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12594" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
DOSBox 0.74-2 has Incorrect Access Control.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Alexandre-Bartel/CVE-2019-12594" target="_blank" rel="noreferrer"&gt;Alexandre-Bartel/CVE-2019-12594&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12735
 &lt;div id="cve-2019-12735" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12735" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pcy190/ace-vim-neovim" target="_blank" rel="noreferrer"&gt;pcy190/ace-vim-neovim&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oldthree3/CVE-2019-12735-VIM-NEOVIM" target="_blank" rel="noreferrer"&gt;oldthree3/CVE-2019-12735-VIM-NEOVIM&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12750
 &lt;div id="cve-2019-12750" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12750" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Symantec Endpoint Protection, prior to 14.2 RU1 &amp;amp; 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/v-p-b/cve-2019-12750" target="_blank" rel="noreferrer"&gt;v-p-b/cve-2019-12750&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12796
 &lt;div id="cve-2019-12796" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12796" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/PeterUpfold/CVE-2019-12796" target="_blank" rel="noreferrer"&gt;PeterUpfold/CVE-2019-12796&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12815
 &lt;div id="cve-2019-12815" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12815" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KTN1990/CVE-2019-12815" target="_blank" rel="noreferrer"&gt;KTN1990/CVE-2019-12815&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12836
 &lt;div id="cve-2019-12836" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12836" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request that can be invoked in the context of an authenticated user, leading to stealing of session tokens and account takeover.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/9lyph/CVE-2019-12836" target="_blank" rel="noreferrer"&gt;9lyph/CVE-2019-12836&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12840
 &lt;div id="cve-2019-12840" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12840" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Webmin through 1.910, any user authorized to the &amp;quot;Package Updates&amp;quot; module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bkaraceylan/CVE-2019-12840_POC" target="_blank" rel="noreferrer"&gt;bkaraceylan/CVE-2019-12840_POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KrE80r/webmin_cve-2019-12840_poc" target="_blank" rel="noreferrer"&gt;KrE80r/webmin_cve-2019-12840_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12889
 &lt;div id="cve-2019-12889" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12889" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System. An attacker would need local access to the machine for a successful exploit. The attacker must disconnect the computer from the local network / WAN and connect it to an internet facing access point / network. At that point, the attacker can execute the password-reset functionality, which will expose a web browser. Browsing to a site that calls local Windows system functions (e.g., file upload) will expose the local file system. From there an attacker can launch a privileged command shell.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nulsect0r/CVE-2019-12889" target="_blank" rel="noreferrer"&gt;nulsect0r/CVE-2019-12889&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12890
 &lt;div id="cve-2019-12890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EthicalHackingCOP/CVE-2019-12890" target="_blank" rel="noreferrer"&gt;EthicalHackingCOP/CVE-2019-12890&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12949
 &lt;div id="cve-2019-12949" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12949" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-12949" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-12949&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-12999
 &lt;div id="cve-2019-12999" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-12999" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lightninglabs/chanleakcheck" target="_blank" rel="noreferrer"&gt;lightninglabs/chanleakcheck&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13000
 &lt;div id="cve-2019-13000" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13000" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states &amp;quot;it is beta-quality software and don't put too much money in it.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ACINQ/detection-tool-cve-2019-13000" target="_blank" rel="noreferrer"&gt;ACINQ/detection-tool-cve-2019-13000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13024
 &lt;div id="cve-2019-13024" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13024" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value &amp;quot;init_script&amp;quot;-&amp;quot;Monitoring Engine Binary&amp;quot; in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2019-13024" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2019-13024&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/get-get-get-get/Centreon-RCE" target="_blank" rel="noreferrer"&gt;get-get-get-get/Centreon-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13025
 &lt;div id="cve-2019-13025" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13025" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, which will be executed on the device, to an backend API endpoint of the cable modem.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/x1tan/CVE-2019-13025" target="_blank" rel="noreferrer"&gt;x1tan/CVE-2019-13025&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13027
 &lt;div id="cve-2019-13027" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13027" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IckoGZ/CVE-2019-13027" target="_blank" rel="noreferrer"&gt;IckoGZ/CVE-2019-13027&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13051
 &lt;div id="cve-2019-13051" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13051" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Pi-Hole 4.3 allows Command Injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pr0tean/CVE-2019-13051" target="_blank" rel="noreferrer"&gt;pr0tean/CVE-2019-13051&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13063
 &lt;div id="cve-2019-13063" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13063" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.e., being able to pull any file from the remote victim application). This can be used to steal and obtain sensitive config and other files. This can result in complete compromise of the application. The script parameter is vulnerable to directory traversal and both local and remote file inclusion.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x6b7966/CVE-2019-13063-POC" target="_blank" rel="noreferrer"&gt;0x6b7966/CVE-2019-13063-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13086
 &lt;div id="cve-2019-13086" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13086" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lingchuL/CVE_POC_test" target="_blank" rel="noreferrer"&gt;lingchuL/CVE_POC_test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13101
 &lt;div id="cve-2019-13101" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13101" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/halencarjunior/dlkploit600" target="_blank" rel="noreferrer"&gt;halencarjunior/dlkploit600&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13115
 &lt;div id="cve-2019-13115" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13115" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CSSProject/libssh2-Exploit" target="_blank" rel="noreferrer"&gt;CSSProject/libssh2-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13143
 &lt;div id="cve-2019-13143" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13143" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securelayer7/pwnfb50" target="_blank" rel="noreferrer"&gt;securelayer7/pwnfb50&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1315
 &lt;div id="cve-2019-1315" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1315" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Mayter/CVE-2019-1315" target="_blank" rel="noreferrer"&gt;Mayter/CVE-2019-1315&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13272
 &lt;div id="cve-2019-13272" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13272" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-13272" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cyc1eC/CVE-2019-13272" target="_blank" rel="noreferrer"&gt;Cyc1eC/CVE-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bigbigliang-malwarebenchmark/cve-2019-13272" target="_blank" rel="noreferrer"&gt;bigbigliang-malwarebenchmark/cve-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oneoy/CVE-2019-13272" target="_blank" rel="noreferrer"&gt;oneoy/CVE-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Huandtx/CVE-2019-13272" target="_blank" rel="noreferrer"&gt;Huandtx/CVE-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/polosec/CVE-2019-13272" target="_blank" rel="noreferrer"&gt;polosec/CVE-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sumedhaDharmasena/-Kernel-ptrace-c-mishandles-vulnerability-CVE-2019-13272" target="_blank" rel="noreferrer"&gt;sumedhaDharmasena/-Kernel-ptrace-c-mishandles-vulnerability-CVE-2019-13272&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13361
 &lt;div id="cve-2019-13361" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13361" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lodi-g/CVE-2019-13361" target="_blank" rel="noreferrer"&gt;lodi-g/CVE-2019-13361&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13403
 &lt;div id="cve-2019-13403" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13403" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/B3Bo1d/CVE-2019-13403" target="_blank" rel="noreferrer"&gt;B3Bo1d/CVE-2019-13403&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13404
 &lt;div id="cve-2019-13404" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13404" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alidnf/CVE-2019-13404" target="_blank" rel="noreferrer"&gt;alidnf/CVE-2019-13404&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13496
 &lt;div id="cve-2019-13496" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13496" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FurqanKhan1/CVE-2019-13496" target="_blank" rel="noreferrer"&gt;FurqanKhan1/CVE-2019-13496&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13497
 &lt;div id="cve-2019-13497" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13497" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FurqanKhan1/CVE-2019-13497" target="_blank" rel="noreferrer"&gt;FurqanKhan1/CVE-2019-13497&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13498
 &lt;div id="cve-2019-13498" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13498" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FurqanKhan1/CVE-2019-13498" target="_blank" rel="noreferrer"&gt;FurqanKhan1/CVE-2019-13498&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13504
 &lt;div id="cve-2019-13504" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13504" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hazedic/fuzzenv-exiv2" target="_blank" rel="noreferrer"&gt;hazedic/fuzzenv-exiv2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13574
 &lt;div id="cve-2019-13574" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13574" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/masahiro331/CVE-2019-13574" target="_blank" rel="noreferrer"&gt;masahiro331/CVE-2019-13574&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1367
 &lt;div id="cve-2019-1367" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1367" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mandarenmanman/CVE-2019-1367" target="_blank" rel="noreferrer"&gt;mandarenmanman/CVE-2019-1367&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13720
 &lt;div id="cve-2019-13720" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13720" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cve-2019-13720/cve-2019-13720" target="_blank" rel="noreferrer"&gt;cve-2019-13720/cve-2019-13720&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ChoKyuWon/CVE-2019-13720" target="_blank" rel="noreferrer"&gt;ChoKyuWon/CVE-2019-13720&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1385
 &lt;div id="cve-2019-1385" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1385" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/klinix5/CVE-2019-1385" target="_blank" rel="noreferrer"&gt;klinix5/CVE-2019-1385&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1388
 &lt;div id="cve-2019-1388" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1388" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-1388" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-1388&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jaychouzzk/CVE-2019-1388" target="_blank" rel="noreferrer"&gt;jaychouzzk/CVE-2019-1388&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sv3nbeast/CVE-2019-1388" target="_blank" rel="noreferrer"&gt;sv3nbeast/CVE-2019-1388&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-13956
 &lt;div id="cve-2019-13956" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-13956" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rhbb/CVE-2019-13956" target="_blank" rel="noreferrer"&gt;rhbb/CVE-2019-13956&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1402
 &lt;div id="cve-2019-1402" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1402" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lauxjpn/CorruptQueryAccessWorkaround" target="_blank" rel="noreferrer"&gt;lauxjpn/CorruptQueryAccessWorkaround&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14040
 &lt;div id="cve-2019-14040" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14040" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &amp;amp; Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SM8150, SXR1130
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tamirzb/CVE-2019-14040" target="_blank" rel="noreferrer"&gt;tamirzb/CVE-2019-14040&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14041
 &lt;div id="cve-2019-14041" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14041" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer with physical address information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &amp;amp; Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tamirzb/CVE-2019-14041" target="_blank" rel="noreferrer"&gt;tamirzb/CVE-2019-14041&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1405
 &lt;div id="cve-2019-1405" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1405" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/apt69/COMahawk" target="_blank" rel="noreferrer"&gt;apt69/COMahawk&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14079
 &lt;div id="cve-2019-14079" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14079" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped in the first place leading to kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MDM9607, MDM9640, MSM8909W, MSM8953, QCA6574AU, QCS605, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SM8150, SXR1130
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/parallelbeings/CVE-2019-14079" target="_blank" rel="noreferrer"&gt;parallelbeings/CVE-2019-14079&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14205
 &lt;div id="cve-2019-14205" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14205" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-kma/EXPLOITING-CVE-2019-14205" target="_blank" rel="noreferrer"&gt;security-kma/EXPLOITING-CVE-2019-14205&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1422
 &lt;div id="cve-2019-1422" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1422" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1423.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/cve-2019-1422" target="_blank" rel="noreferrer"&gt;ze0r/cve-2019-1422&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14220
 &lt;div id="cve-2019-14220" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14220" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/seqred-s-a/cve-2019-14220" target="_blank" rel="noreferrer"&gt;seqred-s-a/cve-2019-14220&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14267
 &lt;div id="cve-2019-14267" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14267" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/snappyJack/pdfresurrect_CVE-2019-14267" target="_blank" rel="noreferrer"&gt;snappyJack/pdfresurrect_CVE-2019-14267&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14287
 &lt;div id="cve-2019-14287" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14287" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a &amp;quot;sudo -u \#$((0xffffffff))&amp;quot; command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FauxFaux/sudo-cve-2019-14287" target="_blank" rel="noreferrer"&gt;FauxFaux/sudo-cve-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CashWilliams/CVE-2019-14287-demo" target="_blank" rel="noreferrer"&gt;CashWilliams/CVE-2019-14287-demo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/n0w4n/CVE-2019-14287" target="_blank" rel="noreferrer"&gt;n0w4n/CVE-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gurneesh/CVE-2019-14287-write-up" target="_blank" rel="noreferrer"&gt;gurneesh/CVE-2019-14287-write-up&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shellvhack/Sudo-Security-Bypass-CVE-2019-14287" target="_blank" rel="noreferrer"&gt;shellvhack/Sudo-Security-Bypass-CVE-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Janette88/cve-2019-14287sudoexp" target="_blank" rel="noreferrer"&gt;Janette88/cve-2019-14287sudoexp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/huang919/cve-2019-14287-PPT" target="_blank" rel="noreferrer"&gt;huang919/cve-2019-14287-PPT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wenyu1999/sudo-" target="_blank" rel="noreferrer"&gt;wenyu1999/sudo-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sindadziy/cve-2019-14287" target="_blank" rel="noreferrer"&gt;Sindadziy/cve-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;Sindayifu/CVE-2019-14287-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Unam3dd/sudo-vulnerability-CVE-2019-14287" target="_blank" rel="noreferrer"&gt;Unam3dd/sudo-vulnerability-CVE-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CMNatic/Dockerized-CVE-2019-14287" target="_blank" rel="noreferrer"&gt;CMNatic/Dockerized-CVE-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14314
 &lt;div id="cve-2019-14314" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14314" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/imthoe/CVE-2019-14314" target="_blank" rel="noreferrer"&gt;imthoe/CVE-2019-14314&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14319
 &lt;div id="cve-2019-14319" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14319" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network traffic.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MelroyB/CVE-2019-14319" target="_blank" rel="noreferrer"&gt;MelroyB/CVE-2019-14319&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14326
 &lt;div id="cve-2019-14326" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14326" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the emulated Android system. This can be exploited by remote attackers to gain full access to the device, or by malicious apps installed inside the emulator to perform privilege escalation from a normal user to root (unlike with standard methods of getting root privileges on Android - e.g., the SuperSu program - the user is not asked for consent). There is no authentication performed - access to a root shell is given upon a successful connection. NOTE: although this was originally published with a slightly different CVE ID number, the correct ID for this Andy vulnerability has always been CVE-2019-14326.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/seqred-s-a/cve-2019-14326" target="_blank" rel="noreferrer"&gt;seqred-s-a/cve-2019-14326&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14339
 &lt;div id="cve-2019-14339" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14339" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x48piraj/CVE-2019-14339" target="_blank" rel="noreferrer"&gt;0x48piraj/CVE-2019-14339&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14439
 &lt;div id="cve-2019-14439" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14439" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-14439" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-14439&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14514
 &lt;div id="cve-2019-14514" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14514" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init program, and is a closed-source proprietary tool that seems to be developed by Microvirt). This program opens TCP port 21509, presumably to receive installation-related commands from the host OS. Because everything after the installer:uninstall command is concatenated directly into a system() call, it is possible to execute arbitrary commands by supplying shell metacharacters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/seqred-s-a/cve-2019-14514" target="_blank" rel="noreferrer"&gt;seqred-s-a/cve-2019-14514&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14529
 &lt;div id="cve-2019-14529" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14529" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Wezery/CVE-2019-14529" target="_blank" rel="noreferrer"&gt;Wezery/CVE-2019-14529&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14530
 &lt;div id="cve-2019-14530" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14530" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Wezery/CVE-2019-14530" target="_blank" rel="noreferrer"&gt;Wezery/CVE-2019-14530&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14537
 &lt;div id="cve-2019-14537" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14537" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Wocanilo/CVE-2019-14537" target="_blank" rel="noreferrer"&gt;Wocanilo/CVE-2019-14537&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14540
 &lt;div id="cve-2019-14540" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14540" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/LeadroyaL/cve-2019-14540-exploit" target="_blank" rel="noreferrer"&gt;LeadroyaL/cve-2019-14540-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1458
 &lt;div id="cve-2019-1458" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1458" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/piotrflorczyk/cve-2019-1458_POC" target="_blank" rel="noreferrer"&gt;piotrflorczyk/cve-2019-1458_POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/unamer/CVE-2019-1458" target="_blank" rel="noreferrer"&gt;unamer/CVE-2019-1458&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14615
 &lt;div id="cve-2019-14615" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14615" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HE-Wenjian/iGPU-Leak" target="_blank" rel="noreferrer"&gt;HE-Wenjian/iGPU-Leak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14745
 &lt;div id="cve-2019-14745" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14745" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xooxo/CVE-2019-14745" target="_blank" rel="noreferrer"&gt;xooxo/CVE-2019-14745&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14751
 &lt;div id="cve-2019-14751" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14751" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mssalvatore/CVE-2019-14751_PoC" target="_blank" rel="noreferrer"&gt;mssalvatore/CVE-2019-14751_PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1476
 &lt;div id="cve-2019-1476" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1476" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sgabe/CVE-2019-1476" target="_blank" rel="noreferrer"&gt;sgabe/CVE-2019-1476&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14830
 &lt;div id="cve-2019-14830" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14830" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Fr3d-/moodle-token-stealer" target="_blank" rel="noreferrer"&gt;Fr3d-/moodle-token-stealer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-14912
 &lt;div id="cve-2019-14912" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-14912" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Wocanilo/adaPwn" target="_blank" rel="noreferrer"&gt;Wocanilo/adaPwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15029
 &lt;div id="cve-2019-15029" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15029" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request with the service id followed by the parameter a=start to execute the stored command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2019-15029" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2019-15029&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15053
 &lt;div id="cve-2019-15053" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15053" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The &amp;quot;HTML Include and replace macro&amp;quot; plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/l0nax/CVE-2019-15053" target="_blank" rel="noreferrer"&gt;l0nax/CVE-2019-15053&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15107
 &lt;div id="cve-2019-15107" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15107" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Webmin &amp;lt;=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-15107" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-15107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HACHp1/webmin_docker_and_exp" target="_blank" rel="noreferrer"&gt;HACHp1/webmin_docker_and_exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ketlerd/CVE-2019-15107" target="_blank" rel="noreferrer"&gt;ketlerd/CVE-2019-15107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AdministratorGithub/CVE-2019-15107" target="_blank" rel="noreferrer"&gt;AdministratorGithub/CVE-2019-15107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Pichuuuuu/CVE-2019-15107" target="_blank" rel="noreferrer"&gt;Pichuuuuu/CVE-2019-15107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Rayferrufino/Make-and-Break" target="_blank" rel="noreferrer"&gt;Rayferrufino/Make-and-Break&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AleWong/WebminRCE-EXP-CVE-2019-15107-" target="_blank" rel="noreferrer"&gt;AleWong/WebminRCE-EXP-CVE-2019-15107-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-15107" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-15107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hannob/webminex" target="_blank" rel="noreferrer"&gt;hannob/webminex&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ChakoMoonFish/webmin_CVE-2019-15107" target="_blank" rel="noreferrer"&gt;ChakoMoonFish/webmin_CVE-2019-15107&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15120
 &lt;div id="cve-2019-15120" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15120" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/h3llraiser/CVE-2019-15120" target="_blank" rel="noreferrer"&gt;h3llraiser/CVE-2019-15120&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15126
 &lt;div id="cve-2019-15126" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15126" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x13enny/kr00k" target="_blank" rel="noreferrer"&gt;0x13enny/kr00k&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hexway/r00kie-kr00kie" target="_blank" rel="noreferrer"&gt;hexway/r00kie-kr00kie&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/akabe1/kr00ker" target="_blank" rel="noreferrer"&gt;akabe1/kr00ker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mustafasevim/kr00k-vulnerability" target="_blank" rel="noreferrer"&gt;mustafasevim/kr00k-vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15224
 &lt;div id="cve-2019-15224" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15224" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions &amp;lt;=1.6.9 and &amp;gt;=1.6.14 are unaffected.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chef-cft/inspec_cve_2019_15224" target="_blank" rel="noreferrer"&gt;chef-cft/inspec_cve_2019_15224&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15233
 &lt;div id="cve-2019-15233" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15233" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/l0nax/CVE-2019-15233" target="_blank" rel="noreferrer"&gt;l0nax/CVE-2019-15233&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15511
 &lt;div id="cve-2019-15511" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15511" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/adenkiewicz/CVE-2019-15511" target="_blank" rel="noreferrer"&gt;adenkiewicz/CVE-2019-15511&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15642
 &lt;div id="cve-2019-15642" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15642" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states &amp;quot;RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-15642" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-15642&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1579
 &lt;div id="cve-2019-1579" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1579" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2019-1579" target="_blank" rel="noreferrer"&gt;securifera/CVE-2019-1579&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15802
 &lt;div id="cve-2019-15802" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15802" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) are used to encrypt and decrypt all passwords using AES256 in CBC mode. With the parameters known, all previously encrypted passwords can be decrypted. This includes the passwords that are part of configuration backups or otherwise embedded as part of the firmware.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jasperla/CVE-2019-15802" target="_blank" rel="noreferrer"&gt;jasperla/CVE-2019-15802&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15846
 &lt;div id="cve-2019-15846" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15846" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/synacktiv/Exim-CVE-2019-15846" target="_blank" rel="noreferrer"&gt;synacktiv/Exim-CVE-2019-15846&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15858
 &lt;div id="cve-2019-15858" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15858" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
admin/includes/class.import.snippet.php in the &amp;quot;Woody ad snippets&amp;quot; plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GeneralEG/CVE-2019-15858" target="_blank" rel="noreferrer"&gt;GeneralEG/CVE-2019-15858&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-15972
 &lt;div id="cve-2019-15972" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-15972" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FSecureLABS/Cisco-UCM-SQLi-Scripts" target="_blank" rel="noreferrer"&gt;FSecureLABS/Cisco-UCM-SQLi-Scripts&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16097
 &lt;div id="cve-2019-16097" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16097" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/evilAdan0s/CVE-2019-16097" target="_blank" rel="noreferrer"&gt;evilAdan0s/CVE-2019-16097&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rockmelodies/CVE-2019-16097-batch" target="_blank" rel="noreferrer"&gt;rockmelodies/CVE-2019-16097-batch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-16097" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-16097&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dacade/cve-2019-16097" target="_blank" rel="noreferrer"&gt;dacade/cve-2019-16097&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/theLSA/harbor-give-me-admin" target="_blank" rel="noreferrer"&gt;theLSA/harbor-give-me-admin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/luckybool1020/CVE-2019-16097" target="_blank" rel="noreferrer"&gt;luckybool1020/CVE-2019-16097&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16098
 &lt;div id="cve-2019-16098" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16098" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Barakat/CVE-2019-16098" target="_blank" rel="noreferrer"&gt;Barakat/CVE-2019-16098&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16278
 &lt;div id="cve-2019-16278" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16278" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-16278" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-16278&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/imjdl/CVE-2019-16278-PoC" target="_blank" rel="noreferrer"&gt;imjdl/CVE-2019-16278-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-16278" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-16278&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/darkerego/Nostromo_Python3" target="_blank" rel="noreferrer"&gt;darkerego/Nostromo_Python3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AnubisSec/CVE-2019-16278" target="_blank" rel="noreferrer"&gt;AnubisSec/CVE-2019-16278&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rptucker/CVE-2019-16278-Nostromo_1.9.6-RCE" target="_blank" rel="noreferrer"&gt;rptucker/CVE-2019-16278-Nostromo_1.9.6-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Kr0ff/cve-2019-16278" target="_blank" rel="noreferrer"&gt;Kr0ff/cve-2019-16278&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NHPT/CVE-2019-16278" target="_blank" rel="noreferrer"&gt;NHPT/CVE-2019-16278&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Unam3dd/nostromo_1_9_6_rce" target="_blank" rel="noreferrer"&gt;Unam3dd/nostromo_1_9_6_rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/keshiba/cve-2019-16278" target="_blank" rel="noreferrer"&gt;keshiba/cve-2019-16278&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16279
 &lt;div id="cve-2019-16279" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16279" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-16279" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-16279&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16394
 &lt;div id="cve-2019-16394" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16394" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SilentVoid13/Silent_CVE_2019_16394" target="_blank" rel="noreferrer"&gt;SilentVoid13/Silent_CVE_2019_16394&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16405
 &lt;div id="cve-2019-16405" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16405" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheCyberGeek/CVE-2019-16405.rb" target="_blank" rel="noreferrer"&gt;TheCyberGeek/CVE-2019-16405.rb&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1652
 &lt;div id="cve-2019-1652" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1652" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x27/CiscoRV320Dump" target="_blank" rel="noreferrer"&gt;0x27/CiscoRV320Dump&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1653
 &lt;div id="cve-2019-1653" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1653" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dubfr33/CVE-2019-1653" target="_blank" rel="noreferrer"&gt;dubfr33/CVE-2019-1653&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shaheemirza/CiscoSpill" target="_blank" rel="noreferrer"&gt;shaheemirza/CiscoSpill&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16662
 &lt;div id="cve-2019-16662" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16662" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2019-16662" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2019-16662&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16663
 &lt;div id="cve-2019-16663" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16663" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2019-16663" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2019-16663&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16692
 &lt;div id="cve-2019-16692" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16692" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kkirsche/CVE-2019-16692" target="_blank" rel="noreferrer"&gt;kkirsche/CVE-2019-16692&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16724
 &lt;div id="cve-2019-16724" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16724" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FULLSHADE/OSCE" target="_blank" rel="noreferrer"&gt;FULLSHADE/OSCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16759
 &lt;div id="cve-2019-16759" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16759" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Frint0/mass-pwn-vbulletin" target="_blank" rel="noreferrer"&gt;Frint0/mass-pwn-vbulletin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/M0sterHxck/CVE-2019-16759-Vbulletin-rce-exploit" target="_blank" rel="noreferrer"&gt;M0sterHxck/CVE-2019-16759-Vbulletin-rce-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r00tpgp/http-vuln-CVE-2019-16759" target="_blank" rel="noreferrer"&gt;r00tpgp/http-vuln-CVE-2019-16759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-16759" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-16759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FarjaalAhmad/CVE-2019-16759" target="_blank" rel="noreferrer"&gt;FarjaalAhmad/CVE-2019-16759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andripwn/pwn-vbulletin" target="_blank" rel="noreferrer"&gt;andripwn/pwn-vbulletin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/psychoxploit/vbull" target="_blank" rel="noreferrer"&gt;psychoxploit/vbull&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16784
 &lt;div id="cve-2019-16784" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16784" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in &amp;quot;onefile&amp;quot; mode is launched by a privileged user (at least more than the current one) which have his &amp;quot;TempPath&amp;quot; resolving to a world writable directory. This is the case for example if the software is launched as a service or as a scheduled task using a system account (TempPath will be C:\Windows\Temp). In order to be exploitable the software has to be (re)started after the attacker launch the exploit program, so for a service launched at startup, a service restart is needed (e.g. after a crash or an upgrade).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AlterSolutions/PyInstallerPrivEsc" target="_blank" rel="noreferrer"&gt;AlterSolutions/PyInstallerPrivEsc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16889
 &lt;div id="cve-2019-16889" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16889" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/grampae/meep" target="_blank" rel="noreferrer"&gt;grampae/meep&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16920
 &lt;div id="cve-2019-16920" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16920" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a &amp;quot;PingTest&amp;quot; device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pwnhacker0x18/CVE-2019-16920-MassPwn3r" target="_blank" rel="noreferrer"&gt;pwnhacker0x18/CVE-2019-16920-MassPwn3r&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-16941
 &lt;div id="cve-2019-16941" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-16941" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/purpleracc00n/CVE-2019-16941" target="_blank" rel="noreferrer"&gt;purpleracc00n/CVE-2019-16941&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17080
 &lt;div id="cve-2019-17080" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17080" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Andhrimnirr/Mintinstall-object-injection" target="_blank" rel="noreferrer"&gt;Andhrimnirr/Mintinstall-object-injection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17124
 &lt;div id="cve-2019-17124" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17124" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hessandrew/CVE-2019-17124" target="_blank" rel="noreferrer"&gt;hessandrew/CVE-2019-17124&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17221
 &lt;div id="cve-2019-17221" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17221" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/h4ckologic/CVE-2019-17221" target="_blank" rel="noreferrer"&gt;h4ckologic/CVE-2019-17221&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17234
 &lt;div id="cve-2019-17234" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17234" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/administra1tor/CVE-2019-17234-Wordpress-DirStroyer" target="_blank" rel="noreferrer"&gt;administra1tor/CVE-2019-17234-Wordpress-DirStroyer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17424
 &lt;div id="cve-2019-17424" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17424" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guywhataguy/CVE-2019-17424" target="_blank" rel="noreferrer"&gt;guywhataguy/CVE-2019-17424&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17427
 &lt;div id="cve-2019-17427" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17427" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealLinkers/CVE-2019-17427" target="_blank" rel="noreferrer"&gt;RealLinkers/CVE-2019-17427&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17495
 &lt;div id="cve-2019-17495" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17495" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that &amp;lt;style&amp;gt;@import within the JSON data was a functional attack method.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SecT0uch/CVE-2019-17495-test" target="_blank" rel="noreferrer"&gt;SecT0uch/CVE-2019-17495-test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17525
 &lt;div id="cve-2019-17525" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17525" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/huzaifahussain98/CVE-2019-17525" target="_blank" rel="noreferrer"&gt;huzaifahussain98/CVE-2019-17525&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17558
 &lt;div id="cve-2019-17558" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17558" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SDNDTeam/CVE-2019-17558_Solr_Vul_Tool" target="_blank" rel="noreferrer"&gt;SDNDTeam/CVE-2019-17558_Solr_Vul_Tool&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17564
 &lt;div id="cve-2019-17564" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17564" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/r00t4dm/CVE-2019-17564" target="_blank" rel="noreferrer"&gt;r00t4dm/CVE-2019-17564&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jaky5155/CVE-2019-17564" target="_blank" rel="noreferrer"&gt;Jaky5155/CVE-2019-17564&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Hu3sky/CVE-2019-17564" target="_blank" rel="noreferrer"&gt;Hu3sky/CVE-2019-17564&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Exploit-3389/CVE-2019-17564" target="_blank" rel="noreferrer"&gt;Exploit-3389/CVE-2019-17564&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Dor-Tumarkin/CVE-2019-17564-FastJson-Gadget" target="_blank" rel="noreferrer"&gt;Dor-Tumarkin/CVE-2019-17564-FastJson-Gadget&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fairyming/CVE-2019-17564" target="_blank" rel="noreferrer"&gt;fairyming/CVE-2019-17564&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17570
 &lt;div id="cve-2019-17570" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17570" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/r00t4dm/CVE-2019-17570" target="_blank" rel="noreferrer"&gt;r00t4dm/CVE-2019-17570&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/orangecertcc/xmlrpc-common-deserialization" target="_blank" rel="noreferrer"&gt;orangecertcc/xmlrpc-common-deserialization&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17571
 &lt;div id="cve-2019-17571" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17571" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shadow-horse/CVE-2019-17571" target="_blank" rel="noreferrer"&gt;shadow-horse/CVE-2019-17571&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17596
 &lt;div id="cve-2019-17596" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17596" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pquerna/poc-dsa-verify-CVE-2019-17596" target="_blank" rel="noreferrer"&gt;pquerna/poc-dsa-verify-CVE-2019-17596&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17625
 &lt;div id="cve-2019-17625" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17625" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ekultek/CVE-2019-17625" target="_blank" rel="noreferrer"&gt;Ekultek/CVE-2019-17625&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17633
 &lt;div id="cve-2019-17633" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17633" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mgrube/CVE-2019-17633" target="_blank" rel="noreferrer"&gt;mgrube/CVE-2019-17633&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17658
 &lt;div id="cve-2019-17658" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17658" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ibonok/CVE-2019-17658" target="_blank" rel="noreferrer"&gt;Ibonok/CVE-2019-17658&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-17671
 &lt;div id="cve-2019-17671" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-17671" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rhbb/CVE-2019-17671" target="_blank" rel="noreferrer"&gt;rhbb/CVE-2019-17671&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1821
 &lt;div id="cve-2019-1821" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1821" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/k8gege/CiscoExploit" target="_blank" rel="noreferrer"&gt;k8gege/CiscoExploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18371
 &lt;div id="cve-2019-18371" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18371" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC" target="_blank" rel="noreferrer"&gt;UltramanGaia/Xiaomi_Mi_WiFi_R3G_Vulnerability_POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18418
 &lt;div id="cve-2019-18418" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18418" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Andhrimnirr/ClonOS-WEB-control-panel-multi-vulnerability" target="_blank" rel="noreferrer"&gt;Andhrimnirr/ClonOS-WEB-control-panel-multi-vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18426
 &lt;div id="cve-2019-18426" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18426" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/PerimeterX/CVE-2019-18426" target="_blank" rel="noreferrer"&gt;PerimeterX/CVE-2019-18426&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18634
 &lt;div id="cve-2019-18634" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18634" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Plazmaz/CVE-2019-18634" target="_blank" rel="noreferrer"&gt;Plazmaz/CVE-2019-18634&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/saleemrashid/sudo-cve-2019-18634" target="_blank" rel="noreferrer"&gt;saleemrashid/sudo-cve-2019-18634&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/N1et/CVE-2019-18634" target="_blank" rel="noreferrer"&gt;N1et/CVE-2019-18634&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jeandelboux/CVE-2019-18634" target="_blank" rel="noreferrer"&gt;jeandelboux/CVE-2019-18634&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18873
 &lt;div id="cve-2019-18873" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18873" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under &amp;quot;User Manager&amp;quot; in the control panel, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server. The problem is in admsession.php and admuser.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fuzzlove/FUDforum-XSS-RCE" target="_blank" rel="noreferrer"&gt;fuzzlove/FUDforum-XSS-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18885
 &lt;div id="cve-2019-18885" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18885" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a crafted btrfs image because fs_devices-&amp;gt;devices is mishandled within find_device, aka CID-09ba3bc9dd15.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bobfuzzer/CVE-2019-18885" target="_blank" rel="noreferrer"&gt;bobfuzzer/CVE-2019-18885&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18890
 &lt;div id="cve-2019-18890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealLinkers/CVE-2019-18890" target="_blank" rel="noreferrer"&gt;RealLinkers/CVE-2019-18890&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-18935
 &lt;div id="cve-2019-18935" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-18935" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bao7uo/RAU_crypto" target="_blank" rel="noreferrer"&gt;bao7uo/RAU_crypto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/noperator/CVE-2019-18935" target="_blank" rel="noreferrer"&gt;noperator/CVE-2019-18935&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19012
 &lt;div id="cve-2019-19012" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19012" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ManhNDd/CVE-2019-19012" target="_blank" rel="noreferrer"&gt;ManhNDd/CVE-2019-19012&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-19012" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-19012&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19033
 &lt;div id="cve-2019-19033" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19033" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ricardojoserf/CVE-2019-19033" target="_blank" rel="noreferrer"&gt;ricardojoserf/CVE-2019-19033&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19203
 &lt;div id="cve-2019-19203" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19203" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ManhNDd/CVE-2019-19203" target="_blank" rel="noreferrer"&gt;ManhNDd/CVE-2019-19203&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-19203" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-19203&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19204
 &lt;div id="cve-2019-19204" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19204" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ManhNDd/CVE-2019-19204" target="_blank" rel="noreferrer"&gt;ManhNDd/CVE-2019-19204&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tarantula-team/CVE-2019-19204" target="_blank" rel="noreferrer"&gt;tarantula-team/CVE-2019-19204&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19231
 &lt;div id="cve-2019-19231" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19231" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hessandrew/CVE-2019-19231" target="_blank" rel="noreferrer"&gt;hessandrew/CVE-2019-19231&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19268
 &lt;div id="cve-2019-19268" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19268" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheCyberGeek/CVE-2019-19268" target="_blank" rel="noreferrer"&gt;TheCyberGeek/CVE-2019-19268&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19315
 &lt;div id="cve-2019-19315" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19315" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \\.\mailslot\nlsX86ccMailslot mailslot.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/monoxgas/mailorder" target="_blank" rel="noreferrer"&gt;monoxgas/mailorder&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19356
 &lt;div id="cve-2019-19356" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19356" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shadowgatt/CVE-2019-19356" target="_blank" rel="noreferrer"&gt;shadowgatt/CVE-2019-19356&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qq1515406085/CVE-2019-19356" target="_blank" rel="noreferrer"&gt;qq1515406085/CVE-2019-19356&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19369
 &lt;div id="cve-2019-19369" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19369" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheCyberGeek/CVE-2019-19369" target="_blank" rel="noreferrer"&gt;TheCyberGeek/CVE-2019-19369&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19383
 &lt;div id="cve-2019-19383" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19383" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/m0rph-1/CVE-2019-19383" target="_blank" rel="noreferrer"&gt;m0rph-1/CVE-2019-19383&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19511
 &lt;div id="cve-2019-19511" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19511" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19511" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19511&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19550
 &lt;div id="cve-2019-19550" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19550" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/underprotection/CVE-2019-19550" target="_blank" rel="noreferrer"&gt;underprotection/CVE-2019-19550&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19576
 &lt;div id="cve-2019-19576" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19576" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19576" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19576&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19633
 &lt;div id="cve-2019-19633" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19633" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19633" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19633&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19634
 &lt;div id="cve-2019-19634" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19634" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19634" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19634&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19651
 &lt;div id="cve-2019-19651" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19651" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19651" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19651&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19652
 &lt;div id="cve-2019-19652" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19652" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19652" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19652&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19653
 &lt;div id="cve-2019-19653" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19653" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19653" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19653&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19654
 &lt;div id="cve-2019-19654" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19654" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19654" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19654&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19658
 &lt;div id="cve-2019-19658" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19658" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19658" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19658&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19699
 &lt;div id="cve-2019-19699" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19699" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&amp;amp;type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&amp;amp;o=c&amp;amp;server_id=1 URI. This is triggered via an export of the Poller Configuration.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SpengeSec/CVE-2019-19699" target="_blank" rel="noreferrer"&gt;SpengeSec/CVE-2019-19699&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19732
 &lt;div id="cve-2019-19732" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19732" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19732" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19732&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19733
 &lt;div id="cve-2019-19733" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19733" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the fileIds parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19733" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19733&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19734
 &lt;div id="cve-2019-19734" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19734" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19734" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19734&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19735
 &lt;div id="cve-2019-19735" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19735" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19735" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19735&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19738
 &lt;div id="cve-2019-19738" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19738" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-19738" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-19738&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19781
 &lt;div id="cve-2019-19781" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19781" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mekoko/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;mekoko/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/projectzeroindia/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;projectzeroindia/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/trustedsec/cve-2019-19781" target="_blank" rel="noreferrer"&gt;trustedsec/cve-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cisagov/check-cve-2019-19781" target="_blank" rel="noreferrer"&gt;cisagov/check-cve-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oways/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;oways/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/becrevex/Citrix_CVE-2019-19781" target="_blank" rel="noreferrer"&gt;becrevex/Citrix_CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/unknowndevice64/Exploits_CVE-2019-19781" target="_blank" rel="noreferrer"&gt;unknowndevice64/Exploits_CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bufsnake/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;bufsnake/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x1sec/citrixmash_scanner" target="_blank" rel="noreferrer"&gt;x1sec/citrixmash_scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jabo-SCO/Shitrix-CVE-2019-19781" target="_blank" rel="noreferrer"&gt;Jabo-SCO/Shitrix-CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x1sec/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;x1sec/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hollerith/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;hollerith/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aqhmal/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;aqhmal/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MalwareTech/CitrixHoneypot" target="_blank" rel="noreferrer"&gt;MalwareTech/CitrixHoneypot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mekhalleh/citrix_dir_traversal_rce" target="_blank" rel="noreferrer"&gt;mekhalleh/citrix_dir_traversal_rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zenturacp/cve-2019-19781-web" target="_blank" rel="noreferrer"&gt;zenturacp/cve-2019-19781-web&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zgelici/CVE-2019-19781-Checker" target="_blank" rel="noreferrer"&gt;zgelici/CVE-2019-19781-Checker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/digitalshadows/CVE-2019-19781_IOCs" target="_blank" rel="noreferrer"&gt;digitalshadows/CVE-2019-19781_IOCs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/onSec-fr/CVE-2019-19781-Forensic" target="_blank" rel="noreferrer"&gt;onSec-fr/CVE-2019-19781-Forensic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DanielWep/CVE-NetScalerFileSystemCheck" target="_blank" rel="noreferrer"&gt;DanielWep/CVE-NetScalerFileSystemCheck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Castaldio86/Detect-CVE-2019-19781" target="_blank" rel="noreferrer"&gt;Castaldio86/Detect-CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/j81blog/ADC-19781" target="_blank" rel="noreferrer"&gt;j81blog/ADC-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/clm123321/Citrix_CVE-2019-19781" target="_blank" rel="noreferrer"&gt;clm123321/Citrix_CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b510/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;b510/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/redscan/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;redscan/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DIVD-NL/Citrix-CVE-2019-19781" target="_blank" rel="noreferrer"&gt;DIVD-NL/Citrix-CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ynsmroztas/citrix.sh" target="_blank" rel="noreferrer"&gt;ynsmroztas/citrix.sh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/digitalgangst/massCitrix" target="_blank" rel="noreferrer"&gt;digitalgangst/massCitrix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fireeye/ioc-scanner-CVE-2019-19781" target="_blank" rel="noreferrer"&gt;fireeye/ioc-scanner-CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/citrix/ioc-scanner-CVE-2019-19781" target="_blank" rel="noreferrer"&gt;citrix/ioc-scanner-CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x1sec/citrix-honeypot" target="_blank" rel="noreferrer"&gt;x1sec/citrix-honeypot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/L4r1k/CitrixNetscalerAnalysis" target="_blank" rel="noreferrer"&gt;L4r1k/CitrixNetscalerAnalysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Azeemering/CVE-2019-19781-DFIR-Notes" target="_blank" rel="noreferrer"&gt;Azeemering/CVE-2019-19781-DFIR-Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xams/citrixvulncheck" target="_blank" rel="noreferrer"&gt;0xams/citrixvulncheck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RaulCalvoLaorden/CVE-2019-19781" target="_blank" rel="noreferrer"&gt;RaulCalvoLaorden/CVE-2019-19781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nmanzi/webcvescanner" target="_blank" rel="noreferrer"&gt;nmanzi/webcvescanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/darren646/CVE-2019-19781POC" target="_blank" rel="noreferrer"&gt;darren646/CVE-2019-19781POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19844
 &lt;div id="cve-2019-19844" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19844" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ryu22e/django_cve_2019_19844_poc" target="_blank" rel="noreferrer"&gt;ryu22e/django_cve_2019_19844_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andripwn/django_cve201919844" target="_blank" rel="noreferrer"&gt;andripwn/django_cve201919844&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xsha/CVE_2019_19844" target="_blank" rel="noreferrer"&gt;0xsha/CVE_2019_19844&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-1987
 &lt;div id="cve-2019-1987" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-1987" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-118143775.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/android-7-9-png-bug" target="_blank" rel="noreferrer"&gt;marcinguy/android-7-9-png-bug&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19871
 &lt;div id="cve-2019-19871" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19871" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/VDISEC/CVE-2019-19871-AuditGuide" target="_blank" rel="noreferrer"&gt;VDISEC/CVE-2019-19871-AuditGuide&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19905
 &lt;div id="cve-2019-19905" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19905" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dpmdpm2/CVE-2019-19905" target="_blank" rel="noreferrer"&gt;dpmdpm2/CVE-2019-19905&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-19943
 &lt;div id="cve-2019-19943" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-19943" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/m0rph-1/CVE-2019-19943" target="_blank" rel="noreferrer"&gt;m0rph-1/CVE-2019-19943&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-20059
 &lt;div id="cve-2019-20059" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-20059" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jra89/CVE-2019-20059" target="_blank" rel="noreferrer"&gt;jra89/CVE-2019-20059&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-20085
 &lt;div id="cve-2019-20085" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-20085" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
TVT NVMS-1000 devices allow GET /.. Directory Traversal
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AleDiBen/NVMS1000-Exploit" target="_blank" rel="noreferrer"&gt;AleDiBen/NVMS1000-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-20197
 &lt;div id="cve-2019-20197" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-20197" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lp008/CVE-2019-20197" target="_blank" rel="noreferrer"&gt;lp008/CVE-2019-20197&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-20197" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-20197&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-20224
 &lt;div id="cve-2019-20224" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-20224" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2019-20224" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2019-20224&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-20326
 &lt;div id="cve-2019-20326" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-20326" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Fysac/CVE-2019-20326" target="_blank" rel="noreferrer"&gt;Fysac/CVE-2019-20326&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2107
 &lt;div id="cve-2019-2107" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2107" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-130024844.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/CVE-2019-2107" target="_blank" rel="noreferrer"&gt;marcinguy/CVE-2019-2107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/infiniteLoopers/CVE-2019-2107" target="_blank" rel="noreferrer"&gt;infiniteLoopers/CVE-2019-2107&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2196
 &lt;div id="cve-2019-2196" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2196" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269143
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IOActive/AOSP-DownloadProviderDbDumperSQLiLimit" target="_blank" rel="noreferrer"&gt;IOActive/AOSP-DownloadProviderDbDumperSQLiLimit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2198
 &lt;div id="cve-2019-2198" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2198" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135270103
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IOActive/AOSP-DownloadProviderDbDumperSQLiWhere" target="_blank" rel="noreferrer"&gt;IOActive/AOSP-DownloadProviderDbDumperSQLiWhere&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2215
 &lt;div id="cve-2019-2215" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2215" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/timwr/CVE-2019-2215" target="_blank" rel="noreferrer"&gt;timwr/CVE-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/addhaloka/CVE-2019-2215" target="_blank" rel="noreferrer"&gt;addhaloka/CVE-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kangtastic/cve-2019-2215" target="_blank" rel="noreferrer"&gt;kangtastic/cve-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/CVE-2019-2215" target="_blank" rel="noreferrer"&gt;marcinguy/CVE-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LIznzn/CVE-2019-2215" target="_blank" rel="noreferrer"&gt;LIznzn/CVE-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DimitriFourny/cve-2019-2215" target="_blank" rel="noreferrer"&gt;DimitriFourny/cve-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/c0n71nu3/android-kernel-exploitation-ashfaq-CVE-2019-2215" target="_blank" rel="noreferrer"&gt;c0n71nu3/android-kernel-exploitation-ashfaq-CVE-2019-2215&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2525
 &lt;div id="cve-2019-2525" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2525" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Phantomn/VirtualBox_CVE-2019-2525-CVE-2019-2548" target="_blank" rel="noreferrer"&gt;Phantomn/VirtualBox_CVE-2019-2525-CVE-2019-2548&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wotmd/VirtualBox-6.0.0-Exploit-1-day" target="_blank" rel="noreferrer"&gt;wotmd/VirtualBox-6.0.0-Exploit-1-day&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2615
 &lt;div id="cve-2019-2615" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2615" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chiaifan/CVE-2019-2615" target="_blank" rel="noreferrer"&gt;chiaifan/CVE-2019-2615&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2618
 &lt;div id="cve-2019-2618" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2618" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2019-2618" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2019-2618&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/cve-2019-2618" target="_blank" rel="noreferrer"&gt;jas502n/cve-2019-2618&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wsfengfan/CVE-2019-2618-" target="_blank" rel="noreferrer"&gt;wsfengfan/CVE-2019-2618-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dr0op/WeblogicScan" target="_blank" rel="noreferrer"&gt;dr0op/WeblogicScan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/he1dan/cve-2019-2618" target="_blank" rel="noreferrer"&gt;he1dan/cve-2019-2618&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/cve-2019-2618" target="_blank" rel="noreferrer"&gt;ianxtianxt/cve-2019-2618&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xn0ne/weblogicScanner" target="_blank" rel="noreferrer"&gt;0xn0ne/weblogicScanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhzyker/exphub" target="_blank" rel="noreferrer"&gt;zhzyker/exphub&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2725
 &lt;div id="cve-2019-2725" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2725" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shack2/javaserializetools" target="_blank" rel="noreferrer"&gt;shack2/javaserializetools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961" target="_blank" rel="noreferrer"&gt;SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iceMatcha/CNTA-2019-0014xCVE-2019-2725" target="_blank" rel="noreferrer"&gt;iceMatcha/CNTA-2019-0014xCVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lasensio/cve-2019-2725" target="_blank" rel="noreferrer"&gt;lasensio/cve-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/davidmthomsen/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;davidmthomsen/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leerina/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;leerina/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhusx110/cve-2019-2725" target="_blank" rel="noreferrer"&gt;zhusx110/cve-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lufeirider/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;lufeirider/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CVCLabs/cve-2019-2725" target="_blank" rel="noreferrer"&gt;CVCLabs/cve-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TopScrew/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;TopScrew/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/welove88888/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;welove88888/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;jiansiting/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kerlingcode/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;kerlingcode/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/black-mirror/Weblogic" target="_blank" rel="noreferrer"&gt;black-mirror/Weblogic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pimps/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;pimps/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-2725" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-2725&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GEIGEI123/CVE-2019-2725-POC" target="_blank" rel="noreferrer"&gt;GEIGEI123/CVE-2019-2725-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GGyao/weblogic_2019_2725_wls_batch" target="_blank" rel="noreferrer"&gt;GGyao/weblogic_2019_2725_wls_batch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2729
 &lt;div id="cve-2019-2729" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2729" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/waffl3ss/CVE-2019-2729" target="_blank" rel="noreferrer"&gt;waffl3ss/CVE-2019-2729&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ruthlezs/CVE-2019-2729-Exploit" target="_blank" rel="noreferrer"&gt;ruthlezs/CVE-2019-2729-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2888
 &lt;div id="cve-2019-2888" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2888" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/21superman/weblogic_cve-2019-2888" target="_blank" rel="noreferrer"&gt;21superman/weblogic_cve-2019-2888&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-2888" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-2888&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-2890
 &lt;div id="cve-2019-2890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-2890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ZO1RO/CVE-2019-2890" target="_blank" rel="noreferrer"&gt;ZO1RO/CVE-2019-2890&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ky0-HVA/CVE-2019-2890" target="_blank" rel="noreferrer"&gt;Ky0-HVA/CVE-2019-2890&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SukaraLin/CVE-2019-2890" target="_blank" rel="noreferrer"&gt;SukaraLin/CVE-2019-2890&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-2890" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-2890&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-2890" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-2890&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3010
 &lt;div id="cve-2019-3010" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3010" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chaizeg/privilege-escalation-breach" target="_blank" rel="noreferrer"&gt;chaizeg/privilege-escalation-breach&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3394
 &lt;div id="cve-2019-3394" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3394" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a page is able to exploit this issue to read arbitrary file on the server under &amp;lt;install-directory&amp;gt;/confluence/WEB-INF directory, which may contain configuration files used for integrating with other services, which could potentially leak credentials or other sensitive information such as LDAP credentials. The LDAP credential will be potentially leaked only if the Confluence server is configured to use LDAP as user repository. All versions of Confluence Server from 6.1.0 before 6.6.16 (the fixed version for 6.6.x), from 6.7.0 before 6.13.7 (the fixed version for 6.13.x), and from 6.14.0 before 6.15.8 (the fixed version for 6.15.x) are affected by this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-3394" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-3394&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3396
 &lt;div id="cve-2019-3396" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3396" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dothanthitiendiettiende/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;dothanthitiendiettiende/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x-f1v3/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;x-f1v3/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shadowsock5/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;shadowsock5/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Yt1g3r/CVE-2019-3396_EXP" target="_blank" rel="noreferrer"&gt;Yt1g3r/CVE-2019-3396_EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s1xg0d/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;s1xg0d/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/quanpt103/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;quanpt103/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vntest11/confluence_CVE-2019-3396" target="_blank" rel="noreferrer"&gt;vntest11/confluence_CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tanw923/test1" target="_blank" rel="noreferrer"&gt;tanw923/test1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/skommando/CVE-2019-3396-confluence-poc" target="_blank" rel="noreferrer"&gt;skommando/CVE-2019-3396-confluence-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JonathanZhou348/CVE-2019-3396TEST" target="_blank" rel="noreferrer"&gt;JonathanZhou348/CVE-2019-3396TEST&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/am6539/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;am6539/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/W2Ning/CVE-2019-3396" target="_blank" rel="noreferrer"&gt;W2Ning/CVE-2019-3396&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3398
 &lt;div id="cve-2019-3398" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3398" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/superevr/cve-2019-3398" target="_blank" rel="noreferrer"&gt;superevr/cve-2019-3398&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3462
 &lt;div id="cve-2019-3462" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3462" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tonejito/check_CVE-2019-3462" target="_blank" rel="noreferrer"&gt;tonejito/check_CVE-2019-3462&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/atilacastro/update-apt-package" target="_blank" rel="noreferrer"&gt;atilacastro/update-apt-package&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3663
 &lt;div id="cve-2019-3663" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3663" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD prior to 4.8. See the Security bulletin for further details
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/funoverip/mcafee_atd_CVE-2019-3663" target="_blank" rel="noreferrer"&gt;funoverip/mcafee_atd_CVE-2019-3663&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3719
 &lt;div id="cve-2019-3719" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3719" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/CVE-2019-3719" target="_blank" rel="noreferrer"&gt;jiansiting/CVE-2019-3719&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3778
 &lt;div id="cve-2019-3778" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3778" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the &amp;quot;redirect_uri&amp;quot; parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code. This vulnerability exposes applications that meet all of the following requirements: Act in the role of an Authorization Server (e.g. @EnableAuthorizationServer) and uses the DefaultRedirectResolver in the AuthorizationEndpoint. This vulnerability does not expose applications that: Act in the role of an Authorization Server and uses a different RedirectResolver implementation other than DefaultRedirectResolver, act in the role of a Resource Server only (e.g. @EnableResourceServer), act in the role of a Client only (e.g. @EnableOAuthClient).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BBB-man/CVE-2019-3778-Spring-Security-OAuth-2.3-Open-Redirection" target="_blank" rel="noreferrer"&gt;BBB-man/CVE-2019-3778-Spring-Security-OAuth-2.3-Open-Redirection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3799
 &lt;div id="cve-2019-3799" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3799" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-3799" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-3799&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3847
 &lt;div id="cve-2019-3847" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3847" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the &amp;quot;login as other users&amp;quot; capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/danielthatcher/moodle-login-csrf" target="_blank" rel="noreferrer"&gt;danielthatcher/moodle-login-csrf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-3929
 &lt;div id="cve-2019-3929" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-3929" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xfox64x/CVE-2019-3929" target="_blank" rel="noreferrer"&gt;xfox64x/CVE-2019-3929&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-48814
 &lt;div id="cve-2019-48814" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-48814" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wucj001/cve-2019-48814" target="_blank" rel="noreferrer"&gt;wucj001/cve-2019-48814&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5010
 &lt;div id="cve-2019-5010" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5010" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JonathanWilbur/CVE-2019-5010" target="_blank" rel="noreferrer"&gt;JonathanWilbur/CVE-2019-5010&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5096
 &lt;div id="cve-2019-5096" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5096" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/papinnon/CVE-2019-5096-GoAhead-Web-Server-Dos-Exploit" target="_blank" rel="noreferrer"&gt;papinnon/CVE-2019-5096-GoAhead-Web-Server-Dos-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5418
 &lt;div id="cve-2019-5418" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5418" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is a File Content Disclosure vulnerability in Action View &amp;lt;5.2.2.1, &amp;lt;5.1.6.2, &amp;lt;5.0.7.2, &amp;lt;4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-5418" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-5418&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/omarkurt/CVE-2019-5418" target="_blank" rel="noreferrer"&gt;omarkurt/CVE-2019-5418&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/brompwnie/CVE-2019-5418-Scanner" target="_blank" rel="noreferrer"&gt;brompwnie/CVE-2019-5418-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/Rails-doubletap-RCE" target="_blank" rel="noreferrer"&gt;mpgn/Rails-doubletap-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/takeokunn/CVE-2019-5418" target="_blank" rel="noreferrer"&gt;takeokunn/CVE-2019-5418&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Bad3r/RailroadBandit" target="_blank" rel="noreferrer"&gt;Bad3r/RailroadBandit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ztgrace/CVE-2019-5418-Rails3" target="_blank" rel="noreferrer"&gt;ztgrace/CVE-2019-5418-Rails3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/random-robbie/CVE-2019-5418" target="_blank" rel="noreferrer"&gt;random-robbie/CVE-2019-5418&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5420
 &lt;div id="cve-2019-5420" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5420" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability in development mode Rails &amp;lt;5.2.2.1, &amp;lt;6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2019-5420" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2019-5420&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2019-5420" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2019-5420&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5475
 &lt;div id="cve-2019-5475" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5475" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jaychouzzk/CVE-2019-5475-Nexus-Repository-Manager-" target="_blank" rel="noreferrer"&gt;jaychouzzk/CVE-2019-5475-Nexus-Repository-Manager-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rabbitmask/CVE-2019-5475-EXP" target="_blank" rel="noreferrer"&gt;rabbitmask/CVE-2019-5475-EXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5489
 &lt;div id="cve-2019-5489" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5489" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mmxsrup/CVE-2019-5489" target="_blank" rel="noreferrer"&gt;mmxsrup/CVE-2019-5489&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5624
 &lt;div id="cve-2019-5624" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5624" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at the privilege level of the user running Metasploit. This issue affects: Rapid7 Metasploit Framework version 4.14.0 and prior versions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/VoidSec/CVE-2019-5624" target="_blank" rel="noreferrer"&gt;VoidSec/CVE-2019-5624&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5630
 &lt;div id="cve-2019-5630" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5630" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rbeede/CVE-2019-5630" target="_blank" rel="noreferrer"&gt;rbeede/CVE-2019-5630&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5700
 &lt;div id="cve-2019-5700" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5700" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/oscardagrach/CVE-2019-5700" target="_blank" rel="noreferrer"&gt;oscardagrach/CVE-2019-5700&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5736
 &lt;div id="cve-2019-5736" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5736" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/q3k/cve-2019-5736-poc" target="_blank" rel="noreferrer"&gt;q3k/cve-2019-5736-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Frichetten/CVE-2019-5736-PoC" target="_blank" rel="noreferrer"&gt;Frichetten/CVE-2019-5736-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-5736" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-5736&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2019-5736" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2019-5736&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/cve-2019-5736-poc" target="_blank" rel="noreferrer"&gt;denmilu/cve-2019-5736-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/agppp/cve-2019-5736-poc" target="_blank" rel="noreferrer"&gt;agppp/cve-2019-5736-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Matthew-Stacks/cve-2019-5736" target="_blank" rel="noreferrer"&gt;Matthew-Stacks/cve-2019-5736&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ebdecastro/poc-cve-2019-5736" target="_blank" rel="noreferrer"&gt;ebdecastro/poc-cve-2019-5736&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/twistlock/RunC-CVE-2019-5736" target="_blank" rel="noreferrer"&gt;twistlock/RunC-CVE-2019-5736&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/k-onishi/CVE-2019-5736-PoC" target="_blank" rel="noreferrer"&gt;k-onishi/CVE-2019-5736-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/k-onishi/CVE-2019-5736-PoC-0" target="_blank" rel="noreferrer"&gt;k-onishi/CVE-2019-5736-PoC-0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zyriuse75/CVE-2019-5736-PoC" target="_blank" rel="noreferrer"&gt;zyriuse75/CVE-2019-5736-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/stillan00b/CVE-2019-5736" target="_blank" rel="noreferrer"&gt;stillan00b/CVE-2019-5736&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/milloni/cve-2019-5736-exp" target="_blank" rel="noreferrer"&gt;milloni/cve-2019-5736-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/13paulmurith/Docker-Runc-Exploit" target="_blank" rel="noreferrer"&gt;13paulmurith/Docker-Runc-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RyanNgWH/CVE-2019-5736-POC" target="_blank" rel="noreferrer"&gt;RyanNgWH/CVE-2019-5736-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Lee-SungYoung/cve-2019-5736-study" target="_blank" rel="noreferrer"&gt;Lee-SungYoung/cve-2019-5736-study&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chosam2/cve-2019-5736-poc" target="_blank" rel="noreferrer"&gt;chosam2/cve-2019-5736-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/epsteina16/Docker-Escape-Miner" target="_blank" rel="noreferrer"&gt;epsteina16/Docker-Escape-Miner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GiverOfGifts/CVE-2019-5736-Custom-Runtime" target="_blank" rel="noreferrer"&gt;GiverOfGifts/CVE-2019-5736-Custom-Runtime&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Billith/CVE-2019-5736-PoC" target="_blank" rel="noreferrer"&gt;Billith/CVE-2019-5736-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5786
 &lt;div id="cve-2019-5786" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5786" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/exodusintel/CVE-2019-5786" target="_blank" rel="noreferrer"&gt;exodusintel/CVE-2019-5786&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5825
 &lt;div id="cve-2019-5825" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5825" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/timwr/CVE-2019-5825" target="_blank" rel="noreferrer"&gt;timwr/CVE-2019-5825&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-5893
 &lt;div id="cve-2019-5893" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-5893" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EmreOvunc/OpenSource-ERP-SQL-Injection" target="_blank" rel="noreferrer"&gt;EmreOvunc/OpenSource-ERP-SQL-Injection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6203
 &lt;div id="cve-2019-6203" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6203" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/qingxp9/CVE-2019-6203-PoC" target="_blank" rel="noreferrer"&gt;qingxp9/CVE-2019-6203-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6207
 &lt;div id="cve-2019-6207" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6207" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dothanthitiendiettiende/CVE-2019-6207" target="_blank" rel="noreferrer"&gt;dothanthitiendiettiende/CVE-2019-6207&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/maldiohead/CVE-2019-6207" target="_blank" rel="noreferrer"&gt;maldiohead/CVE-2019-6207&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DimitriFourny/cve-2019-6207" target="_blank" rel="noreferrer"&gt;DimitriFourny/cve-2019-6207&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6225
 &lt;div id="cve-2019-6225" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6225" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to elevate privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fatgrass/OsirisJailbreak12" target="_blank" rel="noreferrer"&gt;fatgrass/OsirisJailbreak12&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TrungNguyen1909/CVE-2019-6225-macOS" target="_blank" rel="noreferrer"&gt;TrungNguyen1909/CVE-2019-6225-macOS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/raystyle/jailbreak-iOS12" target="_blank" rel="noreferrer"&gt;raystyle/jailbreak-iOS12&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6249
 &lt;div id="cve-2019-6249" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6249" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&amp;amp;act=edit_info&amp;amp;act_type=add.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/NMTech0x90/CVE-2019-6249_Hucart-cms" target="_blank" rel="noreferrer"&gt;NMTech0x90/CVE-2019-6249_Hucart-cms&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6260
 &lt;div id="cve-2019-6260" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6260" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/amboar/cve-2019-6260" target="_blank" rel="noreferrer"&gt;amboar/cve-2019-6260&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6263
 &lt;div id="cve-2019-6263" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6263" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/praveensutar/CVE-2019-6263-Joomla-POC" target="_blank" rel="noreferrer"&gt;praveensutar/CVE-2019-6263-Joomla-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6329
 &lt;div id="cve-2019-6329" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6329" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ManhNDd/CVE-2019-6329" target="_blank" rel="noreferrer"&gt;ManhNDd/CVE-2019-6329&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6340
 &lt;div id="cve-2019-6340" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6340" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/g0rx/Drupal-SA-CORE-2019-003" target="_blank" rel="noreferrer"&gt;g0rx/Drupal-SA-CORE-2019-003&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2019-6340" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2019-6340&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DevDungeon/CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass" target="_blank" rel="noreferrer"&gt;DevDungeon/CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oways/CVE-2019-6340" target="_blank" rel="noreferrer"&gt;oways/CVE-2019-6340&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2019-6340" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2019-6340&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/d1vious/cve-2019-6340-bits" target="_blank" rel="noreferrer"&gt;d1vious/cve-2019-6340-bits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-6340" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-6340&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6440
 &lt;div id="cve-2019-6440" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6440" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Zemana AntiMalware before 3.0.658 Beta mishandles update logic.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hexnone/CVE-2019-6440" target="_blank" rel="noreferrer"&gt;hexnone/CVE-2019-6440&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6446
 &lt;div id="cve-2019-6446" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6446" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RayScri/CVE-2019-6446" target="_blank" rel="noreferrer"&gt;RayScri/CVE-2019-6446&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6447
 &lt;div id="cve-2019-6447" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6447" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fs0c131y/ESFileExplorerOpenPortVuln" target="_blank" rel="noreferrer"&gt;fs0c131y/ESFileExplorerOpenPortVuln&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6453
 &lt;div id="cve-2019-6453" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6453" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/proofofcalc/cve-2019-6453-poc" target="_blank" rel="noreferrer"&gt;proofofcalc/cve-2019-6453-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andripwn/mIRC-CVE-2019-6453" target="_blank" rel="noreferrer"&gt;andripwn/mIRC-CVE-2019-6453&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6467
 &lt;div id="cve-2019-6467" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6467" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-&amp;gt; 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2019-6467" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2019-6467&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6487
 &lt;div id="cve-2019-6487" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6487" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/afang5472/TP-Link-WDR-Router-Command-injection_POC" target="_blank" rel="noreferrer"&gt;afang5472/TP-Link-WDR-Router-Command-injection_POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6690
 &lt;div id="cve-2019-6690" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6690" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a &amp;quot;CWE-20: Improper Input Validation&amp;quot; issue affecting the affect functionality component.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/stigtsp/CVE-2019-6690-python-gnupg-vulnerability" target="_blank" rel="noreferrer"&gt;stigtsp/CVE-2019-6690-python-gnupg-vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/CVE-2019-6690" target="_blank" rel="noreferrer"&gt;brianwrf/CVE-2019-6690&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-6715
 &lt;div id="cve-2019-6715" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-6715" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/random-robbie/cve-2019-6715" target="_blank" rel="noreferrer"&gt;random-robbie/cve-2019-6715&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7216
 &lt;div id="cve-2019-7216" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7216" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user to upload any type of file by using % characters within the extension, e.g., file.%ph%p becomes file.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ekultek/CVE-2019-7216" target="_blank" rel="noreferrer"&gt;Ekultek/CVE-2019-7216&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7219
 &lt;div id="cve-2019-7219" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7219" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/verifysecurity/CVE-2019-7219" target="_blank" rel="noreferrer"&gt;verifysecurity/CVE-2019-7219&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7238
 &lt;div id="cve-2019-7238" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7238" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-7238" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-7238&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-7238" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-7238&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/verctor/nexus_rce_CVE-2019-7238" target="_blank" rel="noreferrer"&gt;verctor/nexus_rce_CVE-2019-7238&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/magicming200/CVE-2019-7238_Nexus_RCE_Tool" target="_blank" rel="noreferrer"&gt;magicming200/CVE-2019-7238_Nexus_RCE_Tool&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7304
 &lt;div id="cve-2019-7304" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7304" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/initstring/dirty_sock" target="_blank" rel="noreferrer"&gt;initstring/dirty_sock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SecuritySi/CVE-2019-7304_DirtySock" target="_blank" rel="noreferrer"&gt;SecuritySi/CVE-2019-7304_DirtySock&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7482
 &lt;div id="cve-2019-7482" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7482" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/singletrackseeker/CVE-2019-7482" target="_blank" rel="noreferrer"&gt;singletrackseeker/CVE-2019-7482&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b4bay/CVE-2019-7482" target="_blank" rel="noreferrer"&gt;b4bay/CVE-2019-7482&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7609
 &lt;div id="cve-2019-7609" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7609" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/kibana-RCE" target="_blank" rel="noreferrer"&gt;jas502n/kibana-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-7609" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-7609&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LandGrey/CVE-2019-7609" target="_blank" rel="noreferrer"&gt;LandGrey/CVE-2019-7609&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hekadan/CVE-2019-7609" target="_blank" rel="noreferrer"&gt;hekadan/CVE-2019-7609&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rhbb/CVE-2019-7609" target="_blank" rel="noreferrer"&gt;rhbb/CVE-2019-7609&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7610
 &lt;div id="cve-2019-7610" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7610" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whoami0622/CVE-2019-7610" target="_blank" rel="noreferrer"&gt;whoami0622/CVE-2019-7610&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7642
 &lt;div id="cve-2019-7642" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7642" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xw77cve/CVE-2019-7642" target="_blank" rel="noreferrer"&gt;xw77cve/CVE-2019-7642&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-7839
 &lt;div id="cve-2019-7839" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-7839" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2019-7839" target="_blank" rel="noreferrer"&gt;securifera/CVE-2019-7839&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8389
 &lt;div id="cve-2019-8389" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8389" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shawarkhanethicalhacker/CVE-2019-8389" target="_blank" rel="noreferrer"&gt;shawarkhanethicalhacker/CVE-2019-8389&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8446
 &lt;div id="cve-2019-8446" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8446" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CyberTrashPanda/CVE-2019-8446" target="_blank" rel="noreferrer"&gt;CyberTrashPanda/CVE-2019-8446&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8449
 &lt;div id="cve-2019-8449" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8449" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mufeedvh/CVE-2019-8449" target="_blank" rel="noreferrer"&gt;mufeedvh/CVE-2019-8449&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r0lh/CVE-2019-8449" target="_blank" rel="noreferrer"&gt;r0lh/CVE-2019-8449&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8451
 &lt;div id="cve-2019-8451" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8451" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xbug/CVE-2019-8451" target="_blank" rel="noreferrer"&gt;0xbug/CVE-2019-8451&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2019-8451" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2019-8451&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2019-8451" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2019-8451&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/h0ffayyy/Jira-CVE-2019-8451" target="_blank" rel="noreferrer"&gt;h0ffayyy/Jira-CVE-2019-8451&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8513
 &lt;div id="cve-2019-8513" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8513" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/genknife/cve-2019-8513" target="_blank" rel="noreferrer"&gt;genknife/cve-2019-8513&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8540
 &lt;div id="cve-2019-8540" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8540" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/maldiohead/CVE-2019-8540" target="_blank" rel="noreferrer"&gt;maldiohead/CVE-2019-8540&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8565
 &lt;div id="cve-2019-8565" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8565" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to gain root privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/genknife/cve-2019-8565" target="_blank" rel="noreferrer"&gt;genknife/cve-2019-8565&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8591
 &lt;div id="cve-2019-8591" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8591" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jsherman212/used_sock" target="_blank" rel="noreferrer"&gt;jsherman212/used_sock&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8601
 &lt;div id="cve-2019-8601" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8601" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BadAccess11/CVE-2019-8601" target="_blank" rel="noreferrer"&gt;BadAccess11/CVE-2019-8601&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8627
 &lt;div id="cve-2019-8627" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8627" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/maldiohead/CVE-2019-8627" target="_blank" rel="noreferrer"&gt;maldiohead/CVE-2019-8627&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8781
 &lt;div id="cve-2019-8781" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8781" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/A2nkF/macOS-Kernel-Exploit" target="_blank" rel="noreferrer"&gt;A2nkF/macOS-Kernel-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TrungNguyen1909/CVE-2019-8781-macOS" target="_blank" rel="noreferrer"&gt;TrungNguyen1909/CVE-2019-8781-macOS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8936
 &lt;div id="cve-2019-8936" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8936" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NTP through 4.2.8p12 has a NULL Pointer Dereference.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/snappyJack/CVE-2019-8936" target="_blank" rel="noreferrer"&gt;snappyJack/CVE-2019-8936&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8942
 &lt;div id="cve-2019-8942" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8942" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/WordPress_4.9.8_RCE_POC" target="_blank" rel="noreferrer"&gt;brianwrf/WordPress_4.9.8_RCE_POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/synacktiv/CVE-2019-8942" target="_blank" rel="noreferrer"&gt;synacktiv/CVE-2019-8942&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8956
 &lt;div id="cve-2019-8956" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8956" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the &amp;quot;sctp_sendmsg()&amp;quot; function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/butterflyhack/CVE-2019-8956" target="_blank" rel="noreferrer"&gt;butterflyhack/CVE-2019-8956&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8978
 &lt;div id="cve-2019-8978" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8978" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO Manager. This vulnerability allows remote attackers to steal a victim's session (and cause a denial of service) by repeatedly requesting the initial Banner Web Tailor main page with the IDMSESSID cookie set to the victim's UDCID, which in the case tested is the institutional ID. During a login attempt by a victim, the attacker can leverage the race condition and will be issued the SESSID that was meant for this victim.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JoshuaMulliken/CVE-2019-8978" target="_blank" rel="noreferrer"&gt;JoshuaMulliken/CVE-2019-8978&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-8997
 &lt;div id="cve-2019-8997" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-8997" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nxkennedy/CVE-2019-8997" target="_blank" rel="noreferrer"&gt;nxkennedy/CVE-2019-8997&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9153
 &lt;div id="cve-2019-9153" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9153" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Improper Verification of a Cryptographic Signature in OpenPGP.js &amp;lt;=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a &amp;quot;standalone&amp;quot; or &amp;quot;timestamp&amp;quot; signature.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ZenyWay/opgp-service-cve-2019-9153" target="_blank" rel="noreferrer"&gt;ZenyWay/opgp-service-cve-2019-9153&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9184
 &lt;div id="cve-2019-9184" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9184" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2019-9184" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2019-9184&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9193
 &lt;div id="cve-2019-9193" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9193" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** In PostgreSQL 9.3 through 11.2, the &amp;quot;COPY TO/FROM PROGRAM&amp;quot; function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/skyship36/CVE-2019-9193" target="_blank" rel="noreferrer"&gt;skyship36/CVE-2019-9193&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9194
 &lt;div id="cve-2019-9194" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9194" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2019-9194" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2019-9194&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9202
 &lt;div id="cve-2019-9202" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9202" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/polict/CVE-2019-9202" target="_blank" rel="noreferrer"&gt;polict/CVE-2019-9202&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9465
 &lt;div id="cve-2019-9465" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9465" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alexbakker/CVE-2019-9465" target="_blank" rel="noreferrer"&gt;alexbakker/CVE-2019-9465&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9506
 &lt;div id="cve-2019-9506" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9506" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka &amp;quot;KNOB&amp;quot;) that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/francozappa/knob" target="_blank" rel="noreferrer"&gt;francozappa/knob&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9580
 &lt;div id="cve-2019-9580" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9580" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a &amp;quot;null&amp;quot; origin value, potentially leading to XSS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-9580" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-9580&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9596
 &lt;div id="cve-2019-9596" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9596" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gerwout/CVE-2019-9596-and-CVE-2019-9597" target="_blank" rel="noreferrer"&gt;gerwout/CVE-2019-9596-and-CVE-2019-9597&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9599
 &lt;div id="cve-2019-9599" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9599" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/s4vitar/AirDroidPwner" target="_blank" rel="noreferrer"&gt;s4vitar/AirDroidPwner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9621
 &lt;div id="cve-2019-9621" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9621" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/k8gege/ZimbraExploit" target="_blank" rel="noreferrer"&gt;k8gege/ZimbraExploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9653
 &lt;div id="cve-2019-9653" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9653" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/grayoneday/CVE-2019-9653" target="_blank" rel="noreferrer"&gt;grayoneday/CVE-2019-9653&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9670
 &lt;div id="cve-2019-9670" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9670" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rek7/Zimbra-RCE" target="_blank" rel="noreferrer"&gt;rek7/Zimbra-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/attackgithub/Zimbra-RCE" target="_blank" rel="noreferrer"&gt;attackgithub/Zimbra-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9673
 &lt;div id="cve-2019-9673" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9673" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mgrube/CVE-2019-9673" target="_blank" rel="noreferrer"&gt;mgrube/CVE-2019-9673&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9729
 &lt;div id="cve-2019-9729" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9729" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HyperSine/SdoKeyCrypt-sys-local-privilege-elevation" target="_blank" rel="noreferrer"&gt;HyperSine/SdoKeyCrypt-sys-local-privilege-elevation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9730
 &lt;div id="cve-2019-9730" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9730" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an unpublished API.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jthuraisamy/CVE-2019-9730" target="_blank" rel="noreferrer"&gt;jthuraisamy/CVE-2019-9730&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9745
 &lt;div id="cve-2019-9745" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9745" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used to import data from CRM software using plugins (.dll files). The plugin to import data from the EXQUISE software (DatasourceExquiseExporter.dll) can be persuaded to start arbitrary programs (including batch files) that are executed using the same privileges as Recognition Update Client Service (NT AUTHORITY\SYSTEM), thus elevating privileges. This occurs because a higher-privileged process executes scripts from a directory writable by a lower-privileged user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KPN-CISO/CVE-2019-9745" target="_blank" rel="noreferrer"&gt;KPN-CISO/CVE-2019-9745&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9766
 &lt;div id="cve-2019-9766" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9766" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .mp3 file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/moonheadobj/CVE-2019-9766" target="_blank" rel="noreferrer"&gt;moonheadobj/CVE-2019-9766&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9787
 &lt;div id="cve-2019-9787" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9787" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rkatogit/cve-2019-9787_csrf_poc" target="_blank" rel="noreferrer"&gt;rkatogit/cve-2019-9787_csrf_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/PalmTreeForest/CodePath_Week_7-8" target="_blank" rel="noreferrer"&gt;PalmTreeForest/CodePath_Week_7-8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sijiahi/Wordpress_cve-2019-9787_defense" target="_blank" rel="noreferrer"&gt;sijiahi/Wordpress_cve-2019-9787_defense&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9810
 &lt;div id="cve-2019-9810" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9810" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox &amp;lt; 66.0.1, Firefox ESR &amp;lt; 60.6.1, and Thunderbird &amp;lt; 60.6.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xuechiyaobai/CVE-2019-9810-PoC" target="_blank" rel="noreferrer"&gt;xuechiyaobai/CVE-2019-9810-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0vercl0k/CVE-2019-9810" target="_blank" rel="noreferrer"&gt;0vercl0k/CVE-2019-9810&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9896
 &lt;div id="cve-2019-9896" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9896" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/yasinyilmaz/vuln-chm-hijack" target="_blank" rel="noreferrer"&gt;yasinyilmaz/vuln-chm-hijack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2019-9978
 &lt;div id="cve-2019-9978" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2019-9978" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2019-9978" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2019-9978&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hash3liZer/CVE-2019-9978" target="_blank" rel="noreferrer"&gt;hash3liZer/CVE-2019-9978&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KTN1990/CVE-2019-9978" target="_blank" rel="noreferrer"&gt;KTN1990/CVE-2019-9978&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2019-9978" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2019-9978&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2018
 &lt;div id="2018" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2018" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0101
 &lt;div id="cve-2018-0101" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0101" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, ASA 1000V Cloud Firewall, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4110 Security Appliance, Firepower 9300 ASA Security Module, Firepower Threat Defense Software (FTD). Cisco Bug IDs: CSCvg35618.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2018-0101-DOS-POC" target="_blank" rel="noreferrer"&gt;1337g/CVE-2018-0101-DOS-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cymmetria/ciscoasa_honeypot" target="_blank" rel="noreferrer"&gt;Cymmetria/ciscoasa_honeypot&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0114
 &lt;div id="cve-2018-0114" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0114" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for JSON Web Tokens (JWTs). This standard specifies that a JSON Web Key (JWK) representing a public key can be embedded within the header of a JWS. This public key is then trusted for verification. An attacker could exploit this by forging valid JWS objects by removing the original signature, adding a new public key to the header, and then signing the object using the (attacker-owned) private key associated with the public key embedded in that JWS header.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zi0Black/POC-CVE-2018-0114" target="_blank" rel="noreferrer"&gt;zi0Black/POC-CVE-2018-0114&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0202
 &lt;div id="cve-2018-0202" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0202" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jaychowjingjie/CVE-2018-0202" target="_blank" rel="noreferrer"&gt;jaychowjingjie/CVE-2018-0202&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0296
 &lt;div id="cve-2018-0296" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0296" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/milo2012/CVE-2018-0296" target="_blank" rel="noreferrer"&gt;milo2012/CVE-2018-0296&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yassineaboukir/CVE-2018-0296" target="_blank" rel="noreferrer"&gt;yassineaboukir/CVE-2018-0296&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bhenner1/CVE-2018-0296" target="_blank" rel="noreferrer"&gt;bhenner1/CVE-2018-0296&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/irbishop/CVE-2018-0296" target="_blank" rel="noreferrer"&gt;irbishop/CVE-2018-0296&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qiantu88/CVE-2018-0296" target="_blank" rel="noreferrer"&gt;qiantu88/CVE-2018-0296&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0708
 &lt;div id="cve-2018-0708" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0708" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ntkernel0/CVE-2019-0708" target="_blank" rel="noreferrer"&gt;ntkernel0/CVE-2019-0708&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0802
 &lt;div id="cve-2018-0802" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0802" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka &amp;quot;Microsoft Office Memory Corruption Vulnerability&amp;quot;. This CVE is unique from CVE-2018-0797 and CVE-2018-0812.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zldww2011/CVE-2018-0802_POC" target="_blank" rel="noreferrer"&gt;zldww2011/CVE-2018-0802_POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rxwx/CVE-2018-0802" target="_blank" rel="noreferrer"&gt;rxwx/CVE-2018-0802&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/RTF_11882_0802" target="_blank" rel="noreferrer"&gt;Ridter/RTF_11882_0802&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-0802_CVE-2017-11882" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-0802_CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0824
 &lt;div id="cve-2018-0824" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0824" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in &amp;quot;Microsoft COM for Windows&amp;quot; when it fails to properly handle serialized objects, aka &amp;quot;Microsoft COM for Windows Remote Code Execution Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/codewhitesec/UnmarshalPwn" target="_blank" rel="noreferrer"&gt;codewhitesec/UnmarshalPwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0833
 &lt;div id="cve-2018-0833" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0833" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka &amp;quot;SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2018-0833" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2018-0833&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0886
 &lt;div id="cve-2018-0886" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0886" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka &amp;quot;CredSSP Remote Code Execution Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/preempt/credssp" target="_blank" rel="noreferrer"&gt;preempt/credssp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-0952
 &lt;div id="cve-2018-0952" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-0952" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka &amp;quot;Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability.&amp;quot; This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/atredispartners/CVE-2018-0952-SystemCollector" target="_blank" rel="noreferrer"&gt;atredispartners/CVE-2018-0952-SystemCollector&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000001
 &lt;div id="cve-2018-1000001" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000001" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2018-1000001" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2018-1000001&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000006
 &lt;div id="cve-2018-1000006" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000006" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CHYbeta/CVE-2018-1000006-DEMO" target="_blank" rel="noreferrer"&gt;CHYbeta/CVE-2018-1000006-DEMO&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000030
 &lt;div id="cve-2018-1000030" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000030" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The vulnerability lies when multiply threads are handling large amounts of data. In both cases there is essentially a race condition that occurs. For the Heap-Buffer-Overflow, Thread 2 is creating the size for a buffer, but Thread1 is already writing to the buffer without knowing how much to write. So when a large amount of data is being processed, it is very easy to cause memory corruption using a Heap-Buffer-Overflow. As for the Use-After-Free, Thread3-&amp;gt;Malloc-&amp;gt;Thread1-&amp;gt;Free's-&amp;gt;Thread2-Re-uses-Free'd Memory. The PSRT has stated that this is not a security vulnerability due to the fact that the attacker must be able to run code, however in some situations, such as function as a service, this vulnerability can potentially be used by an attacker to violate a trust boundary, as such the DWF feels this issue deserves a CVE.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tylepr96/CVE-2018-1000030" target="_blank" rel="noreferrer"&gt;tylepr96/CVE-2018-1000030&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000082
 &lt;div id="cve-2018-1000082" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000082" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed..
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2018-1000082-exploit" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2018-1000082-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000117
 &lt;div id="cve-2018-1000117" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000117" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1337r00t/CVE-2018-1000117-Exploit" target="_blank" rel="noreferrer"&gt;1337r00t/CVE-2018-1000117-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000134
 &lt;div id="cve-2018-1000134" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000134" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process function in SimpleBindRequest class doesn't check for empty password when running in synchronous mode. commit with applied fix https://github.com/pingidentity/ldapsdk/commit/8471904a02438c03965d21367890276bc25fa5a6#diff-f6cb23b459be1ec17df1da33760087fd that can result in Ability to impersonate any valid user. This attack appear to be exploitable via Providing valid username and empty password against servers that do not do additional validation as per https://tools.ietf.org/html/rfc4513#section-5.1.1. This vulnerability appears to have been fixed in after commit 8471904a02438c03965d21367890276bc25fa5a6.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dragotime/cve-2018-1000134" target="_blank" rel="noreferrer"&gt;dragotime/cve-2018-1000134&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000140
 &lt;div id="cve-2018-1000140" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000140" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/s0/rsyslog-librelp-CVE-2018-1000140" target="_blank" rel="noreferrer"&gt;s0/rsyslog-librelp-CVE-2018-1000140&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s0/rsyslog-librelp-CVE-2018-1000140-fixed" target="_blank" rel="noreferrer"&gt;s0/rsyslog-librelp-CVE-2018-1000140-fixed&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000199
 &lt;div id="cve-2018-1000199" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000199" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dsfau/CVE-2018-1000199" target="_blank" rel="noreferrer"&gt;dsfau/CVE-2018-1000199&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000224
 &lt;div id="cve-2018-1000224" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000224" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zann1x/ITS" target="_blank" rel="noreferrer"&gt;zann1x/ITS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000529
 &lt;div id="cve-2018-1000529" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000529" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/martinfrancois/CVE-2018-1000529" target="_blank" rel="noreferrer"&gt;martinfrancois/CVE-2018-1000529&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000802
 &lt;div id="cve-2018-1000802" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000802" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tna0y/CVE-2018-1000802-PoC" target="_blank" rel="noreferrer"&gt;tna0y/CVE-2018-1000802-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1000861
 &lt;div id="cve-2018-1000861" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1000861" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1NTheKut/CVE-2019-1003000_RCE-DETECTION" target="_blank" rel="noreferrer"&gt;1NTheKut/CVE-2019-1003000_RCE-DETECTION&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1002105
 &lt;div id="cve-2018-1002105" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1002105" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gravitational/cve-2018-1002105" target="_blank" rel="noreferrer"&gt;gravitational/cve-2018-1002105&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/evict/poc_CVE-2018-1002105" target="_blank" rel="noreferrer"&gt;evict/poc_CVE-2018-1002105&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/imlzw/Kubernetes-1.12.3-all-auto-install" target="_blank" rel="noreferrer"&gt;imlzw/Kubernetes-1.12.3-all-auto-install&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bgeesaman/cve-2018-1002105" target="_blank" rel="noreferrer"&gt;bgeesaman/cve-2018-1002105&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mdnix/cve-2018-1002105" target="_blank" rel="noreferrer"&gt;mdnix/cve-2018-1002105&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1010
 &lt;div id="cve-2018-1010" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1010" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka &amp;quot;Microsoft Graphics Remote Code Execution Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1012, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ymgh96/Detecting-the-patch-of-CVE-2018-1010" target="_blank" rel="noreferrer"&gt;ymgh96/Detecting-the-patch-of-CVE-2018-1010&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10118
 &lt;div id="cve-2018-10118" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10118" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GeunSam2/CVE-2018-10118" target="_blank" rel="noreferrer"&gt;GeunSam2/CVE-2018-10118&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1026
 &lt;div id="cve-2018-1026" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1026" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka &amp;quot;Microsoft Office Remote Code Execution Vulnerability.&amp;quot; This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ymgh96/Detecting-the-CVE-2018-1026-and-its-patch" target="_blank" rel="noreferrer"&gt;ymgh96/Detecting-the-CVE-2018-1026-and-its-patch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10299
 &lt;div id="cve-2018-10299" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10299" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the &amp;quot;batchOverflow&amp;quot; issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/phzietsman/batchOverflow" target="_blank" rel="noreferrer"&gt;phzietsman/batchOverflow&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10467
 &lt;div id="cve-2018-10467" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10467" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-10467" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-10467&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10517
 &lt;div id="cve-2018-10517" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10517" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In CMS Made Simple (CMSMS) through 2.2.7, the &amp;quot;module import&amp;quot; operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2018-10517" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2018-10517&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10546
 &lt;div id="cve-2018-10546" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10546" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dsfau/CVE-2018-10546" target="_blank" rel="noreferrer"&gt;dsfau/CVE-2018-10546&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1056
 &lt;div id="cve-2018-1056" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1056" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pollonegro/Gpon-Routers" target="_blank" rel="noreferrer"&gt;pollonegro/Gpon-Routers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10561
 &lt;div id="cve-2018-10561" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10561" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending &amp;quot;?images&amp;quot; to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vhackor/GPON-home-routers-Exploit" target="_blank" rel="noreferrer"&gt;vhackor/GPON-home-routers-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10562
 &lt;div id="cve-2018-10562" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10562" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/f3d0x0/GPON" target="_blank" rel="noreferrer"&gt;f3d0x0/GPON&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/649/Pingpon-Exploit" target="_blank" rel="noreferrer"&gt;649/Pingpon-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Choudai/GPON-LOADER" target="_blank" rel="noreferrer"&gt;Choudai/GPON-LOADER&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/c0ld1/GPON_RCE" target="_blank" rel="noreferrer"&gt;c0ld1/GPON_RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ATpiu/CVE-2018-10562" target="_blank" rel="noreferrer"&gt;ATpiu/CVE-2018-10562&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10583
 &lt;div id="cve-2018-10583" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10583" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TaharAmine/CVE-2018-10583" target="_blank" rel="noreferrer"&gt;TaharAmine/CVE-2018-10583&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10715
 &lt;div id="cve-2018-10715" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10715" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-10715" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-10715&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10732
 &lt;div id="cve-2018-10732" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10732" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-10732" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-10732&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10821
 &lt;div id="cve-2018-10821" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10821" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BalvinderSingh23/Cross-Site-Scripting-Reflected-XSS-Vulnerability-in-blackcatcms_v1.3" target="_blank" rel="noreferrer"&gt;BalvinderSingh23/Cross-Site-Scripting-Reflected-XSS-Vulnerability-in-blackcatcms_v1.3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1088
 &lt;div id="cve-2018-1088" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1088" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MauroEldritch/GEVAUDAN" target="_blank" rel="noreferrer"&gt;MauroEldritch/GEVAUDAN&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10920
 &lt;div id="cve-2018-10920" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10920" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shutingrz/CVE-2018-10920_PoC" target="_blank" rel="noreferrer"&gt;shutingrz/CVE-2018-10920_PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10933
 &lt;div id="cve-2018-10933" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10933" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SoledaD208/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;SoledaD208/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/blacknbunny/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;blacknbunny/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hook-s3c/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;hook-s3c/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kn6869610/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;kn6869610/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leapsecurity/libssh-scanner" target="_blank" rel="noreferrer"&gt;leapsecurity/libssh-scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-10933_ssh" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-10933_ssh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/trbpnd/bpnd-libssh" target="_blank" rel="noreferrer"&gt;trbpnd/bpnd-libssh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-10933-libSSH-Authentication-Bypass" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-10933-libSSH-Authentication-Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marco-lancini/hunt-for-cve-2018-10933" target="_blank" rel="noreferrer"&gt;marco-lancini/hunt-for-cve-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hackerhouse-opensource/cve-2018-10933" target="_blank" rel="noreferrer"&gt;hackerhouse-opensource/cve-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cve-2018/cve-2018-10933" target="_blank" rel="noreferrer"&gt;cve-2018/cve-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ninp0/cve-2018-10933_poc" target="_blank" rel="noreferrer"&gt;ninp0/cve-2018-10933_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/IDX4CKS/CVE-2018-10933_Scanner" target="_blank" rel="noreferrer"&gt;IDX4CKS/CVE-2018-10933_Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Virgula0/POC-CVE-2018-10933" target="_blank" rel="noreferrer"&gt;Virgula0/POC-CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shifa123/pythonprojects-CVE-2018-10933" target="_blank" rel="noreferrer"&gt;shifa123/pythonprojects-CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xFreed0m/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;xFreed0m/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Bifrozt/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;Bifrozt/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;r3dxpl0it/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ivanacostarubio/libssh-scanner" target="_blank" rel="noreferrer"&gt;ivanacostarubio/libssh-scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/throwawayaccount12312312/precompiled-CVE-2018-10933" target="_blank" rel="noreferrer"&gt;throwawayaccount12312312/precompiled-CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ensimag-security/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;ensimag-security/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ad1bDaw/libSSH-bypass" target="_blank" rel="noreferrer"&gt;Ad1bDaw/libSSH-bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sambiyal/CVE-2018-10933-POC" target="_blank" rel="noreferrer"&gt;sambiyal/CVE-2018-10933-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nikhil1232/LibSSH-Authentication-Bypass" target="_blank" rel="noreferrer"&gt;nikhil1232/LibSSH-Authentication-Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Kurlee/LibSSH-exploit" target="_blank" rel="noreferrer"&gt;Kurlee/LibSSH-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/crispy-peppers/Libssh-server-CVE-2018-10933" target="_blank" rel="noreferrer"&gt;crispy-peppers/Libssh-server-CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/youkergav/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;youkergav/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kristyna-mlcakova/CVE-2018-10933" target="_blank" rel="noreferrer"&gt;kristyna-mlcakova/CVE-2018-10933&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10936
 &lt;div id="cve-2018-10936" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10936" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-10936" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-10936&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-10949
 &lt;div id="cve-2018-10949" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-10949" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the &amp;quot;HTTP 404 - account is not active&amp;quot; and &amp;quot;HTTP 401 - must authenticate&amp;quot; errors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2018-10949" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2018-10949&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1111
 &lt;div id="cve-2018-1111" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1111" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-1111" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-1111&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kkirsche/CVE-2018-1111" target="_blank" rel="noreferrer"&gt;kkirsche/CVE-2018-1111&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11235
 &lt;div id="cve-2018-11235" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11235" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs &amp;quot;git clone --recurse-submodules&amp;quot; because submodule &amp;quot;names&amp;quot; are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with &amp;quot;../&amp;quot; in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Rogdham/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;Rogdham/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vmotos/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;vmotos/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Choihosu/cve-2018-11235" target="_blank" rel="noreferrer"&gt;Choihosu/cve-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CHYbeta/CVE-2018-11235-DEMO" target="_blank" rel="noreferrer"&gt;CHYbeta/CVE-2018-11235-DEMO&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Kiss-sh0t/CVE-2018-11235-poc" target="_blank" rel="noreferrer"&gt;Kiss-sh0t/CVE-2018-11235-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/H0K5/clone_and_pwn" target="_blank" rel="noreferrer"&gt;H0K5/clone_and_pwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ygouzerh/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;ygouzerh/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qweraqq/CVE-2018-11235-Git-Submodule-CE" target="_blank" rel="noreferrer"&gt;qweraqq/CVE-2018-11235-Git-Submodule-CE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jhswartz/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;jhswartz/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AnonymKing/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;AnonymKing/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/morhax/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;morhax/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cchang27/CVE-2018-11235-test" target="_blank" rel="noreferrer"&gt;cchang27/CVE-2018-11235-test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nthuong95/CVE-2018-11235" target="_blank" rel="noreferrer"&gt;nthuong95/CVE-2018-11235&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11236
 &lt;div id="cve-2018-11236" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11236" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/evilmiracle/CVE-2018-11236" target="_blank" rel="noreferrer"&gt;evilmiracle/CVE-2018-11236&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11311
 &lt;div id="cve-2018-11311" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11311" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EmreOvunc/mySCADA-myPRO-7-Hardcoded-FTP-Username-and-Password" target="_blank" rel="noreferrer"&gt;EmreOvunc/mySCADA-myPRO-7-Hardcoded-FTP-Username-and-Password&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1133
 &lt;div id="cve-2018-1133" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1133" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/darrynten/MoodleExploit" target="_blank" rel="noreferrer"&gt;darrynten/MoodleExploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/M4LV0/MOODLE-3.X-Remote-Code-Execution" target="_blank" rel="noreferrer"&gt;M4LV0/MOODLE-3.X-Remote-Code-Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11450
 &lt;div id="cve-2018-11450" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11450" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3 and newer are not affected.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/LucvanDonk/Siemens-Siemens-PLM-Software-TEAMCENTER-Reflected-Cross-Site-Scripting-XSS-vulnerability" target="_blank" rel="noreferrer"&gt;LucvanDonk/Siemens-Siemens-PLM-Software-TEAMCENTER-Reflected-Cross-Site-Scripting-XSS-vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11510
 &lt;div id="cve-2018-11510" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11510" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mefulton/CVE-2018-11510" target="_blank" rel="noreferrer"&gt;mefulton/CVE-2018-11510&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11517
 &lt;div id="cve-2018-11517" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11517" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&amp;amp;rq=0 requests to TCP port 11010.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EmreOvunc/mySCADA-myPRO-7-projectID-Disclosure" target="_blank" rel="noreferrer"&gt;EmreOvunc/mySCADA-myPRO-7-projectID-Disclosure&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11564
 &lt;div id="cve-2018-11564" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11564" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to &amp;quot;/storage/poc.svg&amp;quot; that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GeunSam2/CVE-2018-11564" target="_blank" rel="noreferrer"&gt;GeunSam2/CVE-2018-11564&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11631
 &lt;div id="cve-2018-11631" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11631" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notifications via crafted Bluetooth Low Energy (BLE) traffic.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xMagass/bandexploit" target="_blank" rel="noreferrer"&gt;xMagass/bandexploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11686
 &lt;div id="cve-2018-11686" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11686" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2018-11686" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2018-11686&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11759
 &lt;div id="cve-2018-11759" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11759" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/immunIT/CVE-2018-11759" target="_blank" rel="noreferrer"&gt;immunIT/CVE-2018-11759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jul10l1r4/Identificador-CVE-2018-11759" target="_blank" rel="noreferrer"&gt;Jul10l1r4/Identificador-CVE-2018-11759&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11761
 &lt;div id="cve-2018-11761" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11761" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/CVE-2018-11761" target="_blank" rel="noreferrer"&gt;brianwrf/CVE-2018-11761&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11770
 &lt;div id="cve-2018-11770" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11770" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests to submit jobs via spark-submit. However, the REST API does not use this or any other authentication mechanism, and this is not adequately documented. In this case, a user would be able to run a driver program without authenticating, but not launch executors, using the REST API. This REST API is also used by Mesos, when set up to run in cluster mode (i.e., when also running MesosClusterDispatcher), for job submission. Future versions of Spark will improve documentation on these points, and prohibit setting 'spark.authenticate.secret' when running the REST APIs, to make this clear. Future versions will also disable the REST API by default in the standalone master by changing the default value of 'spark.master.rest.enabled' to 'false'.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ivanitlearning/CVE-2018-11770" target="_blank" rel="noreferrer"&gt;ivanitlearning/CVE-2018-11770&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11776
 &lt;div id="cve-2018-11776" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11776" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/trbpnd/CVE-2018-11776" target="_blank" rel="noreferrer"&gt;trbpnd/CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xfox64x/CVE-2018-11776" target="_blank" rel="noreferrer"&gt;xfox64x/CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiguangin/CVE-2018-11776" target="_blank" rel="noreferrer"&gt;jiguangin/CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hook-s3c/CVE-2018-11776-Python-PoC" target="_blank" rel="noreferrer"&gt;hook-s3c/CVE-2018-11776-Python-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mazen160/struts-pwn_CVE-2018-11776" target="_blank" rel="noreferrer"&gt;mazen160/struts-pwn_CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bhdresh/CVE-2018-11776" target="_blank" rel="noreferrer"&gt;bhdresh/CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-11776" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ekultek/Strutter" target="_blank" rel="noreferrer"&gt;Ekultek/Strutter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tuxotron/cve-2018-11776-docker" target="_blank" rel="noreferrer"&gt;tuxotron/cve-2018-11776-docker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/S2-057-CVE-2018-11776" target="_blank" rel="noreferrer"&gt;brianwrf/S2-057-CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/649/Apache-Struts-Shodan-Exploit" target="_blank" rel="noreferrer"&gt;649/Apache-Struts-Shodan-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jezzus/CVE-2018-11776-Python-PoC" target="_blank" rel="noreferrer"&gt;jezzus/CVE-2018-11776-Python-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-11776" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776" target="_blank" rel="noreferrer"&gt;OzNetNerd/apche-struts-vuln-demo-cve-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cucadili/CVE-2018-11776" target="_blank" rel="noreferrer"&gt;cucadili/CVE-2018-11776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LightC0der/Apache-Struts-0Day-Exploit" target="_blank" rel="noreferrer"&gt;LightC0der/Apache-Struts-0Day-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11788
 &lt;div id="cve-2018-11788" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11788" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache Karaf provides a features deployer, which allows users to &amp;quot;hot deploy&amp;quot; a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/CVE-2018-11788" target="_blank" rel="noreferrer"&gt;brianwrf/CVE-2018-11788&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-11882
 &lt;div id="cve-2018-11882" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-11882" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jguard01/cve-2018-11882" target="_blank" rel="noreferrer"&gt;jguard01/cve-2018-11882&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12018
 &lt;div id="cve-2018-12018" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12018" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/k3v142/CVE-2018-12018" target="_blank" rel="noreferrer"&gt;k3v142/CVE-2018-12018&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12031
 &lt;div id="cve-2018-12031" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12031" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EmreOvunc/Eaton-Intelligent-Power-Manager-Local-File-Inclusion" target="_blank" rel="noreferrer"&gt;EmreOvunc/Eaton-Intelligent-Power-Manager-Local-File-Inclusion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12038
 &lt;div id="cve-2018-12038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gdraperi/remote-bitlocker-encryption-report" target="_blank" rel="noreferrer"&gt;gdraperi/remote-bitlocker-encryption-report&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12086
 &lt;div id="cve-2018-12086" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12086" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kevinherron/stack-overflow-poc" target="_blank" rel="noreferrer"&gt;kevinherron/stack-overflow-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1235
 &lt;div id="cve-2018-1235" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1235" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AbsoZed/CVE-2018-1235" target="_blank" rel="noreferrer"&gt;AbsoZed/CVE-2018-1235&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12386
 &lt;div id="cve-2018-12386" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12386" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR &amp;lt; 60.2.2 and Firefox &amp;lt; 62.0.3.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Hydra3evil/cve-2018-12386" target="_blank" rel="noreferrer"&gt;Hydra3evil/cve-2018-12386&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xLyte/cve-2018-12386" target="_blank" rel="noreferrer"&gt;0xLyte/cve-2018-12386&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12418
 &lt;div id="cve-2018-12418" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12418" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-12418" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-12418&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12463
 &lt;div id="cve-2018-12463" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12463" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-12463" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-12463&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12533
 &lt;div id="cve-2018-12533" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12533" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheKalin/CVE-2018-12533" target="_blank" rel="noreferrer"&gt;TheKalin/CVE-2018-12533&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12537
 &lt;div id="cve-2018-12537" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12537" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-12537" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-12537&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12540
 &lt;div id="cve-2018-12540" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12540" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-12540" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-12540&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1259
 &lt;div id="cve-2018-1259" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1259" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-1259" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-1259&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12596
 &lt;div id="cve-2018-12596" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12596" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the &amp;quot;activateuser.aspx&amp;quot; page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-12596" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-12596&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12597
 &lt;div id="cve-2018-12597" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12597" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-12597" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-12597&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12598
 &lt;div id="cve-2018-12598" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12598" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-12598" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-12598&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12613
 &lt;div id="cve-2018-12613" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12613" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the &amp;quot;$cfg['AllowArbitraryServer'] = true&amp;quot; case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the &amp;quot;$cfg['ServerDefault'] = 0&amp;quot; case (which bypasses the login requirement and runs the vulnerable code without any authentication).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2018-12613" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2018-12613&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ivanitlearning/CVE-2018-12613" target="_blank" rel="noreferrer"&gt;ivanitlearning/CVE-2018-12613&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eastmountyxz/CVE-2018-12613-phpMyAdmin" target="_blank" rel="noreferrer"&gt;eastmountyxz/CVE-2018-12613-phpMyAdmin&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1270
 &lt;div id="cve-2018-1270" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1270" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CaledoniaProject/CVE-2018-1270" target="_blank" rel="noreferrer"&gt;CaledoniaProject/CVE-2018-1270&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/genxor/CVE-2018-1270_EXP" target="_blank" rel="noreferrer"&gt;genxor/CVE-2018-1270_EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-1270" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-1270&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Venscor/CVE-2018-1270" target="_blank" rel="noreferrer"&gt;Venscor/CVE-2018-1270&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1273
 &lt;div id="cve-2018-1273" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1273" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-1273" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-1273&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wearearima/poc-cve-2018-1273" target="_blank" rel="noreferrer"&gt;wearearima/poc-cve-2018-1273&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/webr0ck/poc-cve-2018-1273" target="_blank" rel="noreferrer"&gt;webr0ck/poc-cve-2018-1273&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-1273" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-1273&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/cve-2018-1273" target="_blank" rel="noreferrer"&gt;jas502n/cve-2018-1273&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12798
 &lt;div id="cve-2018-12798" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12798" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sharmasandeepkr/cve-2018-12798" target="_blank" rel="noreferrer"&gt;sharmasandeepkr/cve-2018-12798&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1288
 &lt;div id="cve-2018-1288" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1288" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/joegallagher4/CVE-2018-1288-" target="_blank" rel="noreferrer"&gt;joegallagher4/CVE-2018-1288-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12895
 &lt;div id="cve-2018-12895" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12895" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bloom-ux/cve-2018-12895-hotfix" target="_blank" rel="noreferrer"&gt;bloom-ux/cve-2018-12895-hotfix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-12914
 &lt;div id="cve-2018-12914" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-12914" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2018-12914" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2018-12914&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1297
 &lt;div id="cve-2018-1297" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1297" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2018-1297" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2018-1297&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1304
 &lt;div id="cve-2018-1304" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1304" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The URL pattern of &amp;quot;&amp;quot; (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-1304" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-1304&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thariyarox/tomcat_CVE-2018-1304_testing" target="_blank" rel="noreferrer"&gt;thariyarox/tomcat_CVE-2018-1304_testing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1305
 &lt;div id="cve-2018-1305" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1305" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2018-1305" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2018-1305&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1306
 &lt;div id="cve-2018-1306" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1306" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JJSO12/Apache-Pluto-3.0.0--CVE-2018-1306" target="_blank" rel="noreferrer"&gt;JJSO12/Apache-Pluto-3.0.0&amp;ndash;CVE-2018-1306&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1313
 &lt;div id="cve-2018-1313" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1313" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-1313" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-1313&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1324
 &lt;div id="cve-2018-1324" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1324" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-1324" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-1324&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13257
 &lt;div id="cve-2018-13257" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13257" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gluxon/CVE-2018-13257" target="_blank" rel="noreferrer"&gt;gluxon/CVE-2018-13257&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1327
 &lt;div id="cve-2018-1327" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1327" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here http://struts.apache.org/plugins/rest/#custom-contenttypehandlers. Another option is to implement a custom XML handler based on the Jackson XML handler from the Apache Struts 2.5.16.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/S2-056-XStream" target="_blank" rel="noreferrer"&gt;RealBearcat/S2-056-XStream&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13341
 &lt;div id="cve-2018-13341" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13341" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/axcheron/crestron_getsudopwd" target="_blank" rel="noreferrer"&gt;axcheron/crestron_getsudopwd&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1335
 &lt;div id="cve-2018-1335" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1335" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SkyBlueEternal/CVE-2018-1335-EXP-GUI" target="_blank" rel="noreferrer"&gt;SkyBlueEternal/CVE-2018-1335-EXP-GUI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GEIGEI123/CVE-2018-1335-Python3" target="_blank" rel="noreferrer"&gt;GEIGEI123/CVE-2018-1335-Python3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13379
 &lt;div id="cve-2018-13379" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13379" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An Improper Limitation of a Pathname to a Restricted Directory (&amp;quot;Path Traversal&amp;quot;) in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/milo2012/CVE-2018-13379" target="_blank" rel="noreferrer"&gt;milo2012/CVE-2018-13379&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jpiechowka/at-doom-fortigate" target="_blank" rel="noreferrer"&gt;jpiechowka/at-doom-fortigate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xHunter/FortiOS-Credentials-Disclosure" target="_blank" rel="noreferrer"&gt;0xHunter/FortiOS-Credentials-Disclosure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Blazz3/cve2018-13379-nmap-script" target="_blank" rel="noreferrer"&gt;Blazz3/cve2018-13379-nmap-script&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13382
 &lt;div id="cve-2018-13382" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13382" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/milo2012/CVE-2018-13382" target="_blank" rel="noreferrer"&gt;milo2012/CVE-2018-13382&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13410
 &lt;div id="cve-2018-13410" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13410" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shinecome/zip" target="_blank" rel="noreferrer"&gt;shinecome/zip&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13784
 &lt;div id="cve-2018-13784" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13784" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ambionics/prestashop-exploits" target="_blank" rel="noreferrer"&gt;ambionics/prestashop-exploits&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-13864
 &lt;div id="cve-2018-13864" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-13864" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially crafted HTTP requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-13864" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-13864&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14
 &lt;div id="cve-2018-14" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lckJack/legacySymfony" target="_blank" rel="noreferrer"&gt;lckJack/legacySymfony&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14083
 &lt;div id="cve-2018-14083" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14083" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for the inc/user.ini file, leading to discovery of a password hash.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pudding2/CVE-2018-14083" target="_blank" rel="noreferrer"&gt;pudding2/CVE-2018-14083&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14442
 &lt;div id="cve-2018-14442" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14442" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/payatu/CVE-2018-14442" target="_blank" rel="noreferrer"&gt;payatu/CVE-2018-14442&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sharmasandeepkr/PS-2018-002---CVE-2018-14442" target="_blank" rel="noreferrer"&gt;sharmasandeepkr/PS-2018-002&amp;mdash;CVE-2018-14442&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14634
 &lt;div id="cve-2018-14634" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14634" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/luan0ap/cve-2018-14634" target="_blank" rel="noreferrer"&gt;luan0ap/cve-2018-14634&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14665
 &lt;div id="cve-2018-14665" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14665" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-14665" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-14665&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bolonobolo/CVE-2018-14665" target="_blank" rel="noreferrer"&gt;bolonobolo/CVE-2018-14665&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/samueldustin/cve-2018-14665" target="_blank" rel="noreferrer"&gt;samueldustin/cve-2018-14665&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14667
 &lt;div id="cve-2018-14667" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14667" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nareshmail/cve-2018-14667" target="_blank" rel="noreferrer"&gt;nareshmail/cve-2018-14667&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zeroto01/CVE-2018-14667" target="_blank" rel="noreferrer"&gt;zeroto01/CVE-2018-14667&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r00t4dm/CVE-2018-14667" target="_blank" rel="noreferrer"&gt;r00t4dm/CVE-2018-14667&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/syriusbughunt/CVE-2018-14667" target="_blank" rel="noreferrer"&gt;syriusbughunt/CVE-2018-14667&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/quandqn/cve-2018-14667" target="_blank" rel="noreferrer"&gt;quandqn/cve-2018-14667&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Venscor/CVE-2018-14667-poc" target="_blank" rel="noreferrer"&gt;Venscor/CVE-2018-14667-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14714
 &lt;div id="cve-2018-14714" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14714" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the &amp;quot;load_script&amp;quot; URL parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tin-z/CVE-2018-14714-POC" target="_blank" rel="noreferrer"&gt;tin-z/CVE-2018-14714-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14729
 &lt;div id="cve-2018-14729" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14729" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FoolMitAh/CVE-2018-14729" target="_blank" rel="noreferrer"&gt;FoolMitAh/CVE-2018-14729&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14772
 &lt;div id="cve-2018-14772" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14772" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/spencerdodd/CVE-2018-14772" target="_blank" rel="noreferrer"&gt;spencerdodd/CVE-2018-14772&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-14847
 &lt;div id="cve-2018-14847" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-14847" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BasuCert/WinboxPoC" target="_blank" rel="noreferrer"&gt;BasuCert/WinboxPoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/msterusky/WinboxExploit" target="_blank" rel="noreferrer"&gt;msterusky/WinboxExploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/syrex1013/MikroRoot" target="_blank" rel="noreferrer"&gt;syrex1013/MikroRoot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-14847" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-14847&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/th3f3n1x87/winboxPOC" target="_blank" rel="noreferrer"&gt;th3f3n1x87/winboxPOC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/krnull/mikrotik-beast" target="_blank" rel="noreferrer"&gt;krnull/mikrotik-beast&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sinichi449/Python-MikrotikLoginExploit" target="_blank" rel="noreferrer"&gt;sinichi449/Python-MikrotikLoginExploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yukar1z0e/CVE-2018-14847" target="_blank" rel="noreferrer"&gt;yukar1z0e/CVE-2018-14847&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15131
 &lt;div id="cve-2018-15131" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15131" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2018-15131" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2018-15131&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15133
 &lt;div id="cve-2018-15133" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15133" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kozmic/laravel-poc-CVE-2018-15133" target="_blank" rel="noreferrer"&gt;kozmic/laravel-poc-CVE-2018-15133&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sKirua/Laravel-CVE-2018-15133" target="_blank" rel="noreferrer"&gt;sKirua/Laravel-CVE-2018-15133&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Prabesh01/Laravel-PHP-Unit-RCE-Auto-shell-uploader" target="_blank" rel="noreferrer"&gt;Prabesh01/Laravel-PHP-Unit-RCE-Auto-shell-uploader&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iansangaji/laravel-rce-cve-2018-15133" target="_blank" rel="noreferrer"&gt;iansangaji/laravel-rce-cve-2018-15133&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15365
 &lt;div id="cve-2018-15365" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15365" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nixwizard/CVE-2018-15365" target="_blank" rel="noreferrer"&gt;nixwizard/CVE-2018-15365&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15473
 &lt;div id="cve-2018-15473" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15473" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/trimstray/massh-enum" target="_blank" rel="noreferrer"&gt;trimstray/massh-enum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gbonacini/opensshenum" target="_blank" rel="noreferrer"&gt;gbonacini/opensshenum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Rhynorater/CVE-2018-15473-Exploit" target="_blank" rel="noreferrer"&gt;Rhynorater/CVE-2018-15473-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/epi052/cve-2018-15473" target="_blank" rel="noreferrer"&gt;epi052/cve-2018-15473&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pyperanger/CVE-2018-15473_exploit" target="_blank" rel="noreferrer"&gt;pyperanger/CVE-2018-15473_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/CVE-2018-15473" target="_blank" rel="noreferrer"&gt;r3dxpl0it/CVE-2018-15473&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JoeBlackSecurity/CrappyCode" target="_blank" rel="noreferrer"&gt;JoeBlackSecurity/CrappyCode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JoeBlackSecurity/SSHUsernameBruter-SSHUB" target="_blank" rel="noreferrer"&gt;JoeBlackSecurity/SSHUsernameBruter-SSHUB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-15473" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-15473&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LINYIKAI/CVE-2018-15473-exp" target="_blank" rel="noreferrer"&gt;LINYIKAI/CVE-2018-15473-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/securemode/enumpossible" target="_blank" rel="noreferrer"&gt;securemode/enumpossible&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/trickster1103/-" target="_blank" rel="noreferrer"&gt;trickster1103/-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NHPT/SSH-account-enumeration-verification-script" target="_blank" rel="noreferrer"&gt;NHPT/SSH-account-enumeration-verification-script&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CaioCGH/EP4-redes" target="_blank" rel="noreferrer"&gt;CaioCGH/EP4-redes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15499
 &lt;div id="cve-2018-15499" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15499" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condition and BSoD on Windows) by not checking that user-mode memory is available right before writing to it. A check is only performed at the beginning of a long subroutine.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DownWithUp/CVE-2018-15499" target="_blank" rel="noreferrer"&gt;DownWithUp/CVE-2018-15499&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15686
 &lt;div id="cve-2018-15686" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15686" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hpcprofessional/remediate_cesa_2019_2091" target="_blank" rel="noreferrer"&gt;hpcprofessional/remediate_cesa_2019_2091&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15727
 &lt;div id="cve-2018-15727" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15727" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid &amp;quot;remember me&amp;quot; cookie knowing only a username of an LDAP or OAuth user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/u238/grafana-CVE-2018-15727" target="_blank" rel="noreferrer"&gt;u238/grafana-CVE-2018-15727&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15832
 &lt;div id="cve-2018-15832" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15832" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JacksonKuo/Ubisoft-Uplay-Desktop-Client-63.0.5699.0" target="_blank" rel="noreferrer"&gt;JacksonKuo/Ubisoft-Uplay-Desktop-Client-63.0.5699.0&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15877
 &lt;div id="cve-2018-15877" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15877" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&amp;amp;tab=activity_tools request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-15877" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-15877&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15912
 &lt;div id="cve-2018-15912" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15912" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can install or remove arbitrary packages and package repositories potentially containing hooks with arbitrary code, which will automatically be run as root, or remove packages vital to the system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/coderobe/CVE-2018-15912-PoC" target="_blank" rel="noreferrer"&gt;coderobe/CVE-2018-15912-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15961
 &lt;div id="cve-2018-15961" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15961" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vah13/CVE-2018-15961" target="_blank" rel="noreferrer"&gt;vah13/CVE-2018-15961&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-15961" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-15961&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15968
 &lt;div id="cve-2018-15968" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15968" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sharmasandeepkr/cve-2018-15968" target="_blank" rel="noreferrer"&gt;sharmasandeepkr/cve-2018-15968&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-15982
 &lt;div id="cve-2018-15982" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-15982" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FlatL1neAPT/CVE-2018-15982" target="_blank" rel="noreferrer"&gt;FlatL1neAPT/CVE-2018-15982&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AirEvan/CVE-2018-15982_PoC" target="_blank" rel="noreferrer"&gt;AirEvan/CVE-2018-15982_PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/CVE-2018-15982_EXP" target="_blank" rel="noreferrer"&gt;Ridter/CVE-2018-15982_EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kphongagsorn/adobe-flash-cve2018-15982" target="_blank" rel="noreferrer"&gt;kphongagsorn/adobe-flash-cve2018-15982&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-15982_EXP_IE" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-15982_EXP_IE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/scanfsec/CVE-2018-15982" target="_blank" rel="noreferrer"&gt;scanfsec/CVE-2018-15982&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SyFi/CVE-2018-15982" target="_blank" rel="noreferrer"&gt;SyFi/CVE-2018-15982&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/create12138/CVE-2018-15982" target="_blank" rel="noreferrer"&gt;create12138/CVE-2018-15982&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16119
 &lt;div id="cve-2018-16119" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16119" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hdbreaker/CVE-2018-16119" target="_blank" rel="noreferrer"&gt;hdbreaker/CVE-2018-16119&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16135
 &lt;div id="cve-2018-16135" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16135" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0d3G33k/CVE-2018-16135" target="_blank" rel="noreferrer"&gt;c0d3G33k/CVE-2018-16135&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16156
 &lt;div id="cve-2018-16156" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16156" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported function named ChangeUninstallString. The default install does not contain this library and therefore if any DLL with that name exists in any directory listed in the PATH variable, it can be used to escalate to SYSTEM level privilege.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2018-16156-Exploit" target="_blank" rel="noreferrer"&gt;securifera/CVE-2018-16156-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16283
 &lt;div id="cve-2018-16283" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16283" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-16283" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-16283&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16323
 &lt;div id="cve-2018-16323" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16323" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ttffdd/XBadManners" target="_blank" rel="noreferrer"&gt;ttffdd/XBadManners&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16341
 &lt;div id="cve-2018-16341" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16341" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2018-16341" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2018-16341&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16370
 &lt;div id="cve-2018-16370" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16370" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&amp;amp;m=Setting&amp;amp;a=upgrade by placing a .php file in a ZIP archive.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/snappyJack/CVE-2018-16370" target="_blank" rel="noreferrer"&gt;snappyJack/CVE-2018-16370&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16373
 &lt;div id="cve-2018-16373" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16373" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/snappyJack/CVE-2018-16373" target="_blank" rel="noreferrer"&gt;snappyJack/CVE-2018-16373&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16447
 &lt;div id="cve-2018-16447" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16447" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16447" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16447&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16509
 &lt;div id="cve-2018-16509" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16509" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect &amp;quot;restoration of privilege&amp;quot; checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the &amp;quot;pipe&amp;quot; instruction.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/farisv/PIL-RCE-Ghostscript-CVE-2018-16509" target="_blank" rel="noreferrer"&gt;farisv/PIL-RCE-Ghostscript-CVE-2018-16509&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-16509" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-16509&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-16509" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-16509&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rhpco/CVE-2018-16509" target="_blank" rel="noreferrer"&gt;rhpco/CVE-2018-16509&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16623
 &lt;div id="cve-2018-16623" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16623" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the &amp;quot;Site options&amp;quot; in the admin panel dashboard dropdown.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16623" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16623&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16624
 &lt;div id="cve-2018-16624" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16624" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16624" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16624&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16625
 &lt;div id="cve-2018-16625" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16625" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16625" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16625&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16626
 &lt;div id="cve-2018-16626" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16626" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16626" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16626&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16627
 &lt;div id="cve-2018-16627" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16627" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
panel/login in Kirby v2.5.12 allows Host header injection via the &amp;quot;forget password&amp;quot; feature.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16627" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16627&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16628
 &lt;div id="cve-2018-16628" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16628" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
panel/login in Kirby v2.5.12 allows XSS via a blog name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16628" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16628&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16629
 &lt;div id="cve-2018-16629" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16629" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16629" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16629&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16630
 &lt;div id="cve-2018-16630" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16630" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kirby v2.5.12 allows XSS by using the &amp;quot;site files&amp;quot; Add option to upload an SVG file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16630" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16630&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16631
 &lt;div id="cve-2018-16631" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16631" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16631" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16631&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16632
 &lt;div id="cve-2018-16632" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16632" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&amp;amp;_popup=1 title parameter at admin/blog/blogpost/add/.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16632" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16632&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16633
 &lt;div id="cve-2018-16633" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16633" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&amp;amp;page= page title.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16633" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16633&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16634
 &lt;div id="cve-2018-16634" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16634" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16634" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16634&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16635
 &lt;div id="cve-2018-16635" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16635" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16635" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16635&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16636
 &lt;div id="cve-2018-16636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16636" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16636&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16637
 &lt;div id="cve-2018-16637" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16637" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16637" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16637&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16638
 &lt;div id="cve-2018-16638" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16638" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16638" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16638&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16639
 &lt;div id="cve-2018-16639" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16639" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-16639" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-16639&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16706
 &lt;div id="cve-2018-16706" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16706" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Nurdilin/CVE-2018-16706" target="_blank" rel="noreferrer"&gt;Nurdilin/CVE-2018-16706&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16711
 &lt;div id="cve-2018-16711" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16711" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for input.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DownWithUp/CVE-2018-16711" target="_blank" rel="noreferrer"&gt;DownWithUp/CVE-2018-16711&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16712
 &lt;div id="cve-2018-16712" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16712" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send a specially crafted IOCTL 0x9C406104 to read physical memory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DownWithUp/CVE-2018-16712" target="_blank" rel="noreferrer"&gt;DownWithUp/CVE-2018-16712&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16713
 &lt;div id="cve-2018-16713" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16713" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DownWithUp/CVE-2018-16713" target="_blank" rel="noreferrer"&gt;DownWithUp/CVE-2018-16713&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16763
 &lt;div id="cve-2018-16763" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16763" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dinhbaouit/CVE-2018-16763" target="_blank" rel="noreferrer"&gt;dinhbaouit/CVE-2018-16763&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SalimAlk/CVE-2018-16763-" target="_blank" rel="noreferrer"&gt;SalimAlk/CVE-2018-16763-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16854
 &lt;div id="cve-2018-16854" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16854" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/danielthatcher/moodle-login-csrf" target="_blank" rel="noreferrer"&gt;danielthatcher/moodle-login-csrf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16858
 &lt;div id="cve-2018-16858" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16858" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/4nimanegra/libreofficeExploit1" target="_blank" rel="noreferrer"&gt;4nimanegra/libreofficeExploit1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/k0o97/detect-cve-2018-16858" target="_blank" rel="noreferrer"&gt;k0o97/detect-cve-2018-16858&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16875
 &lt;div id="cve-2018-16875" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16875" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alexzorin/poc-cve-2018-16875" target="_blank" rel="noreferrer"&gt;alexzorin/poc-cve-2018-16875&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16890
 &lt;div id="cve-2018-16890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zjw88282740/CVE-2018-16890" target="_blank" rel="noreferrer"&gt;zjw88282740/CVE-2018-16890&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-16987
 &lt;div id="cve-2018-16987" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-16987" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gquere/CVE-2018-16987" target="_blank" rel="noreferrer"&gt;gquere/CVE-2018-16987&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17024
 &lt;div id="cve-2018-17024" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17024" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-17024" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-17024&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17144
 &lt;div id="cve-2018-17144" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17144" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/iioch/ban-exploitable-bitcoin-nodes" target="_blank" rel="noreferrer"&gt;iioch/ban-exploitable-bitcoin-nodes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hikame/CVE-2018-17144_POC" target="_blank" rel="noreferrer"&gt;hikame/CVE-2018-17144_POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17182
 &lt;div id="cve-2018-17182" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17182" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-17182" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-17182&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-17182" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-17182&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/vmacache_CVE-2018-17182" target="_blank" rel="noreferrer"&gt;denmilu/vmacache_CVE-2018-17182&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17207
 &lt;div id="cve-2018-17207" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17207" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-17207" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-17207&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17246
 &lt;div id="cve-2018-17246" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17246" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2018-17246" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2018-17246&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17300
 &lt;div id="cve-2018-17300" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17300" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-17300" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-17300&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17301
 &lt;div id="cve-2018-17301" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17301" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-17301" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-17301&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17302
 &lt;div id="cve-2018-17302" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17302" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-17302" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-17302&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17418
 &lt;div id="cve-2018-17418" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17418" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AlwaysHereFight/monstra_cms-3.0.4--getshell" target="_blank" rel="noreferrer"&gt;AlwaysHereFight/monstra_cms-3.0.4&amp;ndash;getshell&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17431
 &lt;div id="cve-2018-17431" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17431" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Fadavvi/CVE-2018-17431-PoC" target="_blank" rel="noreferrer"&gt;Fadavvi/CVE-2018-17431-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17456
 &lt;div id="cve-2018-17456" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17456" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive &amp;quot;git clone&amp;quot; of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SeahunOh/CVE-2018-17456" target="_blank" rel="noreferrer"&gt;SeahunOh/CVE-2018-17456&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/matlink/CVE-2018-17456" target="_blank" rel="noreferrer"&gt;matlink/CVE-2018-17456&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/799600966/CVE-2018-17456" target="_blank" rel="noreferrer"&gt;799600966/CVE-2018-17456&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AnonymKing/CVE-2018-17456" target="_blank" rel="noreferrer"&gt;AnonymKing/CVE-2018-17456&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17873
 &lt;div id="cve-2018-17873" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17873" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Luct0r/CVE-2018-17873" target="_blank" rel="noreferrer"&gt;Luct0r/CVE-2018-17873&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-17961
 &lt;div id="cve-2018-17961" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-17961" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/matlink/CVE-2018-17961" target="_blank" rel="noreferrer"&gt;matlink/CVE-2018-17961&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-18026
 &lt;div id="cve-2018-18026" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-18026" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DownWithUp/CVE-2018-18026" target="_blank" rel="noreferrer"&gt;DownWithUp/CVE-2018-18026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-18368
 &lt;div id="cve-2018-18368" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-18368" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DimopoulosElias/SEPM-EoP" target="_blank" rel="noreferrer"&gt;DimopoulosElias/SEPM-EoP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-18387
 &lt;div id="cve-2018-18387" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-18387" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheeBlind/CVE-2018-18387" target="_blank" rel="noreferrer"&gt;TheeBlind/CVE-2018-18387&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-18500
 &lt;div id="cve-2018-18500" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-18500" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird &amp;lt; 60.5, Firefox ESR &amp;lt; 60.5, and Firefox &amp;lt; 65.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sophoslabs/CVE-2018-18500" target="_blank" rel="noreferrer"&gt;sophoslabs/CVE-2018-18500&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-18714
 &lt;div id="cve-2018-18714" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-18714" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This can lead to denial of service (DoS) or code execution with root privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DownWithUp/CVE-2018-18714" target="_blank" rel="noreferrer"&gt;DownWithUp/CVE-2018-18714&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-18852
 &lt;div id="cve-2018-18852" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-18852" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hook-s3c/CVE-2018-18852" target="_blank" rel="noreferrer"&gt;hook-s3c/CVE-2018-18852&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andripwn/CVE-2018-18852" target="_blank" rel="noreferrer"&gt;andripwn/CVE-2018-18852&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19126
 &lt;div id="cve-2018-19126" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19126" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/farisv/PrestaShop-CVE-2018-19126" target="_blank" rel="noreferrer"&gt;farisv/PrestaShop-CVE-2018-19126&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19127
 &lt;div id="cve-2018-19127" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19127" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a &amp;quot;&amp;lt;?php function &amp;quot; substring.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ab1gale/phpcms-2008-CVE-2018-19127" target="_blank" rel="noreferrer"&gt;ab1gale/phpcms-2008-CVE-2018-19127&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19131
 &lt;div id="cve-2018-19131" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19131" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JonathanWilbur/CVE-2018-19131" target="_blank" rel="noreferrer"&gt;JonathanWilbur/CVE-2018-19131&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19207
 &lt;div id="cve-2018-19207" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19207" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb-&amp;gt;prepare() input is mishandled, as exploited in the wild in November 2018.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aeroot/WP-GDPR-Compliance-Plugin-Exploit" target="_blank" rel="noreferrer"&gt;aeroot/WP-GDPR-Compliance-Plugin-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-19207" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-19207&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19276
 &lt;div id="cve-2018-19276" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19276" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2018-19276" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2018-19276&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19320
 &lt;div id="cve-2018-19320" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19320" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fdiskyou/CVE-2018-19320" target="_blank" rel="noreferrer"&gt;fdiskyou/CVE-2018-19320&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19466
 &lt;div id="cve-2018-19466" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19466" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MauroEldritch/lempo" target="_blank" rel="noreferrer"&gt;MauroEldritch/lempo&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19487
 &lt;div id="cve-2018-19487" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19487" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Antho59/wp-jobhunt-exploit" target="_blank" rel="noreferrer"&gt;Antho59/wp-jobhunt-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19506
 &lt;div id="cve-2018-19506" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19506" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19506" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19506&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19507
 &lt;div id="cve-2018-19507" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19507" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&amp;amp;action=array URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19507" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19507&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19508
 &lt;div id="cve-2018-19508" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19508" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&amp;amp;subdir=userfiles/images/flags/ URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19508" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19508&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19518
 &lt;div id="cve-2018-19518" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19518" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a &amp;quot;-oProxyCommand&amp;quot; argument.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ensimag-security/CVE-2018-19518" target="_blank" rel="noreferrer"&gt;ensimag-security/CVE-2018-19518&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19537
 &lt;div id="cve-2018-19537" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19537" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JackDoan/TP-Link-ArcherC5-RCE" target="_blank" rel="noreferrer"&gt;JackDoan/TP-Link-ArcherC5-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19592
 &lt;div id="cve-2018-19592" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19592" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The &amp;quot;CLink4Service&amp;quot; service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BradyDonovan/CVE-2018-19592" target="_blank" rel="noreferrer"&gt;BradyDonovan/CVE-2018-19592&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19596
 &lt;div id="cve-2018-19596" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19596" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19596" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19596&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19597
 &lt;div id="cve-2018-19597" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19597" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19597" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19597&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19598
 &lt;div id="cve-2018-19598" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19598" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19598" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19598&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19599
 &lt;div id="cve-2018-19599" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19599" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&amp;amp;path=uploads/ URI. NOTE: this is a discontinued product.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19599" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19599&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19600
 &lt;div id="cve-2018-19600" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19600" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Rhymix CMS 1.9.8.1 allows XSS via an index.php?module=admin&amp;amp;act=dispModuleAdminFileBox SVG upload.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19600" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19600&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19601
 &lt;div id="cve-2018-19601" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19601" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&amp;amp;act=dispModuleAdminFileBox SVG upload.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19601" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19601&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19788
 &lt;div id="cve-2018-19788" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19788" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AbsoZed/CVE-2018-19788" target="_blank" rel="noreferrer"&gt;AbsoZed/CVE-2018-19788&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/d4gh0s7/CVE-2018-19788" target="_blank" rel="noreferrer"&gt;d4gh0s7/CVE-2018-19788&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ekultek/PoC" target="_blank" rel="noreferrer"&gt;Ekultek/PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jhlongjr/CVE-2018-19788" target="_blank" rel="noreferrer"&gt;jhlongjr/CVE-2018-19788&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19844
 &lt;div id="cve-2018-19844" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19844" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related issue to CVE-2018-10319.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19844" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19844&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19845
 &lt;div id="cve-2018-19845" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19845" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php &amp;quot;post-menu&amp;quot; parameter, a related issue to CVE-2018-16325.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19845" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19845&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19864
 &lt;div id="cve-2018-19864" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19864" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pwnhacker0x18/CVE-2018-19864" target="_blank" rel="noreferrer"&gt;pwnhacker0x18/CVE-2018-19864&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19901
 &lt;div id="cve-2018-19901" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19901" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ &amp;quot;article_title&amp;quot; parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19901" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19901&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19902
 &lt;div id="cve-2018-19902" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19902" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article &amp;quot;keyword&amp;quot; parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19902" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19902&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19903
 &lt;div id="cve-2018-19903" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19903" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&amp;amp;type=Page title field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19903" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19903&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19904
 &lt;div id="cve-2018-19904" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19904" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&amp;amp;type=Page &amp;quot;body&amp;quot; field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19904" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19904&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19905
 &lt;div id="cve-2018-19905" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19905" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19905" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19905&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19906
 &lt;div id="cve-2018-19906" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19906" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19906" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19906&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19911
 &lt;div id="cve-2018-19911" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19911" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as demonstrated by an api/system?calc URI. This can also be exploited via CSRF. Alternatively, the default password of works for the freeswitch account can sometimes be used.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/iSafeBlue/freeswitch_rce" target="_blank" rel="noreferrer"&gt;iSafeBlue/freeswitch_rce&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19918
 &lt;div id="cve-2018-19918" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19918" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19918" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19918&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-19919
 &lt;div id="cve-2018-19919" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-19919" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload attribute of an SVG element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2018-19919" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2018-19919&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-1999002
 &lt;div id="cve-2018-1999002" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-1999002" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wetw0rk/Exploit-Development" target="_blank" rel="noreferrer"&gt;wetw0rk/Exploit-Development&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xtavian/CVE-2019-1003000-and-CVE-2018-1999002-Pre-Auth-RCE-Jenkins" target="_blank" rel="noreferrer"&gt;0xtavian/CVE-2019-1003000-and-CVE-2018-1999002-Pre-Auth-RCE-Jenkins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x6b7966/CVE-2018-1999002" target="_blank" rel="noreferrer"&gt;0x6b7966/CVE-2018-1999002&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20062
 &lt;div id="cve-2018-20062" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20062" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&amp;amp;filter=phpinfo&amp;amp;data=1 query string.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/NS-Sp4ce/thinkphp5.XRce" target="_blank" rel="noreferrer"&gt;NS-Sp4ce/thinkphp5.XRce&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20162
 &lt;div id="cve-2018-20162" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20162" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/stigtsp/CVE-2018-20162-digi-lr54-restricted-shell-escape" target="_blank" rel="noreferrer"&gt;stigtsp/CVE-2018-20162-digi-lr54-restricted-shell-escape&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20165
 &lt;div id="cve-2018-20165" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20165" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hect0rS/Reflected-XSS-on-Opentext-Portal-v7.4.4" target="_blank" rel="noreferrer"&gt;hect0rS/Reflected-XSS-on-Opentext-Portal-v7.4.4&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2019
 &lt;div id="cve-2018-2019" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2019" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 155265.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/attakercyebr/hack4lx_CVE-2018-2019" target="_blank" rel="noreferrer"&gt;attakercyebr/hack4lx_CVE-2018-2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20250
 &lt;div id="cve-2018-20250" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20250" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/WyAtu/CVE-2018-20250" target="_blank" rel="noreferrer"&gt;WyAtu/CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/QAX-A-Team/CVE-2018-20250" target="_blank" rel="noreferrer"&gt;QAX-A-Team/CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nmweizi/CVE-2018-20250-poc-winrar" target="_blank" rel="noreferrer"&gt;nmweizi/CVE-2018-20250-poc-winrar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/blunden/UNACEV2.DLL-CVE-2018-20250" target="_blank" rel="noreferrer"&gt;blunden/UNACEV2.DLL-CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/easis/CVE-2018-20250-WinRAR-ACE" target="_blank" rel="noreferrer"&gt;easis/CVE-2018-20250-WinRAR-ACE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/STP5940/CVE-2018-20250" target="_blank" rel="noreferrer"&gt;STP5940/CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/n4r1b/WinAce-POC" target="_blank" rel="noreferrer"&gt;n4r1b/WinAce-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/technicaldada/hack-winrar" target="_blank" rel="noreferrer"&gt;technicaldada/hack-winrar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ektoplasma/ezwinrar" target="_blank" rel="noreferrer"&gt;Ektoplasma/ezwinrar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/arkangel-dev/CVE-2018-20250-WINRAR-ACE-GUI" target="_blank" rel="noreferrer"&gt;arkangel-dev/CVE-2018-20250-WINRAR-ACE-GUI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AeolusTF/CVE-2018-20250" target="_blank" rel="noreferrer"&gt;AeolusTF/CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/joydragon/Detect-CVE-2018-20250" target="_blank" rel="noreferrer"&gt;joydragon/Detect-CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DANIELVISPOBLOG/WinRar_ACE_exploit_CVE-2018-20250" target="_blank" rel="noreferrer"&gt;DANIELVISPOBLOG/WinRar_ACE_exploit_CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-20250" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/930201676/CVE-2018-20250" target="_blank" rel="noreferrer"&gt;930201676/CVE-2018-20250&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eastmountyxz/CVE-2018-20250-WinRAR" target="_blank" rel="noreferrer"&gt;eastmountyxz/CVE-2018-20250-WinRAR&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20343
 &lt;div id="cve-2018-20343" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20343" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a special map file to execute arbitrary code when the map file is loaded.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Alexandre-Bartel/CVE-2018-20343" target="_blank" rel="noreferrer"&gt;Alexandre-Bartel/CVE-2018-20343&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20434
 &lt;div id="cve-2018-20434" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20434" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&amp;amp;format=text&amp;amp;type=snmpwalk&amp;amp;hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mhaskar/CVE-2018-20434" target="_blank" rel="noreferrer"&gt;mhaskar/CVE-2018-20434&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20555
 &lt;div id="cve-2018-20555" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20555" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fs0c131y/CVE-2018-20555" target="_blank" rel="noreferrer"&gt;fs0c131y/CVE-2018-20555&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20580
 &lt;div id="cve-2018-20580" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20580" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gscamelo/CVE-2018-20580" target="_blank" rel="noreferrer"&gt;gscamelo/CVE-2018-20580&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-20718
 &lt;div id="cve-2018-20718" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-20718" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a &amp;quot;public link&amp;quot; of a file, or access to any unprivileged user account for creation of such a link.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/us3r777/CVE-2018-20718" target="_blank" rel="noreferrer"&gt;us3r777/CVE-2018-20718&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2380
 &lt;div id="cve-2018-2380" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2380" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing &amp;quot;traverse to parent directory&amp;quot; are passed through to the file APIs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/erpscanteam/CVE-2018-2380" target="_blank" rel="noreferrer"&gt;erpscanteam/CVE-2018-2380&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2628
 &lt;div id="cve-2018-2628" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2628" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/forlin/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;forlin/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shengqi158/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;shengqi158/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/skydarker/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;skydarker/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiansiting/weblogic-cve-2018-2628" target="_blank" rel="noreferrer"&gt;jiansiting/weblogic-cve-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zjxzjx/CVE-2018-2628-detect" target="_blank" rel="noreferrer"&gt;zjxzjx/CVE-2018-2628-detect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aedoo/CVE-2018-2628-MultiThreading" target="_blank" rel="noreferrer"&gt;aedoo/CVE-2018-2628-MultiThreading&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hawk-tiger/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;hawk-tiger/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/9uest/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;9uest/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Shadowshusky/CVE-2018-2628all" target="_blank" rel="noreferrer"&gt;Shadowshusky/CVE-2018-2628all&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shaoshore/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;shaoshore/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tdy218/ysoserial-cve-2018-2628" target="_blank" rel="noreferrer"&gt;tdy218/ysoserial-cve-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s0wr0b1ndef/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;s0wr0b1ndef/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wrysunny/cve-2018-2628" target="_blank" rel="noreferrer"&gt;wrysunny/cve-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/stevenlinfeng/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;stevenlinfeng/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Nervous/WebLogic-RCE-exploit" target="_blank" rel="noreferrer"&gt;Nervous/WebLogic-RCE-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Lighird/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;Lighird/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xMJ/CVE-2018-2628" target="_blank" rel="noreferrer"&gt;0xMJ/CVE-2018-2628&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xn0ne/weblogicScanner" target="_blank" rel="noreferrer"&gt;0xn0ne/weblogicScanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2636
 &lt;div id="cve-2018-2636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). Supported versions that are affected are 2.7, 2.8 and 2.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/erpscanteam/CVE-2018-2636" target="_blank" rel="noreferrer"&gt;erpscanteam/CVE-2018-2636&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cymmetria/micros_honeypot" target="_blank" rel="noreferrer"&gt;Cymmetria/micros_honeypot&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2844
 &lt;div id="cve-2018-2844" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2844" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/renorobert/virtualbox-cve-2018-2844" target="_blank" rel="noreferrer"&gt;renorobert/virtualbox-cve-2018-2844&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2879
 &lt;div id="cve-2018-2879" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2879" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. Note: Please refer to Doc ID &amp;lt;a href=&amp;quot;http://support.oracle.com/CSP/main/article?cmd=show&amp;amp;type=NOT&amp;amp;id=2386496.1&amp;quot;&amp;gt;My Oracle Support Note 2386496.1 for instructions on how to address this issue. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MostafaSoliman/Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit" target="_blank" rel="noreferrer"&gt;MostafaSoliman/Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AymanElSherif/oracle-oam-authentication-bypas-exploit" target="_blank" rel="noreferrer"&gt;AymanElSherif/oracle-oam-authentication-bypas-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/redtimmy/OAMBuster" target="_blank" rel="noreferrer"&gt;redtimmy/OAMBuster&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2893
 &lt;div id="cve-2018-2893" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2893" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/anbai-inc/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;anbai-inc/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ryanInf/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;ryanInf/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bigsizeme/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;bigsizeme/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qianl0ng/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;qianl0ng/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2018-2893" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2018-2893&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-2894
 &lt;div id="cve-2018-2894" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-2894" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/111ddea/cve-2018-2894" target="_blank" rel="noreferrer"&gt;111ddea/cve-2018-2894&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LandGrey/CVE-2018-2894" target="_blank" rel="noreferrer"&gt;LandGrey/CVE-2018-2894&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-2894" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-2894&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3191
 &lt;div id="cve-2018-3191" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3191" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/arongmh/CVE-2018-3191" target="_blank" rel="noreferrer"&gt;arongmh/CVE-2018-3191&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2018-3191" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2018-3191&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Libraggbond/CVE-2018-3191" target="_blank" rel="noreferrer"&gt;Libraggbond/CVE-2018-3191&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-3191" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-3191&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mackleadmire/CVE-2018-3191-Rce-Exploit" target="_blank" rel="noreferrer"&gt;mackleadmire/CVE-2018-3191-Rce-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3245
 &lt;div id="cve-2018-3245" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3245" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2018-3245" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2018-3245&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-3245" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-3245&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2018-3245" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2018-3245&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3252
 &lt;div id="cve-2018-3252" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3252" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2018-3252" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2018-3252&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b1ueb0y/CVE-2018-3252" target="_blank" rel="noreferrer"&gt;b1ueb0y/CVE-2018-3252&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pyn3rd/CVE-2018-3252" target="_blank" rel="noreferrer"&gt;pyn3rd/CVE-2018-3252&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3260
 &lt;div id="cve-2018-3260" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3260" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ionescu007/SpecuCheck" target="_blank" rel="noreferrer"&gt;ionescu007/SpecuCheck&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3295
 &lt;div id="cve-2018-3295" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3295" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ndureiss/e1000_vulnerability_exploit" target="_blank" rel="noreferrer"&gt;ndureiss/e1000_vulnerability_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3608
 &lt;div id="cve-2018-3608" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3608" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ZhiyuanWang-Chengdu-Qihoo360/Trend_Micro_POC" target="_blank" rel="noreferrer"&gt;ZhiyuanWang-Chengdu-Qihoo360/Trend_Micro_POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3639
 &lt;div id="cve-2018-3639" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3639" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tyhicks/ssbd-tools" target="_blank" rel="noreferrer"&gt;tyhicks/ssbd-tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/malindarathnayake/Intel-CVE-2018-3639-Mitigation_RegistryUpdate" target="_blank" rel="noreferrer"&gt;malindarathnayake/Intel-CVE-2018-3639-Mitigation_RegistryUpdate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mmxsrup/CVE-2018-3639" target="_blank" rel="noreferrer"&gt;mmxsrup/CVE-2018-3639&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Shuiliusheng/CVE-2018-3639-specter-v4-" target="_blank" rel="noreferrer"&gt;Shuiliusheng/CVE-2018-3639-specter-v4-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3760
 &lt;div id="cve-2018-3760" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3760" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CVE-2018-3760" target="_blank" rel="noreferrer"&gt;mpgn/CVE-2018-3760&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3783
 &lt;div id="cve-2018-3783" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3783" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A privilege escalation detected in flintcms versions &amp;lt;= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nisaruj/nosqli-flintcms" target="_blank" rel="noreferrer"&gt;nisaruj/nosqli-flintcms&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3810
 &lt;div id="cve-2018-3810" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3810" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lucad93/CVE-2018-3810" target="_blank" rel="noreferrer"&gt;lucad93/CVE-2018-3810&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-3810" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-3810&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-3811
 &lt;div id="cve-2018-3811" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-3811" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST[&amp;quot;oId&amp;quot;] variable before passing it as input into the SQL query.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-3811" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-3811&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4013
 &lt;div id="cve-2018-4013" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4013" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DoubleMice/cve-2018-4013" target="_blank" rel="noreferrer"&gt;DoubleMice/cve-2018-4013&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/RTSPServer-Code-Execution-Vulnerability" target="_blank" rel="noreferrer"&gt;r3dxpl0it/RTSPServer-Code-Execution-Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4087
 &lt;div id="cve-2018-4087" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4087" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the &amp;quot;Core Bluetooth&amp;quot; component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rani-i/bluetoothdPoC" target="_blank" rel="noreferrer"&gt;rani-i/bluetoothdPoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MTJailed/UnjailMe" target="_blank" rel="noreferrer"&gt;MTJailed/UnjailMe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/joedaguy/Exploit11.2" target="_blank" rel="noreferrer"&gt;joedaguy/Exploit11.2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4110
 &lt;div id="cve-2018-4110" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4110" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the &amp;quot;Web App&amp;quot; component. It allows remote attackers to bypass intended restrictions on cookie persistence.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bencompton/ios11-cookie-set-expire-issue" target="_blank" rel="noreferrer"&gt;bencompton/ios11-cookie-set-expire-issue&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4121
 &lt;div id="cve-2018-4121" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4121" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the &amp;quot;WebKit&amp;quot; component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FSecureLABS/CVE-2018-4121" target="_blank" rel="noreferrer"&gt;FSecureLABS/CVE-2018-4121&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-4121" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-4121&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jezzus/CVE-2018-4121" target="_blank" rel="noreferrer"&gt;jezzus/CVE-2018-4121&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4124
 &lt;div id="cve-2018-4124" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4124" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the &amp;quot;CoreText&amp;quot; component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a crafted string containing a certain Telugu character.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ZecOps/TELUGU_CVE-2018-4124_POC" target="_blank" rel="noreferrer"&gt;ZecOps/TELUGU_CVE-2018-4124_POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4150
 &lt;div id="cve-2018-4150" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4150" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Jailbreaks/CVE-2018-4150" target="_blank" rel="noreferrer"&gt;Jailbreaks/CVE-2018-4150&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RPwnage/LovelySn0w" target="_blank" rel="noreferrer"&gt;RPwnage/LovelySn0w&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/littlelailo/incomplete-exploit-for-CVE-2018-4150-bpf-filter-poc-" target="_blank" rel="noreferrer"&gt;littlelailo/incomplete-exploit-for-CVE-2018-4150-bpf-filter-poc-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4185
 &lt;div id="cve-2018-4185" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4185" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/x18-leak" target="_blank" rel="noreferrer"&gt;bazad/x18-leak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4193
 &lt;div id="cve-2018-4193" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4193" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the &amp;quot;Windows Server&amp;quot; component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Synacktiv-contrib/CVE-2018-4193" target="_blank" rel="noreferrer"&gt;Synacktiv-contrib/CVE-2018-4193&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4233
 &lt;div id="cve-2018-4233" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4233" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the &amp;quot;WebKit&amp;quot; component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/saelo/cve-2018-4233" target="_blank" rel="noreferrer"&gt;saelo/cve-2018-4233&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4241
 &lt;div id="cve-2018-4241" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4241" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. A buffer overflow in mptcp_usr_connectx allows attackers to execute arbitrary code in a privileged context via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0neday/multi_path" target="_blank" rel="noreferrer"&gt;0neday/multi_path&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4242
 &lt;div id="cve-2018-4242" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4242" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the &amp;quot;Hypervisor&amp;quot; component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/yeonnic/Look-at-The-XNU-Through-A-Tube-CVE-2018-4242-Write-up-Translation-" target="_blank" rel="noreferrer"&gt;yeonnic/Look-at-The-XNU-Through-A-Tube-CVE-2018-4242-Write-up-Translation-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4243
 &lt;div id="cve-2018-4243" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4243" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. A buffer overflow in getvolattrlist allows attackers to execute arbitrary code in a privileged context via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Jailbreaks/empty_list" target="_blank" rel="noreferrer"&gt;Jailbreaks/empty_list&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4248
 &lt;div id="cve-2018-4248" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4248" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/xpc-string-leak" target="_blank" rel="noreferrer"&gt;bazad/xpc-string-leak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4280
 &lt;div id="cve-2018-4280" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4280" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/launchd-portrep" target="_blank" rel="noreferrer"&gt;bazad/launchd-portrep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/blanket" target="_blank" rel="noreferrer"&gt;bazad/blanket&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4327
 &lt;div id="cve-2018-4327" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4327" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/omerporze/brokentooth" target="_blank" rel="noreferrer"&gt;omerporze/brokentooth&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/harryanon/POC-CVE-2018-4327-and-CVE-2018-4330" target="_blank" rel="noreferrer"&gt;harryanon/POC-CVE-2018-4327-and-CVE-2018-4330&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4330
 &lt;div id="cve-2018-4330" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4330" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/omerporze/toothfairy" target="_blank" rel="noreferrer"&gt;omerporze/toothfairy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4331
 &lt;div id="cve-2018-4331" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4331" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/gsscred-race" target="_blank" rel="noreferrer"&gt;bazad/gsscred-race&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4343
 &lt;div id="cve-2018-4343" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4343" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/gsscred-move-uaf" target="_blank" rel="noreferrer"&gt;bazad/gsscred-move-uaf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4407
 &lt;div id="cve-2018-4407" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4407" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Pa55w0rd/check_icmp_dos" target="_blank" rel="noreferrer"&gt;Pa55w0rd/check_icmp_dos&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/unixpickle/cve-2018-4407" target="_blank" rel="noreferrer"&gt;unixpickle/cve-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s2339956/check_icmp_dos-CVE-2018-4407-" target="_blank" rel="noreferrer"&gt;s2339956/check_icmp_dos-CVE-2018-4407-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/farisv/AppleDOS" target="_blank" rel="noreferrer"&gt;farisv/AppleDOS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/WyAtu/CVE-2018-4407" target="_blank" rel="noreferrer"&gt;WyAtu/CVE-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zteeed/CVE-2018-4407-IOS" target="_blank" rel="noreferrer"&gt;zteeed/CVE-2018-4407-IOS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SamDecrock/node-cve-2018-4407" target="_blank" rel="noreferrer"&gt;SamDecrock/node-cve-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/CVE-2018-4407" target="_blank" rel="noreferrer"&gt;r3dxpl0it/CVE-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lucagiovagnoli/CVE-2018-4407" target="_blank" rel="noreferrer"&gt;lucagiovagnoli/CVE-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/anonymouz4/Apple-Remote-Crash-Tool-CVE-2018-4407" target="_blank" rel="noreferrer"&gt;anonymouz4/Apple-Remote-Crash-Tool-CVE-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/soccercab/wifi" target="_blank" rel="noreferrer"&gt;soccercab/wifi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zeng9t/CVE-2018-4407-iOS-exploit" target="_blank" rel="noreferrer"&gt;zeng9t/CVE-2018-4407-iOS-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/5431/CVE-2018-4407" target="_blank" rel="noreferrer"&gt;5431/CVE-2018-4407&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwnhacker0x18/iOS-Kernel-Crash" target="_blank" rel="noreferrer"&gt;pwnhacker0x18/iOS-Kernel-Crash&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4411
 &lt;div id="cve-2018-4411" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4411" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lilang-wu/POC-CVE-2018-4411" target="_blank" rel="noreferrer"&gt;lilang-wu/POC-CVE-2018-4411&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4415
 &lt;div id="cve-2018-4415" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4415" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/T1V0h/CVE-2018-4415" target="_blank" rel="noreferrer"&gt;T1V0h/CVE-2018-4415&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4431
 &lt;div id="cve-2018-4431" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4431" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ktiOSz/PoC_iOS12" target="_blank" rel="noreferrer"&gt;ktiOSz/PoC_iOS12&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4441
 &lt;div id="cve-2018-4441" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4441" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Cryptogenic/PS4-6.20-WebKit-Code-Execution-Exploit" target="_blank" rel="noreferrer"&gt;Cryptogenic/PS4-6.20-WebKit-Code-Execution-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4878
 &lt;div id="cve-2018-4878" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4878" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ydl555/CVE-2018-4878-" target="_blank" rel="noreferrer"&gt;ydl555/CVE-2018-4878-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mdsecactivebreach/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;mdsecactivebreach/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hybridious/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;hybridious/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vysecurity/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;vysecurity/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/anbai-inc/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;anbai-inc/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sch01ar/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;Sch01ar/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SyFi/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;SyFi/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ydl555/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;ydl555/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/B0fH/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;B0fH/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Yable/CVE-2018-4878" target="_blank" rel="noreferrer"&gt;Yable/CVE-2018-4878&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HuanWoWeiLan/SoftwareSystemSecurity-2019" target="_blank" rel="noreferrer"&gt;HuanWoWeiLan/SoftwareSystemSecurity-2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-4901
 &lt;div id="cve-2018-4901" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-4901" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the document identity representation. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bigric3/CVE-2018-4901" target="_blank" rel="noreferrer"&gt;bigric3/CVE-2018-4901&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5234
 &lt;div id="cve-2018-5234" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5234" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is execution of arbitrary commands on the host system via vulnerable software.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/embedi/ble_norton_core" target="_blank" rel="noreferrer"&gt;embedi/ble_norton_core&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5711
 &lt;div id="cve-2018-5711" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5711" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/huzhenghui/Test-7-2-0-PHP-CVE-2018-5711" target="_blank" rel="noreferrer"&gt;huzhenghui/Test-7-2-0-PHP-CVE-2018-5711&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/huzhenghui/Test-7-2-1-PHP-CVE-2018-5711" target="_blank" rel="noreferrer"&gt;huzhenghui/Test-7-2-1-PHP-CVE-2018-5711&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5724
 &lt;div id="cve-2018-5724" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5724" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gusrmsdlrh/Python-CVE-Code" target="_blank" rel="noreferrer"&gt;gusrmsdlrh/Python-CVE-Code&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5728
 &lt;div id="cve-2018-5728" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5728" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus request, as demonstrated by the Latitude/Longitude of the ship, or satellite details.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ezelf/seatel_terminals" target="_blank" rel="noreferrer"&gt;ezelf/seatel_terminals&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5740
 &lt;div id="cve-2018-5740" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5740" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
&amp;quot;deny-answer-aliases&amp;quot; is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0-&amp;gt;9.8.8, 9.9.0-&amp;gt;9.9.13, 9.10.0-&amp;gt;9.10.8, 9.11.0-&amp;gt;9.11.4, 9.12.0-&amp;gt;9.12.2, 9.13.0-&amp;gt;9.13.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sischkg/cve-2018-5740" target="_blank" rel="noreferrer"&gt;sischkg/cve-2018-5740&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5951
 &lt;div id="cve-2018-5951" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5951" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Mikrotik RouterOS. Crafting a packet that has a size of 1 byte and sending it to an IPv6 address of a RouterOS box with IP Protocol 97 will cause RouterOS to reboot imminently. All versions of RouterOS that supports EoIPv6 are vulnerable to this attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Nat-Lab/CVE-2018-5951" target="_blank" rel="noreferrer"&gt;Nat-Lab/CVE-2018-5951&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-5955
 &lt;div id="cve-2018-5955" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-5955" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cisp/GitStackRCE" target="_blank" rel="noreferrer"&gt;cisp/GitStackRCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/YagamiiLight/Cerberus" target="_blank" rel="noreferrer"&gt;YagamiiLight/Cerberus&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6242
 &lt;div id="cve-2018-6242" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6242" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DavidBuchanan314/NXLoader" target="_blank" rel="noreferrer"&gt;DavidBuchanan314/NXLoader&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/reswitched/rcm-modchips" target="_blank" rel="noreferrer"&gt;reswitched/rcm-modchips&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/switchjs/fusho" target="_blank" rel="noreferrer"&gt;switchjs/fusho&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6376
 &lt;div id="cve-2018-6376" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6376" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-6376" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-6376&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6389
 &lt;div id="cve-2018-6389" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6389" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/yolabingo/wordpress-fix-cve-2018-6389" target="_blank" rel="noreferrer"&gt;yolabingo/wordpress-fix-cve-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/WazeHell/CVE-2018-6389" target="_blank" rel="noreferrer"&gt;WazeHell/CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rastating/modsecurity-cve-2018-6389" target="_blank" rel="noreferrer"&gt;rastating/modsecurity-cve-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-6389" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JulienGadanho/cve-2018-6389-php-patcher" target="_blank" rel="noreferrer"&gt;JulienGadanho/cve-2018-6389-php-patcher&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dsfau/wordpress-CVE-2018-6389" target="_blank" rel="noreferrer"&gt;dsfau/wordpress-CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jetserver/CVE-2018-6389-FIX" target="_blank" rel="noreferrer"&gt;Jetserver/CVE-2018-6389-FIX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thechrono13/PoC---CVE-2018-6389" target="_blank" rel="noreferrer"&gt;thechrono13/PoC&amp;mdash;CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BlackRouter/cve-2018-6389" target="_blank" rel="noreferrer"&gt;BlackRouter/cve-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/alessiogilardi/PoC---CVE-2018-6389" target="_blank" rel="noreferrer"&gt;alessiogilardi/PoC&amp;mdash;CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JavierOlmedo/wordpress-cve-2018-6389" target="_blank" rel="noreferrer"&gt;JavierOlmedo/wordpress-cve-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/m3ssap0/wordpress_cve-2018-6389" target="_blank" rel="noreferrer"&gt;m3ssap0/wordpress_cve-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s0md3v/Shiva" target="_blank" rel="noreferrer"&gt;s0md3v/Shiva&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mudhappy/Wordpress-Hack-CVE-2018-6389" target="_blank" rel="noreferrer"&gt;mudhappy/Wordpress-Hack-CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/armaanpathan12345/WP-DOS-Exploit-CVE-2018-6389" target="_blank" rel="noreferrer"&gt;armaanpathan12345/WP-DOS-Exploit-CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ItinerisLtd/trellis-cve-2018-6389" target="_blank" rel="noreferrer"&gt;ItinerisLtd/trellis-cve-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Zazzzles/Wordpress-DOS" target="_blank" rel="noreferrer"&gt;Zazzzles/Wordpress-DOS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fakedob/tvsz" target="_blank" rel="noreferrer"&gt;fakedob/tvsz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/heisenberg-official/Wordpress-DOS-Attack-CVE-2018-6389" target="_blank" rel="noreferrer"&gt;heisenberg-official/Wordpress-DOS-Attack-CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2018-6389" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2018-6389&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6396
 &lt;div id="cve-2018-6396" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6396" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JavierOlmedo/joomla-cve-2018-6396" target="_blank" rel="noreferrer"&gt;JavierOlmedo/joomla-cve-2018-6396&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6407
 &lt;div id="cve-2018-6407" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6407" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dreadlocked/ConceptronicIPCam_MultipleVulnerabilities" target="_blank" rel="noreferrer"&gt;dreadlocked/ConceptronicIPCam_MultipleVulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6479
 &lt;div id="cve-2018-6479" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6479" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to the / URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dreadlocked/netwave-dosvulnerability" target="_blank" rel="noreferrer"&gt;dreadlocked/netwave-dosvulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6518
 &lt;div id="cve-2018-6518" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6518" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&amp;amp;type=step3 request to /adminzone/index.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/faizzaidi/Composr-CMS-10.0.13-Cross-Site-Scripting-XSS" target="_blank" rel="noreferrer"&gt;faizzaidi/Composr-CMS-10.0.13-Cross-Site-Scripting-XSS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6546
 &lt;div id="cve-2018-6546" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6546" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2018-6546-Exploit" target="_blank" rel="noreferrer"&gt;securifera/CVE-2018-6546-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/YanZiShuang/CVE-2018-6546" target="_blank" rel="noreferrer"&gt;YanZiShuang/CVE-2018-6546&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6574
 &lt;div id="cve-2018-6574" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6574" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow &amp;quot;go get&amp;quot; remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/acole76/cve-2018-6574" target="_blank" rel="noreferrer"&gt;acole76/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/neargle/CVE-2018-6574-POC" target="_blank" rel="noreferrer"&gt;neargle/CVE-2018-6574-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/willbo4r/go-get-rce" target="_blank" rel="noreferrer"&gt;willbo4r/go-get-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ahmetmanga/go-get-rce" target="_blank" rel="noreferrer"&gt;ahmetmanga/go-get-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ahmetmanga/cve-2018-6574" target="_blank" rel="noreferrer"&gt;ahmetmanga/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/michiiii/go-get-exploit" target="_blank" rel="noreferrer"&gt;michiiii/go-get-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kenprice/cve-2018-6574" target="_blank" rel="noreferrer"&gt;kenprice/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/redirected/cve-2018-6574" target="_blank" rel="noreferrer"&gt;redirected/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/20matan/CVE-2018-6574-POC" target="_blank" rel="noreferrer"&gt;20matan/CVE-2018-6574-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zur250/Zur-Go-GET-RCE-Solution" target="_blank" rel="noreferrer"&gt;zur250/Zur-Go-GET-RCE-Solution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mekhalleh/cve-2018-6574" target="_blank" rel="noreferrer"&gt;mekhalleh/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/veter069/go-get-rce" target="_blank" rel="noreferrer"&gt;veter069/go-get-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/duckzsc2/CVE-2018-6574-POC" target="_blank" rel="noreferrer"&gt;duckzsc2/CVE-2018-6574-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ivnnn1/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;ivnnn1/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dollyptm/cve-2018-6574" target="_blank" rel="noreferrer"&gt;dollyptm/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qweraqq/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;qweraqq/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/d4rkshell/go-get-rce" target="_blank" rel="noreferrer"&gt;d4rkshell/go-get-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chaosura/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;chaosura/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/french560/ptl6574" target="_blank" rel="noreferrer"&gt;french560/ptl6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/InfoSecJack/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;InfoSecJack/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/asavior2/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;asavior2/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/drset/golang" target="_blank" rel="noreferrer"&gt;drset/golang&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/frozenkp/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;frozenkp/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kev-ho/cve-2018-6574-payload" target="_blank" rel="noreferrer"&gt;kev-ho/cve-2018-6574-payload&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sdosis/cve-2018-6574" target="_blank" rel="noreferrer"&gt;sdosis/cve-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/No1zy/CVE-2018-6574-PoC" target="_blank" rel="noreferrer"&gt;No1zy/CVE-2018-6574-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nthuong95/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;nthuong95/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AdriVillaB/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;AdriVillaB/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yitingfan/CVE-2018-6574_demo" target="_blank" rel="noreferrer"&gt;yitingfan/CVE-2018-6574_demo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mhamed366/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;mhamed366/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Eugene24/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;Eugene24/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/coblax/CVE-2018-6574" target="_blank" rel="noreferrer"&gt;coblax/CVE-2018-6574&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6622
 &lt;div id="cve-2018-6622" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6622" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 sleep and can clear TPM 2.0. It allows local users to overwrite static PCRs of TPM and neutralize the security features of it, such as seal/unseal and remote attestation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kkamagui/napper-for-tpm" target="_blank" rel="noreferrer"&gt;kkamagui/napper-for-tpm&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6643
 &lt;div id="cve-2018-6643" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6643" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/undefinedmode/CVE-2018-6643" target="_blank" rel="noreferrer"&gt;undefinedmode/CVE-2018-6643&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6789
 &lt;div id="cve-2018-6789" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6789" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0llision/exim-vuln-poc" target="_blank" rel="noreferrer"&gt;c0llision/exim-vuln-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/beraphin/CVE-2018-6789" target="_blank" rel="noreferrer"&gt;beraphin/CVE-2018-6789&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/synacktiv/Exim-CVE-2018-6789" target="_blank" rel="noreferrer"&gt;synacktiv/Exim-CVE-2018-6789&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/martinclauss/exim-rce-cve-2018-6789" target="_blank" rel="noreferrer"&gt;martinclauss/exim-rce-cve-2018-6789&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6791
 &lt;div id="cve-2018-6791" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6791" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is &amp;quot;$(touch b)&amp;quot; -- this will create a file called b in the home folder.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rarar0/KDE_Vuln" target="_blank" rel="noreferrer"&gt;rarar0/KDE_Vuln&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6890
 &lt;div id="cve-2018-6890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pradeepjairamani/WolfCMS-XSS-POC" target="_blank" rel="noreferrer"&gt;pradeepjairamani/WolfCMS-XSS-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6892
 &lt;div id="cve-2018-6892" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6892" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the &amp;quot;CloudMe Sync&amp;quot; client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/manojcode/CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass" target="_blank" rel="noreferrer"&gt;manojcode/CloudMe-Sync-1.10.9&amp;mdash;Buffer-Overflow-SEH-DEP-Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/manojcode/-Win10-x64-CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass" target="_blank" rel="noreferrer"&gt;manojcode/-Win10-x64-CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6905
 &lt;div id="cve-2018-6905" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6905" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pradeepjairamani/TYPO3-XSS-POC" target="_blank" rel="noreferrer"&gt;pradeepjairamani/TYPO3-XSS-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6961
 &lt;div id="cve-2018-6961" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6961" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bokanrb/CVE-2018-6961" target="_blank" rel="noreferrer"&gt;bokanrb/CVE-2018-6961&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/CVE-2018-6961" target="_blank" rel="noreferrer"&gt;r3dxpl0it/CVE-2018-6961&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-6981
 &lt;div id="cve-2018-6981" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-6981" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to execute code on the host.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/heaphopopotamus/vmxnet3Hunter" target="_blank" rel="noreferrer"&gt;heaphopopotamus/vmxnet3Hunter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7171
 &lt;div id="cve-2018-7171" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7171" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mechanico/sharingIsCaring" target="_blank" rel="noreferrer"&gt;mechanico/sharingIsCaring&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7197
 &lt;div id="cve-2018-7197" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7197" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Alyssa-o-Herrera/CVE-2018-7197" target="_blank" rel="noreferrer"&gt;Alyssa-o-Herrera/CVE-2018-7197&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7211
 &lt;div id="cve-2018-7211" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7211" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c3r34lk1ll3r/CVE-2018-7211-PoC" target="_blank" rel="noreferrer"&gt;c3r34lk1ll3r/CVE-2018-7211-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7249
 &lt;div id="cve-2018-7249" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7249" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 can cause a race condition that leads to a use-after-free. When exploited, an unprivileged attacker can run arbitrary code in the kernel.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Elvin9/NotSecDrv" target="_blank" rel="noreferrer"&gt;Elvin9/NotSecDrv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7250
 &lt;div id="cve-2018-7250" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7250" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Elvin9/SecDrvPoolLeak" target="_blank" rel="noreferrer"&gt;Elvin9/SecDrvPoolLeak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7284
 &lt;div id="cve-2018-7284" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7284" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not limit the number of headers it processed, despite having a fixed limit of 32. If more than 32 Accept headers were present, the code would write outside of its memory and cause a crash.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Rodrigo-D/astDoS" target="_blank" rel="noreferrer"&gt;Rodrigo-D/astDoS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7422
 &lt;div id="cve-2018-7422" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7422" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2018-7422" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2018-7422&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7489
 &lt;div id="cve-2018-7489" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7489" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-7489" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-7489&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7600
 &lt;div id="cve-2018-7600" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7600" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/g0rx/CVE-2018-7600-Drupal-RCE" target="_blank" rel="noreferrer"&gt;g0rx/CVE-2018-7600-Drupal-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/a2u/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;a2u/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dreadlocked/Drupalgeddon2" target="_blank" rel="noreferrer"&gt;dreadlocked/Drupalgeddon2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;knqyf263/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE" target="_blank" rel="noreferrer"&gt;dr-iman/CVE-2018-7600-Drupal-0day-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jirojo2/drupalgeddon2" target="_blank" rel="noreferrer"&gt;jirojo2/drupalgeddon2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dwisiswant0/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;dwisiswant0/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thehappydinoa/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;thehappydinoa/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sl4cky/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;sl4cky/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sl4cky/CVE-2018-7600-Masschecker" target="_blank" rel="noreferrer"&gt;sl4cky/CVE-2018-7600-Masschecker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FireFart/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;FireFart/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pimps/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;pimps/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lorddemon/drupalgeddon2" target="_blank" rel="noreferrer"&gt;lorddemon/drupalgeddon2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sch01ar/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;Sch01ar/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Hestat/drupal-check" target="_blank" rel="noreferrer"&gt;Hestat/drupal-check&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fyraiga/CVE-2018-7600-drupalgeddon2-scanner" target="_blank" rel="noreferrer"&gt;fyraiga/CVE-2018-7600-drupalgeddon2-scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Damian972/drupalgeddon-2" target="_blank" rel="noreferrer"&gt;Damian972/drupalgeddon-2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jyozi/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;Jyozi/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/happynote3966/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;happynote3966/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shellord/CVE-2018-7600-Drupal-RCE" target="_blank" rel="noreferrer"&gt;shellord/CVE-2018-7600-Drupal-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/CVE-2018-7600" target="_blank" rel="noreferrer"&gt;r3dxpl0it/CVE-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-7600" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-7600&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/neal1991/drupalgeddon2" target="_blank" rel="noreferrer"&gt;neal1991/drupalgeddon2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/drugeddon/drupal-exploit" target="_blank" rel="noreferrer"&gt;drugeddon/drupal-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shellord/Drupalgeddon-Mass-Exploiter" target="_blank" rel="noreferrer"&gt;shellord/Drupalgeddon-Mass-Exploiter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP" target="_blank" rel="noreferrer"&gt;zhzyker/CVE-2018-7600-Drupal-POC-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rabbitmask/CVE-2018-7600-Drupal7" target="_blank" rel="noreferrer"&gt;rabbitmask/CVE-2018-7600-Drupal7&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7602
 &lt;div id="cve-2018-7602" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7602" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/Drupalgedon3" target="_blank" rel="noreferrer"&gt;1337g/Drupalgedon3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/happynote3966/CVE-2018-7602" target="_blank" rel="noreferrer"&gt;happynote3966/CVE-2018-7602&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kastellanos/CVE-2018-7602" target="_blank" rel="noreferrer"&gt;kastellanos/CVE-2018-7602&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7690
 &lt;div id="cve-2018-7690" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7690" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-7690" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-7690&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7691
 &lt;div id="cve-2018-7691" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7691" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2018-7691" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2018-7691&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7747
 &lt;div id="cve-2018-7747" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7747" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mindpr00f/CVE-2018-7747" target="_blank" rel="noreferrer"&gt;mindpr00f/CVE-2018-7747&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7750
 &lt;div id="cve-2018-7750" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7750" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jm33-m0/CVE-2018-7750" target="_blank" rel="noreferrer"&gt;jm33-m0/CVE-2018-7750&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-7935
 &lt;div id="cve-2018-7935" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-7935" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lawrenceamer/CVE-2018-7935" target="_blank" rel="noreferrer"&gt;lawrenceamer/CVE-2018-7935&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8021
 &lt;div id="cve-2018-8021" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8021" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/r3dxpl0it/Apache-Superset-Remote-Code-Execution-PoC-CVE-2018-8021" target="_blank" rel="noreferrer"&gt;r3dxpl0it/Apache-Superset-Remote-Code-Execution-PoC-CVE-2018-8021&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8032
 &lt;div id="cve-2018-8032" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8032" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cairuojin/CVE-2018-8032" target="_blank" rel="noreferrer"&gt;cairuojin/CVE-2018-8032&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8038
 &lt;div id="cve-2018-8038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-8038" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-8038&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8039
 &lt;div id="cve-2018-8039" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8039" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty(&amp;quot;java.protocol.handler.pkgs&amp;quot;, &amp;quot;com.sun.net.ssl.internal.www.protocol&amp;quot;);'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2018-8039" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2018-8039&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8045
 &lt;div id="cve-2018-8045" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8045" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/luckybool1020/CVE-2018-8045" target="_blank" rel="noreferrer"&gt;luckybool1020/CVE-2018-8045&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8060
 &lt;div id="cve-2018-8060" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8060" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. This affects IOCTLs higher than 0x85FE2600 with the HWiNFO32 symbolic device name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/otavioarj/SIOCtl" target="_blank" rel="noreferrer"&gt;otavioarj/SIOCtl&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8065
 &lt;div id="cve-2018-8065" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8065" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be triggered by rapidly sending a variety of HTTP requests with long HTTP header values or long URIs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EgeBalci/CVE-2018-8065" target="_blank" rel="noreferrer"&gt;EgeBalci/CVE-2018-8065&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8078
 &lt;div id="cve-2018-8078" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8078" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AlwaysHereFight/YZMCMSxss" target="_blank" rel="noreferrer"&gt;AlwaysHereFight/YZMCMSxss&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8090
 &lt;div id="cve-2018-8090" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8090" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00 (QHIS32.exe), (QHISFT32.exe) - Version 10.0.0.37; Quick Heal AntiVirus Pro 64 bit 17.00 (QHAV64.exe), (QHAVFT64.exe) - Version 10.0.0.37; and Quick Heal AntiVirus Pro 32 bit 17.00 (QHAV32.exe), (QHAVFT32.exe) - Version 10.0.0.37 allow DLL Hijacking because of Insecure Library Loading.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kernelm0de/CVE-2018-8090" target="_blank" rel="noreferrer"&gt;kernelm0de/CVE-2018-8090&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8108
 &lt;div id="cve-2018-8108" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8108" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, as demonstrated by workGroupList text.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zlgxzswjy/BUI-select-xss" target="_blank" rel="noreferrer"&gt;zlgxzswjy/BUI-select-xss&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8115
 &lt;div id="cve-2018-8115" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8115" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka &amp;quot;Windows Host Compute Service Shim Remote Code Execution Vulnerability.&amp;quot; This affects Windows Host Compute.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aquasecurity/scan-cve-2018-8115" target="_blank" rel="noreferrer"&gt;aquasecurity/scan-cve-2018-8115&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8120
 &lt;div id="cve-2018-8120" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8120" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot; This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bigric3/cve-2018-8120" target="_blank" rel="noreferrer"&gt;bigric3/cve-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/unamer/CVE-2018-8120" target="_blank" rel="noreferrer"&gt;unamer/CVE-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ne1llee/cve-2018-8120" target="_blank" rel="noreferrer"&gt;ne1llee/cve-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/alpha1ab/CVE-2018-8120" target="_blank" rel="noreferrer"&gt;alpha1ab/CVE-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/areuu/CVE-2018-8120" target="_blank" rel="noreferrer"&gt;areuu/CVE-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/EVOL4/CVE-2018-8120" target="_blank" rel="noreferrer"&gt;EVOL4/CVE-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ozkanbilge/CVE-2018-8120" target="_blank" rel="noreferrer"&gt;ozkanbilge/CVE-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qiantu88/CVE-2018-8120" target="_blank" rel="noreferrer"&gt;qiantu88/CVE-2018-8120&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Y0n0Y/cve-2018-8120-exp" target="_blank" rel="noreferrer"&gt;Y0n0Y/cve-2018-8120-exp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8172
 &lt;div id="cve-2018-8172" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8172" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka &amp;quot;Visual Studio Remote Code Execution Vulnerability.&amp;quot; This affects Microsoft Visual Studio, Expression Blend 4.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SyFi/CVE-2018-8172" target="_blank" rel="noreferrer"&gt;SyFi/CVE-2018-8172&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8174
 &lt;div id="cve-2018-8174" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8174" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka &amp;quot;Windows VBScript Engine Remote Code Execution Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x09AL/CVE-2018-8174-msf" target="_blank" rel="noreferrer"&gt;0x09AL/CVE-2018-8174-msf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Yt1g3r/CVE-2018-8174_EXP" target="_blank" rel="noreferrer"&gt;Yt1g3r/CVE-2018-8174_EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SyFi/CVE-2018-8174" target="_blank" rel="noreferrer"&gt;SyFi/CVE-2018-8174&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/orf53975/Rig-Exploit-for-CVE-2018-8174" target="_blank" rel="noreferrer"&gt;orf53975/Rig-Exploit-for-CVE-2018-8174&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/piotrflorczyk/cve-2018-8174_analysis" target="_blank" rel="noreferrer"&gt;piotrflorczyk/cve-2018-8174_analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-8174-msf" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-8174-msf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ruthlezs/ie11_vbscript_exploit" target="_blank" rel="noreferrer"&gt;ruthlezs/ie11_vbscript_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8208
 &lt;div id="cve-2018-8208" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8208" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka &amp;quot;Windows Desktop Bridge Elevation of Privilege Vulnerability.&amp;quot; This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kaisaryousuf/CVE-2018-8208" target="_blank" rel="noreferrer"&gt;kaisaryousuf/CVE-2018-8208&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8214
 &lt;div id="cve-2018-8214" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8214" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka &amp;quot;Windows Desktop Bridge Elevation of Privilege Vulnerability.&amp;quot; This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guwudoor/CVE-2018-8214" target="_blank" rel="noreferrer"&gt;guwudoor/CVE-2018-8214&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8284
 &lt;div id="cve-2018-8284" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8284" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka &amp;quot;.NET Framework Remote Code Injection Vulnerability.&amp;quot; This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/quantiti/CVE-2018-8284-Sharepoint-RCE" target="_blank" rel="noreferrer"&gt;quantiti/CVE-2018-8284-Sharepoint-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8353
 &lt;div id="cve-2018-8353" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8353" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability.&amp;quot; This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whereisr0da/CVE-2018-8353-POC" target="_blank" rel="noreferrer"&gt;whereisr0da/CVE-2018-8353-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8389
 &lt;div id="cve-2018-8389" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8389" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability.&amp;quot; This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sharmasandeepkr/cve-2018-8389" target="_blank" rel="noreferrer"&gt;sharmasandeepkr/cve-2018-8389&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8414
 &lt;div id="cve-2018-8414" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8414" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka &amp;quot;Windows Shell Remote Code Execution Vulnerability.&amp;quot; This affects Windows 10 Servers, Windows 10.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whereisr0da/CVE-2018-8414-POC" target="_blank" rel="noreferrer"&gt;whereisr0da/CVE-2018-8414-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8420
 &lt;div id="cve-2018-8420" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8420" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka &amp;quot;MS XML Remote Code Execution Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/idkwim/CVE-2018-8420" target="_blank" rel="noreferrer"&gt;idkwim/CVE-2018-8420&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8440
 &lt;div id="cve-2018-8440" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8440" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka &amp;quot;Windows ALPC Elevation of Privilege Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sourceincite/CVE-2018-8440" target="_blank" rel="noreferrer"&gt;sourceincite/CVE-2018-8440&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8453
 &lt;div id="cve-2018-8453" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8453" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Mkv4/cve-2018-8453-exp" target="_blank" rel="noreferrer"&gt;Mkv4/cve-2018-8453-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/cve-2018-8453-exp" target="_blank" rel="noreferrer"&gt;ze0r/cve-2018-8453-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thepwnrip/leHACK-Analysis-of-CVE-2018-8453" target="_blank" rel="noreferrer"&gt;thepwnrip/leHACK-Analysis-of-CVE-2018-8453&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8495
 &lt;div id="cve-2018-8495" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8495" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka &amp;quot;Windows Shell Remote Code Execution Vulnerability.&amp;quot; This affects Windows Server 2016, Windows 10, Windows 10 Servers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whereisr0da/CVE-2018-8495-POC" target="_blank" rel="noreferrer"&gt;whereisr0da/CVE-2018-8495-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8581
 &lt;div id="cve-2018-8581" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8581" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka &amp;quot;Microsoft Exchange Server Elevation of Privilege Vulnerability.&amp;quot; This affects Microsoft Exchange Server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/WyAtu/CVE-2018-8581" target="_blank" rel="noreferrer"&gt;WyAtu/CVE-2018-8581&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qiantu88/CVE-2018-8581" target="_blank" rel="noreferrer"&gt;qiantu88/CVE-2018-8581&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/Exchange2domain" target="_blank" rel="noreferrer"&gt;Ridter/Exchange2domain&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8639
 &lt;div id="cve-2018-8639" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8639" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot; This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ze0r/CVE-2018-8639-exp" target="_blank" rel="noreferrer"&gt;ze0r/CVE-2018-8639-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/timwhitez/CVE-2018-8639-EXP" target="_blank" rel="noreferrer"&gt;timwhitez/CVE-2018-8639-EXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8718
 &lt;div id="cve-2018-8718" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8718" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GeunSam2/CVE-2018-8718" target="_blank" rel="noreferrer"&gt;GeunSam2/CVE-2018-8718&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8733
 &lt;div id="cve-2018-8733" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8733" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xfer0/Nagios-XI-5.2.6-9-5.3-5.4-Chained-Remote-Root-Exploit-Fixed" target="_blank" rel="noreferrer"&gt;xfer0/Nagios-XI-5.2.6-9-5.3-5.4-Chained-Remote-Root-Exploit-Fixed&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8820
 &lt;div id="cve-2018-8820" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8820" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the &amp;quot;match&amp;quot; parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for the attack can be met by sending the default admin credentials.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hateshape/frevvomapexec" target="_blank" rel="noreferrer"&gt;hateshape/frevvomapexec&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8897
 &lt;div id="cve-2018-8897" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8897" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL &amp;lt; 3, the debug exception is delivered after the transfer to CPL &amp;lt; 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nmulasmajic/CVE-2018-8897" target="_blank" rel="noreferrer"&gt;nmulasmajic/CVE-2018-8897&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jiazhang0/pop-mov-ss-exploit" target="_blank" rel="noreferrer"&gt;jiazhang0/pop-mov-ss-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/can1357/CVE-2018-8897" target="_blank" rel="noreferrer"&gt;can1357/CVE-2018-8897&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897" target="_blank" rel="noreferrer"&gt;nmulasmajic/syscall_exploit_CVE-2018-8897&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8941
 &lt;div id="cve-2018-8941" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8941" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2018-8941" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2018-8941&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8943
 &lt;div id="cve-2018-8943" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8943" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is a SQL injection in the PHPSHE 1.6 userbank parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/coolboy0816/CVE-2018-8943" target="_blank" rel="noreferrer"&gt;coolboy0816/CVE-2018-8943&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-8970
 &lt;div id="cve-2018-8970" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-8970" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tiran/CVE-2018-8970" target="_blank" rel="noreferrer"&gt;tiran/CVE-2018-8970&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9059
 &lt;div id="cve-2018-9059" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9059" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request to forum.ghp. NOTE: this may overlap CVE-2014-3791.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/manojcode/easy-file-share-7.2-exploit-CVE-2018-9059" target="_blank" rel="noreferrer"&gt;manojcode/easy-file-share-7.2-exploit-CVE-2018-9059&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9075
 &lt;div id="cve-2018-9075" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9075" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick &amp;quot;``&amp;quot; characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/beverlymiller818/cve-2018-9075" target="_blank" rel="noreferrer"&gt;beverlymiller818/cve-2018-9075&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9160
 &lt;div id="cve-2018-9160" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9160" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mechanico/sickrageWTF" target="_blank" rel="noreferrer"&gt;mechanico/sickrageWTF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9206
 &lt;div id="cve-2018-9206" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9206" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload &amp;lt;= v9.22.0
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Den1al/CVE-2018-9206" target="_blank" rel="noreferrer"&gt;Den1al/CVE-2018-9206&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Stahlz/JQShell" target="_blank" rel="noreferrer"&gt;Stahlz/JQShell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-9206" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-9206&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9207
 &lt;div id="cve-2018-9207" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9207" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Arbitrary file upload in jQuery Upload File &amp;lt;= 4.0.2
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-9207" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-9207&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9208
 &lt;div id="cve-2018-9208" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9208" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut &amp;lt;= v1.1Beta
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2018-9208" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2018-9208&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9276
 &lt;div id="cve-2018-9276" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9276" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wildkindcc/CVE-2018-9276" target="_blank" rel="noreferrer"&gt;wildkindcc/CVE-2018-9276&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9375
 &lt;div id="cve-2018-9375" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9375" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IOActive/AOSP-ExploitUserDictionary" target="_blank" rel="noreferrer"&gt;IOActive/AOSP-ExploitUserDictionary&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9411
 &lt;div id="cve-2018-9411" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9411" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tamirzb/CVE-2018-9411" target="_blank" rel="noreferrer"&gt;tamirzb/CVE-2018-9411&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9468
 &lt;div id="cve-2018-9468" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9468" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IOActive/AOSP-DownloadProviderHijacker" target="_blank" rel="noreferrer"&gt;IOActive/AOSP-DownloadProviderHijacker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9493
 &lt;div id="cve-2018-9493" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9493" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IOActive/AOSP-DownloadProviderDbDumper" target="_blank" rel="noreferrer"&gt;IOActive/AOSP-DownloadProviderDbDumper&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9539
 &lt;div id="cve-2018-9539" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9539" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-113027383
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tamirzb/CVE-2018-9539" target="_blank" rel="noreferrer"&gt;tamirzb/CVE-2018-9539&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9546
 &lt;div id="cve-2018-9546" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9546" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IOActive/AOSP-DownloadProviderHeadersDumper" target="_blank" rel="noreferrer"&gt;IOActive/AOSP-DownloadProviderHeadersDumper&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9948
 &lt;div id="cve-2018-9948" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9948" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of typed arrays. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5380.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/manojcode/Foxit-Reader-RCE-with-virualalloc-and-shellcode-for-CVE-2018-9948-and-CVE-2018-9958" target="_blank" rel="noreferrer"&gt;manojcode/Foxit-Reader-RCE-with-virualalloc-and-shellcode-for-CVE-2018-9948-and-CVE-2018-9958&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/orangepirate/cve-2018-9948-9958-exp" target="_blank" rel="noreferrer"&gt;orangepirate/cve-2018-9948-9958-exp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9950
 &lt;div id="cve-2018-9950" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9950" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5413.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sharmasandeepkr/PS-2017-13---CVE-2018-9950" target="_blank" rel="noreferrer"&gt;sharmasandeepkr/PS-2017-13&amp;mdash;CVE-2018-9950&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9951
 &lt;div id="cve-2018-9951" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9951" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CPDF_Object objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5414.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sharmasandeepkr/cve-2018-9951" target="_blank" rel="noreferrer"&gt;sharmasandeepkr/cve-2018-9951&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9958
 &lt;div id="cve-2018-9958" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9958" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5620.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/t3rabyt3/CVE-2018-9958--Exploit" target="_blank" rel="noreferrer"&gt;t3rabyt3/CVE-2018-9958&amp;ndash;Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2018-9995
 &lt;div id="cve-2018-9995" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2018-9995" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a &amp;quot;Cookie: uid=admin&amp;quot; header, as demonstrated by a device.rsp?opt=user&amp;amp;cmd=list request that provides credentials within JSON data in a response.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ezelf/CVE-2018-9995_dvr_credentials" target="_blank" rel="noreferrer"&gt;ezelf/CVE-2018-9995_dvr_credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zzh217/CVE-2018-9995_Batch_scanning_exp" target="_blank" rel="noreferrer"&gt;zzh217/CVE-2018-9995_Batch_scanning_exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Huangkey/CVE-2018-9995_check" target="_blank" rel="noreferrer"&gt;Huangkey/CVE-2018-9995_check&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gwolfs/CVE-2018-9995-ModifiedByGwolfs" target="_blank" rel="noreferrer"&gt;gwolfs/CVE-2018-9995-ModifiedByGwolfs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shacojx/cve-2018-9995" target="_blank" rel="noreferrer"&gt;shacojx/cve-2018-9995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cyb0r9/DVR-Exploiter" target="_blank" rel="noreferrer"&gt;Cyb0r9/DVR-Exploiter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/codeholic2k18/CVE-2018-9995" target="_blank" rel="noreferrer"&gt;codeholic2k18/CVE-2018-9995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TateYdq/CVE-2018-9995-ModifiedByGwolfs" target="_blank" rel="noreferrer"&gt;TateYdq/CVE-2018-9995-ModifiedByGwolfs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ABIZCHI/CVE-2018-9995_dvr_credentials" target="_blank" rel="noreferrer"&gt;ABIZCHI/CVE-2018-9995_dvr_credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/IHA114/CVE-2018-9995_dvr_credentials" target="_blank" rel="noreferrer"&gt;IHA114/CVE-2018-9995_dvr_credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/likaifeng0/CVE-2018-9995_dvr_credentials-dev_tool" target="_blank" rel="noreferrer"&gt;likaifeng0/CVE-2018-9995_dvr_credentials-dev_tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b510/CVE-2018-9995-POC" target="_blank" rel="noreferrer"&gt;b510/CVE-2018-9995-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/keyw0rds/HTC" target="_blank" rel="noreferrer"&gt;keyw0rds/HTC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/g5q2/cve-2018-9995" target="_blank" rel="noreferrer"&gt;g5q2/cve-2018-9995&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2017
 &lt;div id="2017" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2017" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0038
 &lt;div id="cve-2017-0038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/k0keoyo/CVE-2017-0038-EXP-C-JS" target="_blank" rel="noreferrer"&gt;k0keoyo/CVE-2017-0038-EXP-C-JS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0065
 &lt;div id="cve-2017-0065" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0065" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka &amp;quot;Microsoft Browser Information Disclosure Vulnerability.&amp;quot; This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0068.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Dankirk/cve-2017-0065" target="_blank" rel="noreferrer"&gt;Dankirk/cve-2017-0065&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0075
 &lt;div id="cve-2017-0075" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0075" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka &amp;quot;Hyper-V Remote Code Execution Vulnerability.&amp;quot; This vulnerability is different from that described in CVE-2017-0109.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/4B5F5F4B/HyperV" target="_blank" rel="noreferrer"&gt;4B5F5F4B/HyperV&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0106
 &lt;div id="cve-2017-0106" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0106" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka &amp;quot;Microsoft Office Memory Corruption Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ryhanson/CVE-2017-0106" target="_blank" rel="noreferrer"&gt;ryhanson/CVE-2017-0106&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0108
 &lt;div id="cve-2017-0108" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0108" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka &amp;quot;Graphics Component Remote Code Execution Vulnerability.&amp;quot; This vulnerability is different from that described in CVE-2017-0014.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-0108" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-0108&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0143
 &lt;div id="cve-2017-0143" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0143" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka &amp;quot;Windows SMB Remote Code Execution Vulnerability.&amp;quot; This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/valarauco/wannafind" target="_blank" rel="noreferrer"&gt;valarauco/wannafind&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0144
 &lt;div id="cve-2017-0144" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0144" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka &amp;quot;Windows SMB Remote Code Execution Vulnerability.&amp;quot; This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/peterpt/eternal_scanner" target="_blank" rel="noreferrer"&gt;peterpt/eternal_scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kimocoder/eternalblue" target="_blank" rel="noreferrer"&gt;kimocoder/eternalblue&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0145
 &lt;div id="cve-2017-0145" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0145" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka &amp;quot;Windows SMB Remote Code Execution Vulnerability.&amp;quot; This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MelonSmasher/chef_tissues" target="_blank" rel="noreferrer"&gt;MelonSmasher/chef_tissues&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0199
 &lt;div id="cve-2017-0199" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0199" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka &amp;quot;Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ryhanson/CVE-2017-0199" target="_blank" rel="noreferrer"&gt;ryhanson/CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SyFi/cve-2017-0199" target="_blank" rel="noreferrer"&gt;SyFi/cve-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bhdresh/CVE-2017-0199" target="_blank" rel="noreferrer"&gt;bhdresh/CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NotAwful/CVE-2017-0199-Fix" target="_blank" rel="noreferrer"&gt;NotAwful/CVE-2017-0199-Fix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/haibara3839/CVE-2017-0199-master" target="_blank" rel="noreferrer"&gt;haibara3839/CVE-2017-0199-master&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Exploit-install/CVE-2017-0199" target="_blank" rel="noreferrer"&gt;Exploit-install/CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zakybstrd21215/PoC-CVE-2017-0199" target="_blank" rel="noreferrer"&gt;zakybstrd21215/PoC-CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/n1shant-sinha/CVE-2017-0199" target="_blank" rel="noreferrer"&gt;n1shant-sinha/CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kn0wm4d/htattack" target="_blank" rel="noreferrer"&gt;kn0wm4d/htattack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/joke998/Cve-2017-0199" target="_blank" rel="noreferrer"&gt;joke998/Cve-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/joke998/Cve-2017-0199-" target="_blank" rel="noreferrer"&gt;joke998/Cve-2017-0199-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r0otshell/Microsoft-Word-CVE-2017-0199-" target="_blank" rel="noreferrer"&gt;r0otshell/Microsoft-Word-CVE-2017-0199-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/viethdgit/CVE-2017-0199" target="_blank" rel="noreferrer"&gt;viethdgit/CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nicpenning/RTF-Cleaner" target="_blank" rel="noreferrer"&gt;nicpenning/RTF-Cleaner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bloomer1016/2017-11-17-Maldoc-Using-CVE-2017-0199" target="_blank" rel="noreferrer"&gt;bloomer1016/2017-11-17-Maldoc-Using-CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jacobsoo/RTF-Cleaner" target="_blank" rel="noreferrer"&gt;jacobsoo/RTF-Cleaner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2017-0199" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2017-0199&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0204
 &lt;div id="cve-2017-0204" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0204" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka &amp;quot;Microsoft Office Security Feature Bypass Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ryhanson/CVE-2017-0204" target="_blank" rel="noreferrer"&gt;ryhanson/CVE-2017-0204&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0213
 &lt;div id="cve-2017-0213" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0213" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka &amp;quot;Windows COM Elevation of Privilege Vulnerability&amp;quot;. This CVE ID is unique from CVE-2017-0214.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shaheemirza/CVE-2017-0213-" target="_blank" rel="noreferrer"&gt;shaheemirza/CVE-2017-0213-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zcgonvh/CVE-2017-0213" target="_blank" rel="noreferrer"&gt;zcgonvh/CVE-2017-0213&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/billa3283/CVE-2017-0213" target="_blank" rel="noreferrer"&gt;billa3283/CVE-2017-0213&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2017-0213" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2017-0213&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jbooz1/CVE-2017-0213" target="_blank" rel="noreferrer"&gt;jbooz1/CVE-2017-0213&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eonrickity/CVE-2017-0213" target="_blank" rel="noreferrer"&gt;eonrickity/CVE-2017-0213&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Jos675/CVE-2017-0213-Exploit" target="_blank" rel="noreferrer"&gt;Jos675/CVE-2017-0213-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0248
 &lt;div id="cve-2017-0248" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0248" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka &amp;quot;.NET Security Feature Bypass Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rubenmamo/CVE-2017-0248-Test" target="_blank" rel="noreferrer"&gt;rubenmamo/CVE-2017-0248-Test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0261
 &lt;div id="cve-2017-0261" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0261" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka &amp;quot;Office Remote Code Execution Vulnerability&amp;quot;. This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kcufId/eps-CVE-2017-0261" target="_blank" rel="noreferrer"&gt;kcufId/eps-CVE-2017-0261&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0263
 &lt;div id="cve-2017-0263" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0263" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/R06otMD5/cve-2017-0263-poc" target="_blank" rel="noreferrer"&gt;R06otMD5/cve-2017-0263-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0290
 &lt;div id="cve-2017-0290" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0290" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka &amp;quot;Microsoft Malware Protection Engine Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-0290-" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-0290-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0411
 &lt;div id="cve-2017-0411" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0411" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33042690.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lulusudoku/PoC" target="_blank" rel="noreferrer"&gt;lulusudoku/PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0478
 &lt;div id="cve-2017-0478" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0478" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33718716.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JiounDai/CVE-2017-0478" target="_blank" rel="noreferrer"&gt;JiounDai/CVE-2017-0478&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2017-0478" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2017-0478&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0541
 &lt;div id="cve-2017-0541" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0541" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34031018.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JiounDai/CVE-2017-0541" target="_blank" rel="noreferrer"&gt;JiounDai/CVE-2017-0541&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2017-0541" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2017-0541&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0554
 &lt;div id="cve-2017-0554" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0554" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33815946.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lanrat/tethr" target="_blank" rel="noreferrer"&gt;lanrat/tethr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0564
 &lt;div id="cve-2017-0564" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0564" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34276203.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guoygang/CVE-2017-0564-ION-PoC" target="_blank" rel="noreferrer"&gt;guoygang/CVE-2017-0564-ION-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0781
 &lt;div id="cve-2017-0781" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0781" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ojasookert/CVE-2017-0781" target="_blank" rel="noreferrer"&gt;ojasookert/CVE-2017-0781&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/android712-blueborne" target="_blank" rel="noreferrer"&gt;marcinguy/android712-blueborne&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0785
 &lt;div id="cve-2017-0785" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0785" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ojasookert/CVE-2017-0785" target="_blank" rel="noreferrer"&gt;ojasookert/CVE-2017-0785&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aymankhalfatni/CVE-2017-0785" target="_blank" rel="noreferrer"&gt;aymankhalfatni/CVE-2017-0785&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Alfa100001/-CVE-2017-0785-BlueBorne-PoC" target="_blank" rel="noreferrer"&gt;Alfa100001/-CVE-2017-0785-BlueBorne-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Android013/CVE-2017-0785" target="_blank" rel="noreferrer"&gt;Android013/CVE-2017-0785&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Hackerscript/BlueBorne-CVE-2017-0785" target="_blank" rel="noreferrer"&gt;Hackerscript/BlueBorne-CVE-2017-0785&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pieterbork/blueborne" target="_blank" rel="noreferrer"&gt;pieterbork/blueborne&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sigbitsadmin/diff" target="_blank" rel="noreferrer"&gt;sigbitsadmin/diff&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SigBitsLabs/diff" target="_blank" rel="noreferrer"&gt;SigBitsLabs/diff&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RavSS/Bluetooth-Crash-CVE-2017-0785" target="_blank" rel="noreferrer"&gt;RavSS/Bluetooth-Crash-CVE-2017-0785&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0806
 &lt;div id="cve-2017-0806" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0806" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/michalbednarski/ReparcelBug" target="_blank" rel="noreferrer"&gt;michalbednarski/ReparcelBug&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-0807
 &lt;div id="cve-2017-0807" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-0807" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kpatsakis/PoC_CVE-2017-0807" target="_blank" rel="noreferrer"&gt;kpatsakis/PoC_CVE-2017-0807&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000000
 &lt;div id="cve-2017-1000000" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000000" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/smythtech/DWF-CVE-2017-1000000" target="_blank" rel="noreferrer"&gt;smythtech/DWF-CVE-2017-1000000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000083
 &lt;div id="cve-2017-1000083" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000083" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a &amp;quot;--&amp;quot; command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/matlink/evince-cve-2017-1000083" target="_blank" rel="noreferrer"&gt;matlink/evince-cve-2017-1000083&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/matlink/cve-2017-1000083-atril-nautilus" target="_blank" rel="noreferrer"&gt;matlink/cve-2017-1000083-atril-nautilus&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000112
 &lt;div id="cve-2017-1000112" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000112" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb-&amp;gt;len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev-&amp;gt;len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 (&amp;quot;[IPv4/IPv6]: UFO Scatter-gather approach&amp;quot;) on Oct 18 2005.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hikame/docker_escape_pwn" target="_blank" rel="noreferrer"&gt;hikame/docker_escape_pwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ol0273st-s/CVE-2017-1000112-Adpated" target="_blank" rel="noreferrer"&gt;ol0273st-s/CVE-2017-1000112-Adpated&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000117
 &lt;div id="cve-2017-1000117" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000117" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A malicious third-party can give a crafted &amp;quot;ssh://...&amp;quot; URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running &amp;quot;git clone --recurse-submodules&amp;quot; to trigger the vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/timwr/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;timwr/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GrahamMThomas/test-git-vuln_CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;GrahamMThomas/test-git-vuln_CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Manouchehri/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;Manouchehri/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thelastbyte/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;thelastbyte/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/alilangtest/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;alilangtest/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/VulApps/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;VulApps/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/greymd/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;greymd/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shogo82148/Fix-CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;shogo82148/Fix-CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sasairc/CVE-2017-1000117_wasawasa" target="_blank" rel="noreferrer"&gt;sasairc/CVE-2017-1000117_wasawasa&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Shadow5523/CVE-2017-1000117-test" target="_blank" rel="noreferrer"&gt;Shadow5523/CVE-2017-1000117-test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bells17/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;bells17/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ieee0824/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;ieee0824/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rootclay/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;rootclay/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ieee0824/CVE-2017-1000117-sl" target="_blank" rel="noreferrer"&gt;ieee0824/CVE-2017-1000117-sl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/takehaya/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;takehaya/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ikmski/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;ikmski/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nkoneko/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;nkoneko/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chenzhuo0618/test" target="_blank" rel="noreferrer"&gt;chenzhuo0618/test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siling2017/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;siling2017/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Q2h1Cg/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;Q2h1Cg/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-1000117" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leezp/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;leezp/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AnonymKing/CVE-2017-1000117" target="_blank" rel="noreferrer"&gt;AnonymKing/CVE-2017-1000117&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000250
 &lt;div id="cve-2017-1000250" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000250" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/olav-st/CVE-2017-1000250-PoC" target="_blank" rel="noreferrer"&gt;olav-st/CVE-2017-1000250-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000251
 &lt;div id="cve-2017-1000251" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000251" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hayzamjs/Blueborne-CVE-2017-1000251" target="_blank" rel="noreferrer"&gt;hayzamjs/Blueborne-CVE-2017-1000251&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chmod750/blueborne" target="_blank" rel="noreferrer"&gt;chmod750/blueborne&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tlatkdgus1/blueborne-CVE-2017-1000251" target="_blank" rel="noreferrer"&gt;tlatkdgus1/blueborne-CVE-2017-1000251&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/own2pwn/blueborne-CVE-2017-1000251-POC" target="_blank" rel="noreferrer"&gt;own2pwn/blueborne-CVE-2017-1000251-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marcinguy/blueborne-CVE-2017-1000251" target="_blank" rel="noreferrer"&gt;marcinguy/blueborne-CVE-2017-1000251&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000253
 &lt;div id="cve-2017-1000253" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000253" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm-&amp;gt;mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm-&amp;gt;mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm-&amp;gt;mmap_base into the are that is supposed to be the &amp;quot;gap&amp;quot; between the stack and the binary.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sagiesec/PIE-Stack-Clash-CVE-2017-1000253" target="_blank" rel="noreferrer"&gt;sagiesec/PIE-Stack-Clash-CVE-2017-1000253&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000353
 &lt;div id="cve-2017-1000353" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000353" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vulhub/CVE-2017-1000353" target="_blank" rel="noreferrer"&gt;vulhub/CVE-2017-1000353&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000367
 &lt;div id="cve-2017-1000367" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000367" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0d3z3r0/sudo-CVE-2017-1000367" target="_blank" rel="noreferrer"&gt;c0d3z3r0/sudo-CVE-2017-1000367&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-1000367" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-1000367&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pucerpocok/sudo_exploit" target="_blank" rel="noreferrer"&gt;pucerpocok/sudo_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000405
 &lt;div id="cve-2017-1000405" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000405" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original &amp;quot;Dirty cow&amp;quot; because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bindecy/HugeDirtyCowPOC" target="_blank" rel="noreferrer"&gt;bindecy/HugeDirtyCowPOC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000475
 &lt;div id="cve-2017-1000475" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000475" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lajarajorge/CVE-2017-1000475" target="_blank" rel="noreferrer"&gt;lajarajorge/CVE-2017-1000475&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000486
 &lt;div id="cve-2017-1000486" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000486" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pimps/CVE-2017-1000486" target="_blank" rel="noreferrer"&gt;pimps/CVE-2017-1000486&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mogwailabs/CVE-2017-1000486" target="_blank" rel="noreferrer"&gt;mogwailabs/CVE-2017-1000486&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-1000486" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-1000486&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1000499
 &lt;div id="cve-2017-1000499" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1000499" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Villaquiranm/5MMISSI-CVE-2017-1000499" target="_blank" rel="noreferrer"&gt;Villaquiranm/5MMISSI-CVE-2017-1000499&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1002101
 &lt;div id="cve-2017-1002101" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1002101" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bgeesaman/subpath-exploit" target="_blank" rel="noreferrer"&gt;bgeesaman/subpath-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10235
 &lt;div id="cve-2017-10235" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10235" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fundacion-sadosky/vbox_cve_2017_10235" target="_blank" rel="noreferrer"&gt;fundacion-sadosky/vbox_cve_2017_10235&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10271
 &lt;div id="cve-2017-10271" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10271" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;1337g/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s3xy/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;s3xy/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271" target="_blank" rel="noreferrer"&gt;ZH3FENG/PoCs-Weblogic_2017_10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/c0mmand3rOpSec/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;c0mmand3rOpSec/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Luffin/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;Luffin/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cjjduck/weblogic_wls_wsat_rce" target="_blank" rel="noreferrer"&gt;cjjduck/weblogic_wls_wsat_rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kkirsche/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;kkirsche/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pssss/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;pssss/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SuperHacker-liuan/cve-2017-10271-poc" target="_blank" rel="noreferrer"&gt;SuperHacker-liuan/cve-2017-10271-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bmcculley/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;bmcculley/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/Oracle-WebLogic-CVE-2017-10271" target="_blank" rel="noreferrer"&gt;RealBearcat/Oracle-WebLogic-CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sch01ar/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;Sch01ar/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cymmetria/weblogic_honeypot" target="_blank" rel="noreferrer"&gt;Cymmetria/weblogic_honeypot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JackyTsuuuy/weblogic_wls_rce_poc-exp" target="_blank" rel="noreferrer"&gt;JackyTsuuuy/weblogic_wls_rce_poc-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s0wr0b1ndef/Oracle-WebLogic-WLS-WSAT" target="_blank" rel="noreferrer"&gt;s0wr0b1ndef/Oracle-WebLogic-WLS-WSAT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lonehand/Oracle-WebLogic-CVE-2017-10271-master" target="_blank" rel="noreferrer"&gt;lonehand/Oracle-WebLogic-CVE-2017-10271-master&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shack2/javaserializetools" target="_blank" rel="noreferrer"&gt;shack2/javaserializetools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nhwuxiaojun/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;nhwuxiaojun/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ETOCheney/JavaDeserialization" target="_blank" rel="noreferrer"&gt;ETOCheney/JavaDeserialization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-10271" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/XHSecurity/Oracle-WebLogic-CVE-2017-10271" target="_blank" rel="noreferrer"&gt;XHSecurity/Oracle-WebLogic-CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kaidb/Weblogic_Wsat_RCE" target="_blank" rel="noreferrer"&gt;kaidb/Weblogic_Wsat_RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961" target="_blank" rel="noreferrer"&gt;SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Yuusuke4/WebLogic_CNVD_C_2019_48814" target="_blank" rel="noreferrer"&gt;Yuusuke4/WebLogic_CNVD_C_2019_48814&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/7kbstorm/WebLogic_CNVD_C2019_48814" target="_blank" rel="noreferrer"&gt;7kbstorm/WebLogic_CNVD_C2019_48814&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/-CVE-2017-10271-" target="_blank" rel="noreferrer"&gt;ianxtianxt/-CVE-2017-10271-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/testwc/CVE-2017-10271" target="_blank" rel="noreferrer"&gt;testwc/CVE-2017-10271&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10352
 &lt;div id="cve-2017-10352" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10352" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bigsizeme/weblogic-XMLDecoder" target="_blank" rel="noreferrer"&gt;bigsizeme/weblogic-XMLDecoder&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10366
 &lt;div id="cve-2017-10366" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10366" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/blazeinfosec/CVE-2017-10366_peoplesoft" target="_blank" rel="noreferrer"&gt;blazeinfosec/CVE-2017-10366_peoplesoft&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10617
 &lt;div id="cve-2017-10617" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10617" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gteissier/CVE-2017-10617" target="_blank" rel="noreferrer"&gt;gteissier/CVE-2017-10617&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10661
 &lt;div id="cve-2017-10661" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10661" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GeneBlue/CVE-2017-10661_POC" target="_blank" rel="noreferrer"&gt;GeneBlue/CVE-2017-10661_POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10797
 &lt;div id="cve-2017-10797" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10797" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/n4xh4ck5/CVE-2017-10797" target="_blank" rel="noreferrer"&gt;n4xh4ck5/CVE-2017-10797&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-10952
 &lt;div id="cve-2017-10952" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-10952" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack of proper validation of user-supplied data, which can lead to writing arbitrary files into attacker controlled locations. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4518.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/afbase/CVE-2017-10952" target="_blank" rel="noreferrer"&gt;afbase/CVE-2017-10952&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11176
 &lt;div id="cve-2017-11176" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11176" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DoubleMice/cve-2017-11176" target="_blank" rel="noreferrer"&gt;DoubleMice/cve-2017-11176&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HckEX/CVE-2017-11176" target="_blank" rel="noreferrer"&gt;HckEX/CVE-2017-11176&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leonardo1101/cve-2017-11176" target="_blank" rel="noreferrer"&gt;leonardo1101/cve-2017-11176&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/c3r34lk1ll3r/CVE-2017-11176" target="_blank" rel="noreferrer"&gt;c3r34lk1ll3r/CVE-2017-11176&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11317
 &lt;div id="cve-2017-11317" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11317" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bao7uo/RAU_crypto" target="_blank" rel="noreferrer"&gt;bao7uo/RAU_crypto&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11427
 &lt;div id="cve-2017-11427" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11427" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CHYbeta/CVE-2017-11427-DEMO" target="_blank" rel="noreferrer"&gt;CHYbeta/CVE-2017-11427-DEMO&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11503
 &lt;div id="cve-2017-11503" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11503" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PHPMailer 5.2.23 has XSS in the &amp;quot;From Email Address&amp;quot; and &amp;quot;To Email Address&amp;quot; fields of code_generator.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wizardafric/download" target="_blank" rel="noreferrer"&gt;wizardafric/download&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11519
 &lt;div id="cve-2017-11519" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11519" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vakzz/tplink-CVE-2017-11519" target="_blank" rel="noreferrer"&gt;vakzz/tplink-CVE-2017-11519&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11610
 &lt;div id="cve-2017-11610" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11610" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ivanitlearning/CVE-2017-11610" target="_blank" rel="noreferrer"&gt;ivanitlearning/CVE-2017-11610&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11611
 &lt;div id="cve-2017-11611" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11611" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a &amp;quot;create-file-popup&amp;quot; action, and the directory name in a &amp;quot;create-directory-popup&amp;quot; action, in the HTTP POST method to the &amp;quot;/plugin/file_manager/&amp;quot; script (aka an /admin/plugin/file_manager/browse// URI).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/faizzaidi/Wolfcms-v0.8.3.1-xss-POC-by-Provensec-llc" target="_blank" rel="noreferrer"&gt;faizzaidi/Wolfcms-v0.8.3.1-xss-POC-by-Provensec-llc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11774
 &lt;div id="cve-2017-11774" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11774" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka &amp;quot;Microsoft Outlook Security Feature Bypass Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/devcoinfet/SniperRoost" target="_blank" rel="noreferrer"&gt;devcoinfet/SniperRoost&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11783
 &lt;div id="cve-2017-11783" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11783" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka &amp;quot;Windows Elevation of Privilege Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Sheisback/CVE-2017-11783" target="_blank" rel="noreferrer"&gt;Sheisback/CVE-2017-11783&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11816
 &lt;div id="cve-2017-11816" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11816" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka &amp;quot;Windows GDI Information Disclosure Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lr3800/CVE-2017-11816" target="_blank" rel="noreferrer"&gt;lr3800/CVE-2017-11816&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11826
 &lt;div id="cve-2017-11826" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11826" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/thatskriptkid/CVE-2017-11826" target="_blank" rel="noreferrer"&gt;thatskriptkid/CVE-2017-11826&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11882
 &lt;div id="cve-2017-11882" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11882" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka &amp;quot;Microsoft Office Memory Corruption Vulnerability&amp;quot;. This CVE ID is unique from CVE-2017-11884.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/starnightcyber/exploits" target="_blank" rel="noreferrer"&gt;starnightcyber/exploits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhouat/cve-2017-11882" target="_blank" rel="noreferrer"&gt;zhouat/cve-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/embedi/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;embedi/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;Ridter/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BlackMathIT/2017-11882_Generator" target="_blank" rel="noreferrer"&gt;BlackMathIT/2017-11882_Generator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/unamer/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;unamer/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x09AL/CVE-2017-11882-metasploit" target="_blank" rel="noreferrer"&gt;0x09AL/CVE-2017-11882-metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HZachev/ABC" target="_blank" rel="noreferrer"&gt;HZachev/ABC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/starnightcyber/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;starnightcyber/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Grey-Li/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;Grey-Li/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/legendsec/CVE-2017-11882-for-Kali" target="_blank" rel="noreferrer"&gt;legendsec/CVE-2017-11882-for-Kali&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CSC-pentest/cve-2017-11882" target="_blank" rel="noreferrer"&gt;CSC-pentest/cve-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Shadowshusky/CVE-2017-11882-" target="_blank" rel="noreferrer"&gt;Shadowshusky/CVE-2017-11882-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rxwx/CVE-2018-0802" target="_blank" rel="noreferrer"&gt;rxwx/CVE-2018-0802&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ridter/RTF_11882_0802" target="_blank" rel="noreferrer"&gt;Ridter/RTF_11882_0802&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/CVE-2018-0802_CVE-2017-11882" target="_blank" rel="noreferrer"&gt;denmilu/CVE-2018-0802_CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bloomer1016/CVE-2017-11882-Possible-Remcos-Malspam" target="_blank" rel="noreferrer"&gt;bloomer1016/CVE-2017-11882-Possible-Remcos-Malspam&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ChaitanyaHaritash/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;ChaitanyaHaritash/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qy1202/https-github.com-Ridter-CVE-2017-11882-" target="_blank" rel="noreferrer"&gt;qy1202/https-github.com-Ridter-CVE-2017-11882-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/j0lama/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;j0lama/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/R0fM1a/IDB_Share" target="_blank" rel="noreferrer"&gt;R0fM1a/IDB_Share&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chanbin/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;chanbin/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/littlebin404/CVE-2017-11882" target="_blank" rel="noreferrer"&gt;littlebin404/CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ekgg/Overflow-Demo-CVE-2017-11882" target="_blank" rel="noreferrer"&gt;ekgg/Overflow-Demo-CVE-2017-11882&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-11907
 &lt;div id="cve-2017-11907" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-11907" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability&amp;quot;. This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/re4lity/CVE-2017-11907" target="_blank" rel="noreferrer"&gt;re4lity/CVE-2017-11907&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12149
 &lt;div id="cve-2017-12149" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12149" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sevck/CVE-2017-12149" target="_blank" rel="noreferrer"&gt;sevck/CVE-2017-12149&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yunxu1/jboss-_CVE-2017-12149" target="_blank" rel="noreferrer"&gt;yunxu1/jboss-_CVE-2017-12149&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2017-12149" target="_blank" rel="noreferrer"&gt;1337g/CVE-2017-12149&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jreppiks/CVE-2017-12149" target="_blank" rel="noreferrer"&gt;jreppiks/CVE-2017-12149&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12426
 &lt;div id="cve-2017-12426" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12426" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sm-paul-schuette/CVE-2017-12426" target="_blank" rel="noreferrer"&gt;sm-paul-schuette/CVE-2017-12426&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12542
 &lt;div id="cve-2017-12542" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12542" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/skelsec/CVE-2017-12542" target="_blank" rel="noreferrer"&gt;skelsec/CVE-2017-12542&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sk1dish/ilo4-rce-vuln-scanner" target="_blank" rel="noreferrer"&gt;sk1dish/ilo4-rce-vuln-scanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12611
 &lt;div id="cve-2017-12611" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12611" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/S2-053-CVE-2017-12611" target="_blank" rel="noreferrer"&gt;brianwrf/S2-053-CVE-2017-12611&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12615
 &lt;div id="cve-2017-12615" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12615" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/breaktoprotect/CVE-2017-12615" target="_blank" rel="noreferrer"&gt;breaktoprotect/CVE-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mefulton/cve-2017-12615" target="_blank" rel="noreferrer"&gt;mefulton/cve-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717" target="_blank" rel="noreferrer"&gt;zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2017-12615" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wsg00d/cve-2017-12615" target="_blank" rel="noreferrer"&gt;wsg00d/cve-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2017-12615" target="_blank" rel="noreferrer"&gt;1337g/CVE-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Shellkeys/CVE-2017-12615" target="_blank" rel="noreferrer"&gt;Shellkeys/CVE-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-12615" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2017-12615" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2017-12615&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12617
 &lt;div id="cve-2017-12617" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12617" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cyberheartmi9/CVE-2017-12617" target="_blank" rel="noreferrer"&gt;cyberheartmi9/CVE-2017-12617&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/devcoinfet/CVE-2017-12617" target="_blank" rel="noreferrer"&gt;devcoinfet/CVE-2017-12617&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qiantu88/CVE-2017-12617" target="_blank" rel="noreferrer"&gt;qiantu88/CVE-2017-12617&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ygouzerh/CVE-2017-12617" target="_blank" rel="noreferrer"&gt;ygouzerh/CVE-2017-12617&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12624
 &lt;div id="cve-2017-12624" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12624" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property &amp;quot;attachment-max-header-size&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2017-12624" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2017-12624&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12635
 &lt;div id="cve-2017-12635" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12635" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available in the JSON, the second one will be used for authorising the document write, but the first 'roles' key is used for subsequent authorization for the newly created user. By design, users can not assign themselves roles. The vulnerability allows non-admin users to give themselves admin privileges.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/assalielmehdi/CVE-2017-12635" target="_blank" rel="noreferrer"&gt;assalielmehdi/CVE-2017-12635&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12636
 &lt;div id="cve-2017-12636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/moayadalmalat/CVE-2017-12636" target="_blank" rel="noreferrer"&gt;moayadalmalat/CVE-2017-12636&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/F1uffyGoat/F1uffyCouchDB" target="_blank" rel="noreferrer"&gt;F1uffyGoat/F1uffyCouchDB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RedTeamWing/CVE-2017-12636" target="_blank" rel="noreferrer"&gt;RedTeamWing/CVE-2017-12636&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12792
 &lt;div id="cve-2017-12792" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12792" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ZZS2017/cve-2017-12792" target="_blank" rel="noreferrer"&gt;ZZS2017/cve-2017-12792&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12852
 &lt;div id="cve-2017-12852" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12852" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BT123/numpy-1.13.1" target="_blank" rel="noreferrer"&gt;BT123/numpy-1.13.1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12943
 &lt;div id="cve-2017-12943" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12943" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aymankhalfatni/D-Link" target="_blank" rel="noreferrer"&gt;aymankhalfatni/D-Link&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-12945
 &lt;div id="cve-2017-12945" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-12945" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aress31/cve-2017-12945" target="_blank" rel="noreferrer"&gt;aress31/cve-2017-12945&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-13089
 &lt;div id="cve-2017-13089" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-13089" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's length, but doesn't check that the chunk length is a non-negative number. The code then tries to skip the chunk in pieces of 512 bytes by using the MIN() macro, but ends up passing the negative chunk length to connect.c:fd_read(). As fd_read() takes an int argument, the high 32 bits of the chunk length are discarded, leaving fd_read() with a completely attacker controlled length argument.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/r1b/CVE-2017-13089" target="_blank" rel="noreferrer"&gt;r1b/CVE-2017-13089&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mzeyong/CVE-2017-13089" target="_blank" rel="noreferrer"&gt;mzeyong/CVE-2017-13089&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-13156
 &lt;div id="cve-2017-13156" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-13156" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xyzAsian/Janus-CVE-2017-13156" target="_blank" rel="noreferrer"&gt;xyzAsian/Janus-CVE-2017-13156&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/caxmd/CVE-2017-13156" target="_blank" rel="noreferrer"&gt;caxmd/CVE-2017-13156&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/giacomoferretti/janus-toolkit" target="_blank" rel="noreferrer"&gt;giacomoferretti/janus-toolkit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-13253
 &lt;div id="cve-2017-13253" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-13253" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71389378.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tamirzb/CVE-2017-13253" target="_blank" rel="noreferrer"&gt;tamirzb/CVE-2017-13253&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-13672
 &lt;div id="cve-2017-13672" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-13672" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DavidBuchanan314/CVE-2017-13672" target="_blank" rel="noreferrer"&gt;DavidBuchanan314/CVE-2017-13672&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-13868
 &lt;div id="cve-2017-13868" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-13868" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/ctl_ctloutput-leak" target="_blank" rel="noreferrer"&gt;bazad/ctl_ctloutput-leak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-13872
 &lt;div id="cve-2017-13872" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-13872" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the &amp;quot;Directory Utility&amp;quot; component. It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/giovannidispoto/CVE-2017-13872-Patch" target="_blank" rel="noreferrer"&gt;giovannidispoto/CVE-2017-13872-Patch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14105
 &lt;div id="cve-2017-14105" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14105" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An authenticated, local attacker - even restricted as a tenant - can add a jsp at HiveManager/tomcat/webapps/hm/domains/$yourtenant/maps (it will be exposed at the web interface).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/theguly/CVE-2017-14105" target="_blank" rel="noreferrer"&gt;theguly/CVE-2017-14105&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14262
 &lt;div id="cve-2017-14262" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14262" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zzz66686/CVE-2017-14262" target="_blank" rel="noreferrer"&gt;zzz66686/CVE-2017-14262&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14263
 &lt;div id="cve-2017-14263" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14263" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zzz66686/CVE-2017-14263" target="_blank" rel="noreferrer"&gt;zzz66686/CVE-2017-14263&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14322
 &lt;div id="cve-2017-14322" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14322" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/joesmithjaffa/CVE-2017-14322" target="_blank" rel="noreferrer"&gt;joesmithjaffa/CVE-2017-14322&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14491
 &lt;div id="cve-2017-14491" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14491" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/YIHSUEHTsai/dnsmasq-2.4.1-fix-CVE-2017-14491" target="_blank" rel="noreferrer"&gt;YIHSUEHTsai/dnsmasq-2.4.1-fix-CVE-2017-14491&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14493
 &lt;div id="cve-2017-14493" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14493" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pupiles/bof-dnsmasq-cve-2017-14493" target="_blank" rel="noreferrer"&gt;pupiles/bof-dnsmasq-cve-2017-14493&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14719
 &lt;div id="cve-2017-14719" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14719" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/PalmTreeForest/CodePath_Week_7-8" target="_blank" rel="noreferrer"&gt;PalmTreeForest/CodePath_Week_7-8&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-14948
 &lt;div id="cve-2017-14948" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-14948" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/badnack/d_link_880_bug" target="_blank" rel="noreferrer"&gt;badnack/d_link_880_bug&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15120
 &lt;div id="cve-2017-15120" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15120" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remote attacker could cause a denial of service.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shutingrz/CVE-2017-15120_PoC" target="_blank" rel="noreferrer"&gt;shutingrz/CVE-2017-15120_PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15277
 &lt;div id="cve-2017-15277" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15277" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tacticthreat/ImageMagick-CVE-2017-15277" target="_blank" rel="noreferrer"&gt;tacticthreat/ImageMagick-CVE-2017-15277&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15303
 &lt;div id="cve-2017-15303" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15303" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., cpuz141_x64.sys for version 1.41).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hfiref0x/Stryker" target="_blank" rel="noreferrer"&gt;hfiref0x/Stryker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15361
 &lt;div id="cve-2017-15361" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15361" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lva/Infineon-CVE-2017-15361" target="_blank" rel="noreferrer"&gt;lva/Infineon-CVE-2017-15361&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/titanous/rocacheck" target="_blank" rel="noreferrer"&gt;titanous/rocacheck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jnpuskar/RocaCmTest" target="_blank" rel="noreferrer"&gt;jnpuskar/RocaCmTest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nsacyber/Detect-CVE-2017-15361-TPM" target="_blank" rel="noreferrer"&gt;nsacyber/Detect-CVE-2017-15361-TPM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xxon/zeek-plugin-roca" target="_blank" rel="noreferrer"&gt;0xxon/zeek-plugin-roca&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xxon/roca" target="_blank" rel="noreferrer"&gt;0xxon/roca&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15394
 &lt;div id="cve-2017-15394" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15394" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sudosammy/CVE-2017-15394" target="_blank" rel="noreferrer"&gt;sudosammy/CVE-2017-15394&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15708
 &lt;div id="cve-2017-15708" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15708" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2017-15708" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2017-15708&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15715
 &lt;div id="cve-2017-15715" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15715" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache httpd 2.4.0 to 2.4.29, the expression specified in &amp;lt;FilesMatch&amp;gt; could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whisp1830/CVE-2017-15715" target="_blank" rel="noreferrer"&gt;whisp1830/CVE-2017-15715&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-15944
 &lt;div id="cve-2017-15944" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-15944" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xxnbyy/CVE-2017-15944-POC" target="_blank" rel="noreferrer"&gt;xxnbyy/CVE-2017-15944-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/surajraghuvanshi/PaloAltoRceDetectionAndExploit" target="_blank" rel="noreferrer"&gt;surajraghuvanshi/PaloAltoRceDetectionAndExploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16082
 &lt;div id="cve-2017-16082" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16082" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nulldreams/CVE-2017-16082" target="_blank" rel="noreferrer"&gt;nulldreams/CVE-2017-16082&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16088
 &lt;div id="cve-2017-16088" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16088" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Flyy-yu/CVE-2017-16088" target="_blank" rel="noreferrer"&gt;Flyy-yu/CVE-2017-16088&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16245
 &lt;div id="cve-2017-16245" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16245" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/AOCorsaire/CVE-2017-16245" target="_blank" rel="noreferrer"&gt;AOCorsaire/CVE-2017-16245&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-1635
 &lt;div id="cve-2017-1635" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-1635" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/emcalv/tivoli-poc" target="_blank" rel="noreferrer"&gt;emcalv/tivoli-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16524
 &lt;div id="cve-2017-16524" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16524" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a direct request to the file in the upload/ directory. To authenticate for this attack, one can obtain web-interface credentials in cleartext by leveraging the existing Local File Read Vulnerability referenced as CVE-2015-8279, which allows remote attackers to read the web-interface credentials via a request for the cslog_export.php?path=/root/php_modules/lighttpd/sbin/userpw URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/realistic-security/CVE-2017-16524" target="_blank" rel="noreferrer"&gt;realistic-security/CVE-2017-16524&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16567
 &lt;div id="cve-2017-16567" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16567" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a &amp;quot;favorite.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dewankpant/CVE-2017-16567" target="_blank" rel="noreferrer"&gt;dewankpant/CVE-2017-16567&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16568
 &lt;div id="cve-2017-16568" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16568" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dewankpant/CVE-2017-16568" target="_blank" rel="noreferrer"&gt;dewankpant/CVE-2017-16568&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16744
 &lt;div id="cve-2017-16744" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16744" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GainSec/CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara" target="_blank" rel="noreferrer"&gt;GainSec/CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16778
 &lt;div id="cve-2017-16778" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16778" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit owner may allow such an access grant. However, due to incorrect access control, an attacker could inject it via the speaker unit to perform an access grant to gain unauthorized access, as demonstrated by a loud DTMF tone representing '1' and a long '#' (697 Hz and 1209 Hz, followed by 941 Hz and 1477 Hz).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/breaktoprotect/CVE-2017-16778-Intercom-DTMF-Injection" target="_blank" rel="noreferrer"&gt;breaktoprotect/CVE-2017-16778-Intercom-DTMF-Injection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16806
 &lt;div id="cve-2017-16806" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16806" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rickoooooo/ulteriusExploit" target="_blank" rel="noreferrer"&gt;rickoooooo/ulteriusExploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16943
 &lt;div id="cve-2017-16943" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16943" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/beraphin/CVE-2017-16943" target="_blank" rel="noreferrer"&gt;beraphin/CVE-2017-16943&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16995
 &lt;div id="cve-2017-16995" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16995" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/CVE-2017-16995" target="_blank" rel="noreferrer"&gt;RealBearcat/CVE-2017-16995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Al1ex/CVE-2017-16995" target="_blank" rel="noreferrer"&gt;Al1ex/CVE-2017-16995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gugronnier/CVE-2017-16995" target="_blank" rel="noreferrer"&gt;gugronnier/CVE-2017-16995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/senyuuri/cve-2017-16995" target="_blank" rel="noreferrer"&gt;senyuuri/cve-2017-16995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vnik5287/CVE-2017-16995" target="_blank" rel="noreferrer"&gt;vnik5287/CVE-2017-16995&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/littlebin404/CVE-2017-16995" target="_blank" rel="noreferrer"&gt;littlebin404/CVE-2017-16995&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-16997
 &lt;div id="cve-2017-16997" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-16997" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the &amp;quot;./&amp;quot; directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Xiami2012/CVE-2017-16997-poc" target="_blank" rel="noreferrer"&gt;Xiami2012/CVE-2017-16997-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-17099
 &lt;div id="cve-2017-17099" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-17099" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wetw0rk/Exploit-Development" target="_blank" rel="noreferrer"&gt;wetw0rk/Exploit-Development&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-17215
 &lt;div id="cve-2017-17215" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-17215" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2017-17215" target="_blank" rel="noreferrer"&gt;1337g/CVE-2017-17215&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-17309
 &lt;div id="cve-2017-17309" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-17309" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/exploit-labs/huawei_hg255s_exploit" target="_blank" rel="noreferrer"&gt;exploit-labs/huawei_hg255s_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-17485
 &lt;div id="cve-2017-17485" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-17485" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/Jackson-CVE-2017-17485" target="_blank" rel="noreferrer"&gt;RealBearcat/Jackson-CVE-2017-17485&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2017-17485" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2017-17485&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x7iaob/cve-2017-17485" target="_blank" rel="noreferrer"&gt;x7iaob/cve-2017-17485&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-17562
 &lt;div id="cve-2017-17562" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-17562" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2017-17562" target="_blank" rel="noreferrer"&gt;1337g/CVE-2017-17562&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ivanitlearning/CVE-2017-17562" target="_blank" rel="noreferrer"&gt;ivanitlearning/CVE-2017-17562&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/crispy-peppers/Goahead-CVE-2017-17562" target="_blank" rel="noreferrer"&gt;crispy-peppers/Goahead-CVE-2017-17562&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-17692
 &lt;div id="cve-2017-17692" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-17692" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lr3800/CVE-2017-17692" target="_blank" rel="noreferrer"&gt;lr3800/CVE-2017-17692&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-18044
 &lt;div id="cve-2017-18044" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-18044" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to CreateProcess. As a result, a specially crafted message can inject commands that will be executed on the target operating system. Exploitation of this vulnerability does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon. This is a different vulnerability than CVE-2017-3195.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2017-18044-Exploit" target="_blank" rel="noreferrer"&gt;securifera/CVE-2017-18044-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-18345
 &lt;div id="cve-2017-18345" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-18345" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&amp;amp;controller=details&amp;amp;task=download&amp;amp;path=configuration.php request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Luth1er/CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD" target="_blank" rel="noreferrer"&gt;Luth1er/CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-18486
 &lt;div id="cve-2017-18486" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-18486" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Kc57/JitBit_Helpdesk_Auth_Bypass" target="_blank" rel="noreferrer"&gt;Kc57/JitBit_Helpdesk_Auth_Bypass&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-18635
 &lt;div id="cve-2017-18635" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-18635" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ShielderSec/CVE-2017-18635" target="_blank" rel="noreferrer"&gt;ShielderSec/CVE-2017-18635&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2368
 &lt;div id="cve-2017-2368" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2368" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the &amp;quot;Contacts&amp;quot; component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vincedes3/CVE-2017-2368" target="_blank" rel="noreferrer"&gt;vincedes3/CVE-2017-2368&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2370
 &lt;div id="cve-2017-2370" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2370" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/maximehip/extra_recipe" target="_blank" rel="noreferrer"&gt;maximehip/extra_recipe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JackBro/extra_recipe" target="_blank" rel="noreferrer"&gt;JackBro/extra_recipe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Rootkitsmm/extra_recipe-iOS-10.2" target="_blank" rel="noreferrer"&gt;Rootkitsmm/extra_recipe-iOS-10.2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Peterpan0927/CVE-2017-2370" target="_blank" rel="noreferrer"&gt;Peterpan0927/CVE-2017-2370&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2388
 &lt;div id="cve-2017-2388" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2388" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the &amp;quot;IOFireWireFamily&amp;quot; component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/IOFireWireFamily-null-deref" target="_blank" rel="noreferrer"&gt;bazad/IOFireWireFamily-null-deref&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2636
 &lt;div id="cve-2017-2636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alexzorin/cve-2017-2636-el" target="_blank" rel="noreferrer"&gt;alexzorin/cve-2017-2636-el&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2666
 &lt;div id="cve-2017-2666" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2666" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2017-2666" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2017-2666&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2671
 &lt;div id="cve-2017-2671" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2671" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-2671" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-2671&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2751
 &lt;div id="cve-2017-2751" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2751" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BaderSZ/CVE-2017-2751" target="_blank" rel="noreferrer"&gt;BaderSZ/CVE-2017-2751&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-2793
 &lt;div id="cve-2017-2793" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-2793" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/r0otshell/Detection-for-CVE-2017-2793" target="_blank" rel="noreferrer"&gt;r0otshell/Detection-for-CVE-2017-2793&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3000
 &lt;div id="cve-2017-3000" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3000" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generator used for constant blinding. Successful exploitation could lead to information disclosure.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dangokyo/CVE-2017-3000" target="_blank" rel="noreferrer"&gt;dangokyo/CVE-2017-3000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3066
 &lt;div id="cve-2017-3066" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3066" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/codewhitesec/ColdFusionPwn" target="_blank" rel="noreferrer"&gt;codewhitesec/ColdFusionPwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cucadili/CVE-2017-3066" target="_blank" rel="noreferrer"&gt;cucadili/CVE-2017-3066&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3078
 &lt;div id="cve-2017-3078" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3078" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-3078" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-3078&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3143
 &lt;div id="cve-2017-3143" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3143" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0-&amp;gt;9.8.8, 9.9.0-&amp;gt;9.9.10-P1, 9.10.0-&amp;gt;9.10.5-P1, 9.11.0-&amp;gt;9.11.1-P1, 9.9.3-S1-&amp;gt;9.9.10-S2, 9.10.5-S1-&amp;gt;9.10.5-S2.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/saaph/CVE-2017-3143" target="_blank" rel="noreferrer"&gt;saaph/CVE-2017-3143&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3241
 &lt;div id="cve-2017-3241" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3241" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS v3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xfei3/CVE-2017-3241-POC" target="_blank" rel="noreferrer"&gt;xfei3/CVE-2017-3241-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3248
 &lt;div id="cve-2017-3248" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3248" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS v3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2017-3248" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2017-3248&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xn0ne/weblogicScanner" target="_blank" rel="noreferrer"&gt;0xn0ne/weblogicScanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3506
 &lt;div id="cve-2017-3506" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3506" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2017-3506" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2017-3506&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3599
 &lt;div id="cve-2017-3599" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3599" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily &amp;quot;exploitable&amp;quot; vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue is an integer overflow in sql/auth/sql_authentication.cc which allows remote attackers to cause a denial of service via a crafted authentication packet.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2017-3599" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2017-3599&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3730
 &lt;div id="cve-2017-3730" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3730" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guidovranken/CVE-2017-3730" target="_blank" rel="noreferrer"&gt;guidovranken/CVE-2017-3730&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ymmah/OpenSSL-CVE-2017-3730" target="_blank" rel="noreferrer"&gt;ymmah/OpenSSL-CVE-2017-3730&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-3881
 &lt;div id="cve-2017-3881" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-3881" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/artkond/cisco-rce" target="_blank" rel="noreferrer"&gt;artkond/cisco-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-3881-exploit-cisco-" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-3881-exploit-cisco-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-3881-Cisco" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-3881-Cisco&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zakybstrd21215/PoC-CVE-2017-3881" target="_blank" rel="noreferrer"&gt;zakybstrd21215/PoC-CVE-2017-3881&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1337g/CVE-2017-3881" target="_blank" rel="noreferrer"&gt;1337g/CVE-2017-3881&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-4490
 &lt;div id="cve-2017-4490" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-4490" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-4490-" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-4490-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-4490-install-Script-Python-in-Terminal-" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-4490-install-Script-Python-in-Terminal-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-4878
 &lt;div id="cve-2017-4878" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-4878" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/CVE-2017-4878-Samples" target="_blank" rel="noreferrer"&gt;brianwrf/CVE-2017-4878-Samples&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-4971
 &lt;div id="cve-2017-4971" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-4971" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-4971" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-4971&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5005
 &lt;div id="cve-2017-5005" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5005" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/payatu/QuickHeal" target="_blank" rel="noreferrer"&gt;payatu/QuickHeal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5007
 &lt;div id="cve-2017-5007" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5007" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ang-YC/CVE-2017-5007" target="_blank" rel="noreferrer"&gt;Ang-YC/CVE-2017-5007&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5123
 &lt;div id="cve-2017-5123" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5123" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FloatingGuy/CVE-2017-5123" target="_blank" rel="noreferrer"&gt;FloatingGuy/CVE-2017-5123&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x5068656e6f6c/CVE-2017-5123" target="_blank" rel="noreferrer"&gt;0x5068656e6f6c/CVE-2017-5123&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Synacktiv-contrib/exploiting-cve-2017-5123" target="_blank" rel="noreferrer"&gt;Synacktiv-contrib/exploiting-cve-2017-5123&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/teawater/CVE-2017-5123" target="_blank" rel="noreferrer"&gt;teawater/CVE-2017-5123&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5124
 &lt;div id="cve-2017-5124" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5124" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Bo0oM/CVE-2017-5124" target="_blank" rel="noreferrer"&gt;Bo0oM/CVE-2017-5124&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5223
 &lt;div id="cve-2017-5223" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5223" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to /, meaning that relative image URLs get treated as absolute local file paths and added as attachments. To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cscli/CVE-2017-5223" target="_blank" rel="noreferrer"&gt;cscli/CVE-2017-5223&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5415
 &lt;div id="cve-2017-5415" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5415" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by &amp;quot;blob:&amp;quot; as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox &amp;lt; 52.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/649/CVE-2017-5415" target="_blank" rel="noreferrer"&gt;649/CVE-2017-5415&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5487
 &lt;div id="cve-2017-5487" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5487" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/teambugsbunny/wpUsersScan" target="_blank" rel="noreferrer"&gt;teambugsbunny/wpUsersScan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/R3K1NG/wpUsersScan" target="_blank" rel="noreferrer"&gt;R3K1NG/wpUsersScan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GeunSam2/CVE-2017-5487" target="_blank" rel="noreferrer"&gt;GeunSam2/CVE-2017-5487&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/patilkr/wp-CVE-2017-5487-exploit" target="_blank" rel="noreferrer"&gt;patilkr/wp-CVE-2017-5487-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5633
 &lt;div id="cve-2017-5633" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5633" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cardangi/Exploit-CVE-2017-5633" target="_blank" rel="noreferrer"&gt;cardangi/Exploit-CVE-2017-5633&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5638
 &lt;div id="cve-2017-5638" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5638" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/PolarisLab/S2-045" target="_blank" rel="noreferrer"&gt;PolarisLab/S2-045&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Flyteas/Struts2-045-Exp" target="_blank" rel="noreferrer"&gt;Flyteas/Struts2-045-Exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bongbongco/cve-2017-5638" target="_blank" rel="noreferrer"&gt;bongbongco/cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/S2-045-EXP-POC-TOOLS" target="_blank" rel="noreferrer"&gt;jas502n/S2-045-EXP-POC-TOOLS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mthbernardes/strutszeiro" target="_blank" rel="noreferrer"&gt;mthbernardes/strutszeiro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xsscx/cve-2017-5638" target="_blank" rel="noreferrer"&gt;xsscx/cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/immunio/apache-struts2-CVE-2017-5638" target="_blank" rel="noreferrer"&gt;immunio/apache-struts2-CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Masahiro-Yamada/OgnlContentTypeRejectorValve" target="_blank" rel="noreferrer"&gt;Masahiro-Yamada/OgnlContentTypeRejectorValve&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aljazceru/CVE-2017-5638-Apache-Struts2" target="_blank" rel="noreferrer"&gt;aljazceru/CVE-2017-5638-Apache-Struts2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sjitech/test_struts2_vulnerability_CVE-2017-5638" target="_blank" rel="noreferrer"&gt;sjitech/test_struts2_vulnerability_CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jrrombaldo/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;jrrombaldo/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/random-robbie/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;random-robbie/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/initconf/CVE-2017-5638_struts" target="_blank" rel="noreferrer"&gt;initconf/CVE-2017-5638_struts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mazen160/struts-pwn" target="_blank" rel="noreferrer"&gt;mazen160/struts-pwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ret2jazzy/Struts-Apache-ExploitPack" target="_blank" rel="noreferrer"&gt;ret2jazzy/Struts-Apache-ExploitPack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lolwaleet/ExpStruts" target="_blank" rel="noreferrer"&gt;lolwaleet/ExpStruts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oktavianto/CVE-2017-5638-Apache-Struts2" target="_blank" rel="noreferrer"&gt;oktavianto/CVE-2017-5638-Apache-Struts2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jrrdev/cve-2017-5638" target="_blank" rel="noreferrer"&gt;jrrdev/cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/opt9/Strutshock" target="_blank" rel="noreferrer"&gt;opt9/Strutshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/falcon-lnhg/StrutsShell" target="_blank" rel="noreferrer"&gt;falcon-lnhg/StrutsShell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bhagdave/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;bhagdave/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/st2-046-poc" target="_blank" rel="noreferrer"&gt;jas502n/st2-046-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KarzsGHR/S2-046_S2-045_POC" target="_blank" rel="noreferrer"&gt;KarzsGHR/S2-046_S2-045_POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gsfish/S2-Reaper" target="_blank" rel="noreferrer"&gt;gsfish/S2-Reaper&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mcassano/cve-2017-5638" target="_blank" rel="noreferrer"&gt;mcassano/cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/opt9/Strutscli" target="_blank" rel="noreferrer"&gt;opt9/Strutscli&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tahmed11/strutsy" target="_blank" rel="noreferrer"&gt;tahmed11/strutsy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/payatu/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;payatu/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Aasron/Struts2-045-Exp" target="_blank" rel="noreferrer"&gt;Aasron/Struts2-045-Exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SpiderMate/Stutsfi" target="_blank" rel="noreferrer"&gt;SpiderMate/Stutsfi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jpacora/Struts2Shell" target="_blank" rel="noreferrer"&gt;jpacora/Struts2Shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NyaMeeEain/Apache-Struts" target="_blank" rel="noreferrer"&gt;NyaMeeEain/Apache-Struts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AndreasKl/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;AndreasKl/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/riyazwalikar/struts-rce-cve-2017-5638" target="_blank" rel="noreferrer"&gt;riyazwalikar/struts-rce-cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eeehit/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;eeehit/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r0otshell/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner" target="_blank" rel="noreferrer"&gt;r0otshell/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r0otshell/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638" target="_blank" rel="noreferrer"&gt;r0otshell/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-" target="_blank" rel="noreferrer"&gt;R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Xhendos/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;Xhendos/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TamiiLambrado/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner" target="_blank" rel="noreferrer"&gt;TamiiLambrado/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/S2-045" target="_blank" rel="noreferrer"&gt;RealBearcat/S2-045&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/invisiblethreat/strutser" target="_blank" rel="noreferrer"&gt;invisiblethreat/strutser&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lizhi16/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;lizhi16/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/donaldashdown/Common-Vulnerability-and-Exploit" target="_blank" rel="noreferrer"&gt;donaldashdown/Common-Vulnerability-and-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/grant100/cybersecurity-struts2" target="_blank" rel="noreferrer"&gt;grant100/cybersecurity-struts2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cafnet/apache-struts-v2-CVE-2017-5638" target="_blank" rel="noreferrer"&gt;cafnet/apache-struts-v2-CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/m3ssap0/struts2_cve-2017-5638" target="_blank" rel="noreferrer"&gt;m3ssap0/struts2_cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Greynad/struts2-jakarta-inject" target="_blank" rel="noreferrer"&gt;Greynad/struts2-jakarta-inject&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ggolawski/struts-rce" target="_blank" rel="noreferrer"&gt;ggolawski/struts-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/win3zz/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;win3zz/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leandrocamposcardoso/CVE-2017-5638-Mass-Exploit" target="_blank" rel="noreferrer"&gt;leandrocamposcardoso/CVE-2017-5638-Mass-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Iletee/struts2-rce" target="_blank" rel="noreferrer"&gt;Iletee/struts2-rce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/andypitcher/check_struts" target="_blank" rel="noreferrer"&gt;andypitcher/check_struts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/un4ckn0wl3z/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;un4ckn0wl3z/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/colorblindpentester/CVE-2017-5638" target="_blank" rel="noreferrer"&gt;colorblindpentester/CVE-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/injcristianrojas/cve-2017-5638" target="_blank" rel="noreferrer"&gt;injcristianrojas/cve-2017-5638&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5645
 &lt;div id="cve-2017-5645" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5645" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pimps/CVE-2017-5645" target="_blank" rel="noreferrer"&gt;pimps/CVE-2017-5645&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5689
 &lt;div id="cve-2017-5689" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5689" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CerberusSecurity/CVE-2017-5689" target="_blank" rel="noreferrer"&gt;CerberusSecurity/CVE-2017-5689&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/x1sec/amthoneypot" target="_blank" rel="noreferrer"&gt;x1sec/amthoneypot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Bijaye/intel_amt_bypass" target="_blank" rel="noreferrer"&gt;Bijaye/intel_amt_bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/embedi/amt_auth_bypass_poc" target="_blank" rel="noreferrer"&gt;embedi/amt_auth_bypass_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5693
 &lt;div id="cve-2017-5693" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5693" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Firmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network attacker to create a denial of service via crafted network traffic.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nallar/Puma6Fail" target="_blank" rel="noreferrer"&gt;nallar/Puma6Fail&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5715
 &lt;div id="cve-2017-5715" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5715" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-cve-2017-5715" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-cve-2017-5715&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mathse/meltdown-spectre-bios-list" target="_blank" rel="noreferrer"&gt;mathse/meltdown-spectre-bios-list&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GregAskew/SpeculativeExecutionAssessment" target="_blank" rel="noreferrer"&gt;GregAskew/SpeculativeExecutionAssessment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dmo2118/retpoline-audit" target="_blank" rel="noreferrer"&gt;dmo2118/retpoline-audit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5721
 &lt;div id="cve-2017-5721" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5721" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/embedi/smm_usbrt_poc" target="_blank" rel="noreferrer"&gt;embedi/smm_usbrt_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5753
 &lt;div id="cve-2017-5753" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5753" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Eugnis/spectre-attack" target="_blank" rel="noreferrer"&gt;Eugnis/spectre-attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/EdwardOwusuAdjei/Spectre-PoC" target="_blank" rel="noreferrer"&gt;EdwardOwusuAdjei/Spectre-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/poilynx/spectre-attack-example" target="_blank" rel="noreferrer"&gt;poilynx/spectre-attack-example&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xsscx/cve-2017-5753" target="_blank" rel="noreferrer"&gt;xsscx/cve-2017-5753&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pedrolucasoliva/spectre-attack-demo" target="_blank" rel="noreferrer"&gt;pedrolucasoliva/spectre-attack-demo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ixtal23/spectreScope" target="_blank" rel="noreferrer"&gt;ixtal23/spectreScope&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5754
 &lt;div id="cve-2017-5754" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5754" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ionescu007/SpecuCheck" target="_blank" rel="noreferrer"&gt;ionescu007/SpecuCheck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/raphaelsc/Am-I-affected-by-Meltdown" target="_blank" rel="noreferrer"&gt;raphaelsc/Am-I-affected-by-Meltdown&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Viralmaniar/In-Spectre-Meltdown" target="_blank" rel="noreferrer"&gt;Viralmaniar/In-Spectre-Meltdown&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/speecyy/Am-I-affected-by-Meltdown" target="_blank" rel="noreferrer"&gt;speecyy/Am-I-affected-by-Meltdown&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zzado/Meltdown" target="_blank" rel="noreferrer"&gt;zzado/Meltdown&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jdmulloy/meltdown-aws-scanner" target="_blank" rel="noreferrer"&gt;jdmulloy/meltdown-aws-scanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-5792
 &lt;div id="cve-2017-5792" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-5792" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/HPE-iMC-7.3-RMI-Java-Deserialization" target="_blank" rel="noreferrer"&gt;RealBearcat/HPE-iMC-7.3-RMI-Java-Deserialization&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6008
 &lt;div id="cve-2017-6008" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6008" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cbayet/Exploit-CVE-2017-6008" target="_blank" rel="noreferrer"&gt;cbayet/Exploit-CVE-2017-6008&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6074
 &lt;div id="cve-2017-6074" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6074" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/node1392/Linux-Kernel-Vulnerability" target="_blank" rel="noreferrer"&gt;node1392/Linux-Kernel-Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6079
 &lt;div id="cve-2017-6079" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6079" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MostafaSoliman/CVE-2017-6079-Blind-Command-Injection-In-Edgewater-Edgemarc-Devices-Exploit" target="_blank" rel="noreferrer"&gt;MostafaSoliman/CVE-2017-6079-Blind-Command-Injection-In-Edgewater-Edgemarc-Devices-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6090
 &lt;div id="cve-2017-6090" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6090" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jlk/exploit-CVE-2017-6090" target="_blank" rel="noreferrer"&gt;jlk/exploit-CVE-2017-6090&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6206
 &lt;div id="cve-2017-6206" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6206" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/varangamin/CVE-2017-6206" target="_blank" rel="noreferrer"&gt;varangamin/CVE-2017-6206&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6370
 &lt;div id="cve-2017-6370" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6370" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request" target="_blank" rel="noreferrer"&gt;faizzaidi/TYPO3-v7.6.15-Unencrypted-Login-Request&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6558
 &lt;div id="cve-2017-6558" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6558" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GemGeorge/iBall-UTStar-CVEChecker" target="_blank" rel="noreferrer"&gt;GemGeorge/iBall-UTStar-CVEChecker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6640
 &lt;div id="cve-2017-6640" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6640" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to the affected software by using the credentials for this default user account. A successful exploit could allow the attacker to use this default user account to log in to the affected software and gain access to the administrative console of a DCNM server. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software releases prior to Release 10.2(1) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd95346.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hemp3l/CVE-2017-6640-POC" target="_blank" rel="noreferrer"&gt;hemp3l/CVE-2017-6640-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6736
 &lt;div id="cve-2017-6736" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6736" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. Cisco Bug IDs: CSCve57697.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GarnetSunset/CiscoSpectreTakeover" target="_blank" rel="noreferrer"&gt;GarnetSunset/CiscoSpectreTakeover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GarnetSunset/CiscoIOSSNMPToolkit" target="_blank" rel="noreferrer"&gt;GarnetSunset/CiscoIOSSNMPToolkit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6913
 &lt;div id="cve-2017-6913" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6913" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gquere/CVE-2017-6913" target="_blank" rel="noreferrer"&gt;gquere/CVE-2017-6913&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-6971
 &lt;div id="cve-2017-6971" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-6971" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault ID ENG-104862.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patrickfreed/nfsen-exploit" target="_blank" rel="noreferrer"&gt;patrickfreed/nfsen-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KeyStrOke95/nfsen_1.3.7_CVE-2017-6971" target="_blank" rel="noreferrer"&gt;KeyStrOke95/nfsen_1.3.7_CVE-2017-6971&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7038
 &lt;div id="cve-2017-7038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the &amp;quot;WebKit&amp;quot; component.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ansjdnakjdnajkd/CVE-2017-7038" target="_blank" rel="noreferrer"&gt;ansjdnakjdnajkd/CVE-2017-7038&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7047
 &lt;div id="cve-2017-7047" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7047" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the &amp;quot;libxpc&amp;quot; component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JosephShenton/Triple_Fetch-Kernel-Creds" target="_blank" rel="noreferrer"&gt;JosephShenton/Triple_Fetch-Kernel-Creds&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/q1f3/Triple_fetch" target="_blank" rel="noreferrer"&gt;q1f3/Triple_fetch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7061
 &lt;div id="cve-2017-7061" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7061" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the &amp;quot;WebKit&amp;quot; component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TheLoneHaxor/jailbreakme103" target="_blank" rel="noreferrer"&gt;TheLoneHaxor/jailbreakme103&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7089
 &lt;div id="cve-2017-7089" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7089" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the &amp;quot;WebKit&amp;quot; component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Bo0oM/CVE-2017-7089" target="_blank" rel="noreferrer"&gt;Bo0oM/CVE-2017-7089&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aymankhalfatni/Safari_Mac" target="_blank" rel="noreferrer"&gt;aymankhalfatni/Safari_Mac&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7092
 &lt;div id="cve-2017-7092" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7092" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the &amp;quot;WebKit&amp;quot; component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xuechiyaobai/CVE-2017-7092-PoC" target="_blank" rel="noreferrer"&gt;xuechiyaobai/CVE-2017-7092-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7173
 &lt;div id="cve-2017-7173" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7173" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/sysctl_coalition_get_pid_list-dos" target="_blank" rel="noreferrer"&gt;bazad/sysctl_coalition_get_pid_list-dos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7184
 &lt;div id="cve-2017-7184" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7184" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rockl/cve-2017-7184" target="_blank" rel="noreferrer"&gt;rockl/cve-2017-7184&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rockl/cve-2017-7184-bak" target="_blank" rel="noreferrer"&gt;rockl/cve-2017-7184-bak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7188
 &lt;div id="cve-2017-7188" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7188" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/faizzaidi/Zurmo-Stable-3.1.1-XSS-By-Provensec-LLC" target="_blank" rel="noreferrer"&gt;faizzaidi/Zurmo-Stable-3.1.1-XSS-By-Provensec-LLC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7269
 &lt;div id="cve-2017-7269" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7269" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with &amp;quot;If: &amp;lt;http://&amp;quot; in a PROPFIND request, as exploited in the wild in July or August 2016.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/eliuha/webdav_exploit" target="_blank" rel="noreferrer"&gt;eliuha/webdav_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lcatro/CVE-2017-7269-Echo-PoC" target="_blank" rel="noreferrer"&gt;lcatro/CVE-2017-7269-Echo-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/caicai1355/CVE-2017-7269-exploit" target="_blank" rel="noreferrer"&gt;caicai1355/CVE-2017-7269-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/M1a0rz/CVE-2017-7269" target="_blank" rel="noreferrer"&gt;M1a0rz/CVE-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/whiteHat001/cve-2017-7269picture" target="_blank" rel="noreferrer"&gt;whiteHat001/cve-2017-7269picture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zcgonvh/cve-2017-7269" target="_blank" rel="noreferrer"&gt;zcgonvh/cve-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jrrombaldo/CVE-2017-7269" target="_blank" rel="noreferrer"&gt;jrrombaldo/CVE-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/g0rx/iis6-exploit-2017-CVE-2017-7269" target="_blank" rel="noreferrer"&gt;g0rx/iis6-exploit-2017-CVE-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/slimpagey/IIS_6.0_WebDAV_Ruby" target="_blank" rel="noreferrer"&gt;slimpagey/IIS_6.0_WebDAV_Ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/cve-2017-7269" target="_blank" rel="noreferrer"&gt;homjxi0e/cve-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xiaovpn/CVE-2017-7269" target="_blank" rel="noreferrer"&gt;xiaovpn/CVE-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zcgonvh/cve-2017-7269-tool" target="_blank" rel="noreferrer"&gt;zcgonvh/cve-2017-7269-tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mirrorblack/CVE-2017-7269" target="_blank" rel="noreferrer"&gt;mirrorblack/CVE-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Al1ex/CVE-2017-7269" target="_blank" rel="noreferrer"&gt;Al1ex/CVE-2017-7269&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7374
 &lt;div id="cve-2017-7374" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7374" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ww9210/cve-2017-7374" target="_blank" rel="noreferrer"&gt;ww9210/cve-2017-7374&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7472
 &lt;div id="cve-2017-7472" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7472" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-7472" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-7472&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7494
 &lt;div id="cve-2017-7494" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7494" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/betab0t/cve-2017-7494" target="_blank" rel="noreferrer"&gt;betab0t/cve-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-7494" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-CVE-2017-7494" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-CVE-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Waffles-2/SambaCry" target="_blank" rel="noreferrer"&gt;Waffles-2/SambaCry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/SambaHunter" target="_blank" rel="noreferrer"&gt;brianwrf/SambaHunter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/joxeankoret/CVE-2017-7494" target="_blank" rel="noreferrer"&gt;joxeankoret/CVE-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Zer0d0y/Samba-CVE-2017-7494" target="_blank" rel="noreferrer"&gt;Zer0d0y/Samba-CVE-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/incredible1yu/CVE-2017-7494" target="_blank" rel="noreferrer"&gt;incredible1yu/CVE-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-7494" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/john-80/cve-2017-7494" target="_blank" rel="noreferrer"&gt;john-80/cve-2017-7494&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7525
 &lt;div id="cve-2017-7525" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7525" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SecureSkyTechnology/study-struts2-s2-054_055-jackson-cve-2017-7525_cve-2017-15095" target="_blank" rel="noreferrer"&gt;SecureSkyTechnology/study-struts2-s2-054_055-jackson-cve-2017-7525_cve-2017-15095&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/S2-055" target="_blank" rel="noreferrer"&gt;RealBearcat/S2-055&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JavanXD/Demo-Exploit-Jackson-RCE" target="_blank" rel="noreferrer"&gt;JavanXD/Demo-Exploit-Jackson-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/47bwy/CVE-2017-7525" target="_blank" rel="noreferrer"&gt;47bwy/CVE-2017-7525&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BassinD/jackson-RCE" target="_blank" rel="noreferrer"&gt;BassinD/jackson-RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Dannners/jackson-deserialization-2017-7525" target="_blank" rel="noreferrer"&gt;Dannners/jackson-deserialization-2017-7525&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ingenuity-Fainting-Goats/CVE-2017-7525-Jackson-Deserialization-Lab" target="_blank" rel="noreferrer"&gt;Ingenuity-Fainting-Goats/CVE-2017-7525-Jackson-Deserialization-Lab&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7529
 &lt;div id="cve-2017-7529" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7529" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/liusec/CVE-2017-7529" target="_blank" rel="noreferrer"&gt;liusec/CVE-2017-7529&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/en0f/CVE-2017-7529_PoC" target="_blank" rel="noreferrer"&gt;en0f/CVE-2017-7529_PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-7529" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-7529&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mpalonso/ferni" target="_blank" rel="noreferrer"&gt;mpalonso/ferni&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MaxSecurity/CVE-2017-7529-POC" target="_blank" rel="noreferrer"&gt;MaxSecurity/CVE-2017-7529-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7648
 &lt;div id="cve-2017-7648" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7648" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/notmot/CVE-2017-7648." target="_blank" rel="noreferrer"&gt;notmot/CVE-2017-7648.&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7679
 &lt;div id="cve-2017-7679" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7679" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/snknritr/CVE-2017-7679-in-python" target="_blank" rel="noreferrer"&gt;snknritr/CVE-2017-7679-in-python&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7912
 &lt;div id="cve-2017-7912" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7912" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-7912_Sneak" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-7912_Sneak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7921
 &lt;div id="cve-2017-7921" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7921" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JrDw0/CVE-2017-7921-EXP" target="_blank" rel="noreferrer"&gt;JrDw0/CVE-2017-7921-EXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-7998
 &lt;div id="cve-2017-7998" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-7998" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username parameter to webapp/users/user_reg.jsp.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-7998" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-7998&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8046
 &lt;div id="cve-2017-8046" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8046" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Soontao/CVE-2017-8046-DEMO" target="_blank" rel="noreferrer"&gt;Soontao/CVE-2017-8046-DEMO&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sj/spring-data-rest-CVE-2017-8046" target="_blank" rel="noreferrer"&gt;sj/spring-data-rest-CVE-2017-8046&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/m3ssap0/SpringBreakVulnerableApp" target="_blank" rel="noreferrer"&gt;m3ssap0/SpringBreakVulnerableApp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/m3ssap0/spring-break_cve-2017-8046" target="_blank" rel="noreferrer"&gt;m3ssap0/spring-break_cve-2017-8046&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FixYourFace/SpringBreakPoC" target="_blank" rel="noreferrer"&gt;FixYourFace/SpringBreakPoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jkutner/spring-break-cve-2017-8046" target="_blank" rel="noreferrer"&gt;jkutner/spring-break-cve-2017-8046&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bkhablenko/CVE-2017-8046" target="_blank" rel="noreferrer"&gt;bkhablenko/CVE-2017-8046&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-8046" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-8046&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jsotiro/VulnerableSpringDataRest" target="_blank" rel="noreferrer"&gt;jsotiro/VulnerableSpringDataRest&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8295
 &lt;div id="cve-2017-8295" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8295" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-8295-WordPress-4.7.4---Unauthorized-Password-Reset" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-8295-WordPress-4.7.4&amp;mdash;Unauthorized-Password-Reset&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/alash3al/wp-allowed-hosts" target="_blank" rel="noreferrer"&gt;alash3al/wp-allowed-hosts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cyberheartmi9/CVE-2017-8295" target="_blank" rel="noreferrer"&gt;cyberheartmi9/CVE-2017-8295&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8382
 &lt;div id="cve-2017-8382" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8382" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/faizzaidi/Admidio-3.2.8-CSRF-POC-by-Provensec-llc" target="_blank" rel="noreferrer"&gt;faizzaidi/Admidio-3.2.8-CSRF-POC-by-Provensec-llc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8464
 &lt;div id="cve-2017-8464" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8464" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka &amp;quot;LNK Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Elm0D/CVE-2017-8464" target="_blank" rel="noreferrer"&gt;Elm0D/CVE-2017-8464&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/3gstudent/CVE-2017-8464-EXP" target="_blank" rel="noreferrer"&gt;3gstudent/CVE-2017-8464-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Securitykid/CVE-2017-8464-exp-generator" target="_blank" rel="noreferrer"&gt;Securitykid/CVE-2017-8464-exp-generator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/X-Vector/usbhijacking" target="_blank" rel="noreferrer"&gt;X-Vector/usbhijacking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xssfile/CVE-2017-8464-EXP" target="_blank" rel="noreferrer"&gt;xssfile/CVE-2017-8464-EXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8465
 &lt;div id="cve-2017-8465" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8465" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot; This CVE ID is unique from CVE-2017-8468.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nghiadt1098/CVE-2017-8465" target="_blank" rel="noreferrer"&gt;nghiadt1098/CVE-2017-8465&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8529
 &lt;div id="cve-2017-8529" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8529" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka &amp;quot;Microsoft Browser Information Disclosure Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Lynggaard91/windows2016fixCVE-2017-8529" target="_blank" rel="noreferrer"&gt;Lynggaard91/windows2016fixCVE-2017-8529&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sfitpro/cve-2017-8529" target="_blank" rel="noreferrer"&gt;sfitpro/cve-2017-8529&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8543
 &lt;div id="cve-2017-8543" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8543" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka &amp;quot;Windows Search Remote Code Execution Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/americanhanko/windows-security-cve-2017-8543" target="_blank" rel="noreferrer"&gt;americanhanko/windows-security-cve-2017-8543&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8570
 &lt;div id="cve-2017-8570" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8570" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka &amp;quot;Microsoft Office Remote Code Execution Vulnerability&amp;quot;. This CVE ID is unique from CVE-2017-0243.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/temesgeny/ppsx-file-generator" target="_blank" rel="noreferrer"&gt;temesgeny/ppsx-file-generator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rxwx/CVE-2017-8570" target="_blank" rel="noreferrer"&gt;rxwx/CVE-2017-8570&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MaxSecurity/Office-CVE-2017-8570" target="_blank" rel="noreferrer"&gt;MaxSecurity/Office-CVE-2017-8570&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SwordSheath/CVE-2017-8570" target="_blank" rel="noreferrer"&gt;SwordSheath/CVE-2017-8570&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Drac0nids/CVE-2017-8570" target="_blank" rel="noreferrer"&gt;Drac0nids/CVE-2017-8570&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/930201676/CVE-2017-8570" target="_blank" rel="noreferrer"&gt;930201676/CVE-2017-8570&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8625
 &lt;div id="cve-2017-8625" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8625" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka &amp;quot;Internet Explorer Security Feature Bypass Vulnerability&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-8625_Bypass_UMCI" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-8625_Bypass_UMCI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8641
 &lt;div id="cve-2017-8641" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8641" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render when handling objects in memory, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability&amp;quot;. This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-8641_chakra_Js_GlobalObject" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-8641_chakra_Js_GlobalObject&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8759
 &lt;div id="cve-2017-8759" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8759" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka &amp;quot;.NET Framework Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Voulnet/CVE-2017-8759-Exploit-sample" target="_blank" rel="noreferrer"&gt;Voulnet/CVE-2017-8759-Exploit-sample&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nccgroup/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;nccgroup/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vysecurity/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;vysecurity/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BasuCert/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;BasuCert/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tahisaad6/CVE-2017-8759-Exploit-sample2" target="_blank" rel="noreferrer"&gt;tahisaad6/CVE-2017-8759-Exploit-sample2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-8759_-SOAP_WSDL" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-8759_-SOAP_WSDL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bhdresh/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;bhdresh/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Lz1y/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;Lz1y/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JonasUliana/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;JonasUliana/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Securitykid/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;Securitykid/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ashr/CVE-2017-8759-exploits" target="_blank" rel="noreferrer"&gt;ashr/CVE-2017-8759-exploits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/l0n3rs/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;l0n3rs/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ChaitanyaHaritash/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;ChaitanyaHaritash/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/smashinu/CVE-2017-8759Expoit" target="_blank" rel="noreferrer"&gt;smashinu/CVE-2017-8759Expoit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/adeljck/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;adeljck/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhengkook/CVE-2017-8759" target="_blank" rel="noreferrer"&gt;zhengkook/CVE-2017-8759&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8760
 &lt;div id="cve-2017-8760" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8760" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Voraka/cve-2017-8760" target="_blank" rel="noreferrer"&gt;Voraka/cve-2017-8760&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8779
 &lt;div id="cve-2017-8779" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8779" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/drbothen/GO-RPCBOMB" target="_blank" rel="noreferrer"&gt;drbothen/GO-RPCBOMB&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8802
 &lt;div id="cve-2017-8802" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8802" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the &amp;quot;Show Snippet&amp;quot; functionality.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ozzi-/Zimbra-CVE-2017-8802-Hotifx" target="_blank" rel="noreferrer"&gt;ozzi-/Zimbra-CVE-2017-8802-Hotifx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8809
 &lt;div id="cve-2017-8809" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8809" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/motikan2010/CVE-2017-8809_MediaWiki_RFD" target="_blank" rel="noreferrer"&gt;motikan2010/CVE-2017-8809_MediaWiki_RFD&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8890
 &lt;div id="cve-2017-8890" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8890" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/beraphin/CVE-2017-8890" target="_blank" rel="noreferrer"&gt;beraphin/CVE-2017-8890&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thinkycx/CVE-2017-8890" target="_blank" rel="noreferrer"&gt;thinkycx/CVE-2017-8890&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/7043mcgeep/cve-2017-8890-msf" target="_blank" rel="noreferrer"&gt;7043mcgeep/cve-2017-8890-msf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-8917
 &lt;div id="cve-2017-8917" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-8917" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/Joomla3.7-SQLi-CVE-2017-8917" target="_blank" rel="noreferrer"&gt;brianwrf/Joomla3.7-SQLi-CVE-2017-8917&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/stefanlucas/Exploit-Joomla" target="_blank" rel="noreferrer"&gt;stefanlucas/Exploit-Joomla&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2017-8917" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2017-8917&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9097
 &lt;div id="cve-2017-9097" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9097" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ezelf/AntiWeb_testing-Suite" target="_blank" rel="noreferrer"&gt;ezelf/AntiWeb_testing-Suite&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9101
 &lt;div id="cve-2017-9101" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9101" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jasperla/CVE-2017-9101" target="_blank" rel="noreferrer"&gt;jasperla/CVE-2017-9101&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9248
 &lt;div id="cve-2017-9248" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9248" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bao7uo/dp_crypto" target="_blank" rel="noreferrer"&gt;bao7uo/dp_crypto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/capt-meelo/Telewreck" target="_blank" rel="noreferrer"&gt;capt-meelo/Telewreck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ictnamanh/CVE-2017-9248" target="_blank" rel="noreferrer"&gt;ictnamanh/CVE-2017-9248&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shacojx/dp" target="_blank" rel="noreferrer"&gt;shacojx/dp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9417
 &lt;div id="cve-2017-9417" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9417" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the &amp;quot;Broadpwn&amp;quot; issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mailinneberg/Broadpwn" target="_blank" rel="noreferrer"&gt;mailinneberg/Broadpwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9430
 &lt;div id="cve-2017-9430" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9430" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-9430" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-9430&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/j0lama/Dnstracer-1.9-Fix" target="_blank" rel="noreferrer"&gt;j0lama/Dnstracer-1.9-Fix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9476
 &lt;div id="cve-2017-9476" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9476" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&amp;amp;DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices makes it easy for remote attackers to determine the hidden SSID and passphrase for a Home Security Wi-Fi network.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wiire-a/CVE-2017-9476" target="_blank" rel="noreferrer"&gt;wiire-a/CVE-2017-9476&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9506
 &lt;div id="cve-2017-9506" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9506" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/random-robbie/Jira-Scan" target="_blank" rel="noreferrer"&gt;random-robbie/Jira-Scan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwn1sher/jira-ssrf" target="_blank" rel="noreferrer"&gt;pwn1sher/jira-ssrf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9544
 &lt;div id="cve-2017-9544" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9544" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/adenkiewicz/CVE-2017-9544" target="_blank" rel="noreferrer"&gt;adenkiewicz/CVE-2017-9544&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9554
 &lt;div id="cve-2017-9554" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9554" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rfcl/Synology-DiskStation-User-Enumeration-CVE-2017-9554-" target="_blank" rel="noreferrer"&gt;rfcl/Synology-DiskStation-User-Enumeration-CVE-2017-9554-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9606
 &lt;div id="cve-2017-9606" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9606" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Houl777/CVE-2017-9606" target="_blank" rel="noreferrer"&gt;Houl777/CVE-2017-9606&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9609
 &lt;div id="cve-2017-9609" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9609" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pages/lang_settings.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/faizzaidi/Blackcat-cms-v1.2-xss-POC-by-Provensec-llc" target="_blank" rel="noreferrer"&gt;faizzaidi/Blackcat-cms-v1.2-xss-POC-by-Provensec-llc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9779
 &lt;div id="cve-2017-9779" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9779" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 &amp;quot;but with much less impact.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-9779" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-9779&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9791
 &lt;div id="cve-2017-9791" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9791" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/IanSmith123/s2-048" target="_blank" rel="noreferrer"&gt;IanSmith123/s2-048&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dragoneeg/Struts2-048" target="_blank" rel="noreferrer"&gt;dragoneeg/Struts2-048&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xfer0/CVE-2017-9791" target="_blank" rel="noreferrer"&gt;xfer0/CVE-2017-9791&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9798
 &lt;div id="cve-2017-9798" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9798" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nitrado/CVE-2017-9798" target="_blank" rel="noreferrer"&gt;nitrado/CVE-2017-9798&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pabloec20/optionsbleed" target="_blank" rel="noreferrer"&gt;pabloec20/optionsbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/l0n3rs/CVE-2017-9798" target="_blank" rel="noreferrer"&gt;l0n3rs/CVE-2017-9798&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/brokensound77/OptionsBleed-POC-Scanner" target="_blank" rel="noreferrer"&gt;brokensound77/OptionsBleed-POC-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9805
 &lt;div id="cve-2017-9805" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9805" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/luc10/struts-rce-cve-2017-9805" target="_blank" rel="noreferrer"&gt;luc10/struts-rce-cve-2017-9805&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hahwul/struts2-rce-cve-2017-9805-ruby" target="_blank" rel="noreferrer"&gt;hahwul/struts2-rce-cve-2017-9805-ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mazen160/struts-pwn_CVE-2017-9805" target="_blank" rel="noreferrer"&gt;mazen160/struts-pwn_CVE-2017-9805&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Lone-Ranger/apache-struts-pwn_CVE-2017-9805" target="_blank" rel="noreferrer"&gt;Lone-Ranger/apache-struts-pwn_CVE-2017-9805&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RealBearcat/S2-052" target="_blank" rel="noreferrer"&gt;RealBearcat/S2-052&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/-CVE-2017-9805" target="_blank" rel="noreferrer"&gt;0x00-0x00/-CVE-2017-9805&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chrisjd20/cve-2017-9805.py" target="_blank" rel="noreferrer"&gt;chrisjd20/cve-2017-9805.py&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/UbuntuStrike/struts_rest_rce_fuzz-CVE-2017-9805-" target="_blank" rel="noreferrer"&gt;UbuntuStrike/struts_rest_rce_fuzz-CVE-2017-9805-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/UbuntuStrike/CVE-2017-9805_Struts_Fuzz_N_Sploit" target="_blank" rel="noreferrer"&gt;UbuntuStrike/CVE-2017-9805_Struts_Fuzz_N_Sploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thevivekkryadav/CVE-2017-9805-Exploit" target="_blank" rel="noreferrer"&gt;thevivekkryadav/CVE-2017-9805-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9830
 &lt;div id="cve-2017-9830" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9830" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listens on a TCP port and deserializes objects sent by TCP clients.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2017-9830" target="_blank" rel="noreferrer"&gt;securifera/CVE-2017-9830&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9841
 &lt;div id="cve-2017-9841" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9841" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a &amp;quot;&amp;lt;?php &amp;quot; substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mbrasile/CVE-2017-9841" target="_blank" rel="noreferrer"&gt;mbrasile/CVE-2017-9841&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-98505
 &lt;div id="cve-2017-98505" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-98505" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mike-williams/Struts2Vuln" target="_blank" rel="noreferrer"&gt;mike-williams/Struts2Vuln&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9934
 &lt;div id="cve-2017-9934" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9934" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xyringe/CVE-2017-9934" target="_blank" rel="noreferrer"&gt;xyringe/CVE-2017-9934&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2017-9999
 &lt;div id="cve-2017-9999" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2017-9999" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2017-9999_bypassing_General_Firefox" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2017-9999_bypassing_General_Firefox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2016
 &lt;div id="2016" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2016" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0034
 &lt;div id="cve-2016-0034" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0034" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka &amp;quot;Silverlight Runtime Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/DiamondHunters/CVE-2016-0034-Decompile" target="_blank" rel="noreferrer"&gt;DiamondHunters/CVE-2016-0034-Decompile&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0040
 &lt;div id="cve-2016-0040" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0040" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka &amp;quot;Windows Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Rootkitsmm/cve-2016-0040" target="_blank" rel="noreferrer"&gt;Rootkitsmm/cve-2016-0040&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/de7ec7ed/CVE-2016-0040" target="_blank" rel="noreferrer"&gt;de7ec7ed/CVE-2016-0040&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0049
 &lt;div id="cve-2016-0049" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0049" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka &amp;quot;Windows Kerberos Security Feature Bypass.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JackOfMostTrades/bluebox" target="_blank" rel="noreferrer"&gt;JackOfMostTrades/bluebox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0051
 &lt;div id="cve-2016-0051" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0051" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka &amp;quot;WebDAV Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/koczkatamas/CVE-2016-0051" target="_blank" rel="noreferrer"&gt;koczkatamas/CVE-2016-0051&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hexx0r/CVE-2016-0051" target="_blank" rel="noreferrer"&gt;hexx0r/CVE-2016-0051&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ganrann/CVE-2016-0051" target="_blank" rel="noreferrer"&gt;ganrann/CVE-2016-0051&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0095
 &lt;div id="cve-2016-0095" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0095" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka &amp;quot;Win32k Elevation of Privilege Vulnerability,&amp;quot; a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/4M4Z4/cve-2016-0095-x64" target="_blank" rel="noreferrer"&gt;4M4Z4/cve-2016-0095-x64&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0099
 &lt;div id="cve-2016-0099" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0099" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka &amp;quot;Secondary Logon Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zcgonvh/MS16-032" target="_blank" rel="noreferrer"&gt;zcgonvh/MS16-032&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-010033
 &lt;div id="cve-2016-010033" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-010033" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zi0Black/CVE-2016-010033-010045" target="_blank" rel="noreferrer"&gt;zi0Black/CVE-2016-010033-010045&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0189
 &lt;div id="cve-2016-0189" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0189" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability,&amp;quot; a different vulnerability than CVE-2016-0187.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/theori-io/cve-2016-0189" target="_blank" rel="noreferrer"&gt;theori-io/cve-2016-0189&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/deamwork/MS16-051-poc" target="_blank" rel="noreferrer"&gt;deamwork/MS16-051-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0199
 &lt;div id="cve-2016-0199" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0199" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka &amp;quot;Internet Explorer Memory Corruption Vulnerability,&amp;quot; a different vulnerability than CVE-2016-0200 and CVE-2016-3211.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/LeoonZHANG/CVE-2016-0199" target="_blank" rel="noreferrer"&gt;LeoonZHANG/CVE-2016-0199&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0638
 &lt;div id="cve-2016-0638" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0638" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xn0ne/weblogicScanner" target="_blank" rel="noreferrer"&gt;0xn0ne/weblogicScanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0701
 &lt;div id="cve-2016-0701" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0701" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/luanjampa/cve-2016-0701" target="_blank" rel="noreferrer"&gt;luanjampa/cve-2016-0701&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0728
 &lt;div id="cve-2016-0728" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0728" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/idl3r/cve-2016-0728" target="_blank" rel="noreferrer"&gt;idl3r/cve-2016-0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kennetham/cve_2016_0728" target="_blank" rel="noreferrer"&gt;kennetham/cve_2016_0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nardholio/cve-2016-0728" target="_blank" rel="noreferrer"&gt;nardholio/cve-2016-0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/googleweb/CVE-2016-0728" target="_blank" rel="noreferrer"&gt;googleweb/CVE-2016-0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MagicPwn/CVE-2016-0728-Check" target="_blank" rel="noreferrer"&gt;MagicPwn/CVE-2016-0728-Check&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/neuschaefer/cve-2016-0728-testbed" target="_blank" rel="noreferrer"&gt;neuschaefer/cve-2016-0728-testbed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bittorrent3389/cve-2016-0728" target="_blank" rel="noreferrer"&gt;bittorrent3389/cve-2016-0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sibilleg/exploit_cve-2016-0728" target="_blank" rel="noreferrer"&gt;sibilleg/exploit_cve-2016-0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hal0taso/CVE-2016-0728" target="_blank" rel="noreferrer"&gt;hal0taso/CVE-2016-0728&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sugarvillela/CVE" target="_blank" rel="noreferrer"&gt;sugarvillela/CVE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0752
 &lt;div id="cve-2016-0752" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0752" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/forced-request/rails-rce-cve-2016-0752" target="_blank" rel="noreferrer"&gt;forced-request/rails-rce-cve-2016-0752&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dachidahu/CVE-2016-0752" target="_blank" rel="noreferrer"&gt;dachidahu/CVE-2016-0752&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0792
 &lt;div id="cve-2016-0792" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0792" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jpiechowka/jenkins-cve-2016-0792" target="_blank" rel="noreferrer"&gt;jpiechowka/jenkins-cve-2016-0792&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/s0wr0b1ndef/java-deserialization-exploits" target="_blank" rel="noreferrer"&gt;s0wr0b1ndef/java-deserialization-exploits&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0793
 &lt;div id="cve-2016-0793" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0793" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) &amp;quot;meaningless&amp;quot; characters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2016-0793" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2016-0793&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0801
 &lt;div id="cve-2016-0801" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0801" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/abdsec/CVE-2016-0801" target="_blank" rel="noreferrer"&gt;abdsec/CVE-2016-0801&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zsaurus/CVE-2016-0801-test" target="_blank" rel="noreferrer"&gt;zsaurus/CVE-2016-0801-test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0805
 &lt;div id="cve-2016-0805" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0805" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hulovebin/cve-2016-0805" target="_blank" rel="noreferrer"&gt;hulovebin/cve-2016-0805&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0846
 &lt;div id="cve-2016-0846" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0846" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26877992.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/secmob/CVE-2016-0846" target="_blank" rel="noreferrer"&gt;secmob/CVE-2016-0846&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b0b0505/CVE-2016-0846-PoC" target="_blank" rel="noreferrer"&gt;b0b0505/CVE-2016-0846-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-0974
 &lt;div id="cve-2016-0974" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-0974" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK &amp;amp; Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Fullmetal5/FlashHax" target="_blank" rel="noreferrer"&gt;Fullmetal5/FlashHax&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-10033
 &lt;div id="cve-2016-10033" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-10033" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \&amp;quot; (backslash double quote) in a crafted Sender property.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-CVE-2016-10033" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Zenexer/safeshell" target="_blank" rel="noreferrer"&gt;Zenexer/safeshell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GeneralTesler/CVE-2016-10033" target="_blank" rel="noreferrer"&gt;GeneralTesler/CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chipironcin/CVE-2016-10033" target="_blank" rel="noreferrer"&gt;chipironcin/CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Bajunan/CVE-2016-10033" target="_blank" rel="noreferrer"&gt;Bajunan/CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/qwertyuiop12138/CVE-2016-10033" target="_blank" rel="noreferrer"&gt;qwertyuiop12138/CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/liusec/WP-CVE-2016-10033" target="_blank" rel="noreferrer"&gt;liusec/WP-CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pedro823/cve-2016-10033-45" target="_blank" rel="noreferrer"&gt;pedro823/cve-2016-10033-45&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/awidardi/opsxcq-cve-2016-10033" target="_blank" rel="noreferrer"&gt;awidardi/opsxcq-cve-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2016-10033" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2016-10033" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2016-10033&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-10034
 &lt;div id="cve-2016-10034" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-10034" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \&amp;quot; (backslash double quote) in a crafted e-mail address.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/heikipikker/exploit-CVE-2016-10034" target="_blank" rel="noreferrer"&gt;heikipikker/exploit-CVE-2016-10034&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-10277
 &lt;div id="cve-2016-10277" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-10277" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33840490.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alephsecurity/initroot" target="_blank" rel="noreferrer"&gt;alephsecurity/initroot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/leosol/initroot" target="_blank" rel="noreferrer"&gt;leosol/initroot&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-10709
 &lt;div id="cve-2016-10709" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-10709" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wetw0rk/Exploit-Development" target="_blank" rel="noreferrer"&gt;wetw0rk/Exploit-Development&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-10761
 &lt;div id="cve-2016-10761" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-10761" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ISSAPolska/CVE-2016-10761" target="_blank" rel="noreferrer"&gt;ISSAPolska/CVE-2016-10761&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1240
 &lt;div id="cve-2016-1240" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1240" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8.0.32-1ubuntu1.2 on Ubuntu 16.04 LTS allows local users with access to the tomcat account to gain root privileges via a symlink attack on the Catalina log file, as demonstrated by /var/log/tomcat7/catalina.out.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Naramsim/Offensive" target="_blank" rel="noreferrer"&gt;Naramsim/Offensive&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mhe18/CVE_Project" target="_blank" rel="noreferrer"&gt;mhe18/CVE_Project&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1287
 &lt;div id="cve-2016-1287" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1287" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services Module for Cisco Catalyst 6500 and Cisco 7600 devices, ASA 1000V devices, Adaptive Security Virtual Appliance (aka ASAv), Firepower 9300 ASA Security Module, and ISA 3000 devices allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via crafted UDP packets, aka Bug IDs CSCux29978 and CSCux42019.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jgajek/killasa" target="_blank" rel="noreferrer"&gt;jgajek/killasa&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NetSPI/asa_tools" target="_blank" rel="noreferrer"&gt;NetSPI/asa_tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1494
 &lt;div id="cve-2016-1494" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1494" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/matthiasbe/secuimag3a" target="_blank" rel="noreferrer"&gt;matthiasbe/secuimag3a&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1542
 &lt;div id="cve-2016-1542" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1542" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/patriknordlen/bladelogic_bmc-cve-2016-1542" target="_blank" rel="noreferrer"&gt;patriknordlen/bladelogic_bmc-cve-2016-1542&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bao7uo/bmc_bladelogic" target="_blank" rel="noreferrer"&gt;bao7uo/bmc_bladelogic&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1555
 &lt;div id="cve-2016-1555" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1555" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ide0x90/cve-2016-1555" target="_blank" rel="noreferrer"&gt;ide0x90/cve-2016-1555&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1734
 &lt;div id="cve-2016-1734" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1734" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Manouchehri/CVE-2016-1734" target="_blank" rel="noreferrer"&gt;Manouchehri/CVE-2016-1734&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1757
 &lt;div id="cve-2016-1757" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1757" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gdbinit/mach_race" target="_blank" rel="noreferrer"&gt;gdbinit/mach_race&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1764
 &lt;div id="cve-2016-1764" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1764" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/moloch--/cve-2016-1764" target="_blank" rel="noreferrer"&gt;moloch&amp;ndash;/cve-2016-1764&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1825
 &lt;div id="cve-2016-1825" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1825" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/physmem" target="_blank" rel="noreferrer"&gt;bazad/physmem&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1827
 &lt;div id="cve-2016-1827" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1827" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1828, CVE-2016-1829, and CVE-2016-1830.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/flow_divert-heap-overflow" target="_blank" rel="noreferrer"&gt;bazad/flow_divert-heap-overflow&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-1828
 &lt;div id="cve-2016-1828" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-1828" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/rootsh" target="_blank" rel="noreferrer"&gt;bazad/rootsh&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2098
 &lt;div id="cve-2016-2098" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2098" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hderms/dh-CVE_2016_2098" target="_blank" rel="noreferrer"&gt;hderms/dh-CVE_2016_2098&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CyberDefenseInstitute/PoC_CVE-2016-2098_Rails42" target="_blank" rel="noreferrer"&gt;CyberDefenseInstitute/PoC_CVE-2016-2098_Rails42&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Alejandro-MartinG/rails-PoC-CVE-2016-2098" target="_blank" rel="noreferrer"&gt;Alejandro-MartinG/rails-PoC-CVE-2016-2098&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2016-2098" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2016-2098&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/its-arun/CVE-2016-2098" target="_blank" rel="noreferrer"&gt;its-arun/CVE-2016-2098&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/3rg1s/CVE-2016-2098" target="_blank" rel="noreferrer"&gt;3rg1s/CVE-2016-2098&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2107
 &lt;div id="cve-2016-2107" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2107" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FiloSottile/CVE-2016-2107" target="_blank" rel="noreferrer"&gt;FiloSottile/CVE-2016-2107&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tmiklas/docker-cve-2016-2107" target="_blank" rel="noreferrer"&gt;tmiklas/docker-cve-2016-2107&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2118
 &lt;div id="cve-2016-2118" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2118" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka &amp;quot;BADLOCK.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nickanderson/cfengine-CVE-2016-2118" target="_blank" rel="noreferrer"&gt;nickanderson/cfengine-CVE-2016-2118&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2173
 &lt;div id="cve-2016-2173" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2173" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HaToan/CVE-2016-2173" target="_blank" rel="noreferrer"&gt;HaToan/CVE-2016-2173&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2233
 &lt;div id="cve-2016-2233" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2233" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fath0218/CVE-2016-2233" target="_blank" rel="noreferrer"&gt;fath0218/CVE-2016-2233&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2334
 &lt;div id="cve-2016-2334" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2334" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/icewall/CVE-2016-2334" target="_blank" rel="noreferrer"&gt;icewall/CVE-2016-2334&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2402
 &lt;div id="cve-2016-2402" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2402" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ikoz/cert-pinning-flaw-poc" target="_blank" rel="noreferrer"&gt;ikoz/cert-pinning-flaw-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ikoz/certPinningVulnerableOkHttp" target="_blank" rel="noreferrer"&gt;ikoz/certPinningVulnerableOkHttp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2431
 &lt;div id="cve-2016-2431" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2431" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 24968809.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/laginimaineb/cve-2016-2431" target="_blank" rel="noreferrer"&gt;laginimaineb/cve-2016-2431&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/laginimaineb/ExtractKeyMaster" target="_blank" rel="noreferrer"&gt;laginimaineb/ExtractKeyMaster&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2434
 &lt;div id="cve-2016-2434" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2434" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27251090.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jianqiangzhao/CVE-2016-2434" target="_blank" rel="noreferrer"&gt;jianqiangzhao/CVE-2016-2434&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2468
 &lt;div id="cve-2016-2468" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2468" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privileges via a crafted application, aka internal bug 27475454.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gitcollect/CVE-2016-2468" target="_blank" rel="noreferrer"&gt;gitcollect/CVE-2016-2468&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2569
 &lt;div id="cve-2016-2569" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2569" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/amit-raut/CVE-2016-2569" target="_blank" rel="noreferrer"&gt;amit-raut/CVE-2016-2569&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2776
 &lt;div id="cve-2016-2776" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2776" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-2776" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-2776&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/infobyte/CVE-2016-2776" target="_blank" rel="noreferrer"&gt;infobyte/CVE-2016-2776&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-2783
 &lt;div id="cve-2016-2783" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-2783" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/iknowjason/spb" target="_blank" rel="noreferrer"&gt;iknowjason/spb&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3088
 &lt;div id="cve-2016-3088" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3088" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/VVzv/CVE-2016-3088" target="_blank" rel="noreferrer"&gt;VVzv/CVE-2016-3088&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3113
 &lt;div id="cve-2016-3113" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3113" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xEmanuel/CVE-2016-3113" target="_blank" rel="noreferrer"&gt;0xEmanuel/CVE-2016-3113&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3141
 &lt;div id="cve-2016-3141" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3141" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/peternguyen93/CVE-2016-3141" target="_blank" rel="noreferrer"&gt;peternguyen93/CVE-2016-3141&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3308
 &lt;div id="cve-2016-3308" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3308" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka &amp;quot;Win32k Elevation of Privilege Vulnerability,&amp;quot; a different vulnerability than CVE-2016-3309, CVE-2016-3310, and CVE-2016-3311.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/55-AA/CVE-2016-3308" target="_blank" rel="noreferrer"&gt;55-AA/CVE-2016-3308&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3309
 &lt;div id="cve-2016-3309" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3309" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka &amp;quot;Win32k Elevation of Privilege Vulnerability,&amp;quot; a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/siberas/CVE-2016-3309_Reloaded" target="_blank" rel="noreferrer"&gt;siberas/CVE-2016-3309_Reloaded&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3714
 &lt;div id="cve-2016-3714" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3714" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka &amp;quot;ImageTragick.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jackdpeterson/imagick_secure_puppet" target="_blank" rel="noreferrer"&gt;jackdpeterson/imagick_secure_puppet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tommiionfire/CVE-2016-3714" target="_blank" rel="noreferrer"&gt;tommiionfire/CVE-2016-3714&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chusiang/CVE-2016-3714.ansible.role" target="_blank" rel="noreferrer"&gt;chusiang/CVE-2016-3714.ansible.role&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jpeanut/ImageTragick-CVE-2016-3714-RShell" target="_blank" rel="noreferrer"&gt;jpeanut/ImageTragick-CVE-2016-3714-RShell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Hood3dRob1n/CVE-2016-3714" target="_blank" rel="noreferrer"&gt;Hood3dRob1n/CVE-2016-3714&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HRSkraps/CVE-2016-3714" target="_blank" rel="noreferrer"&gt;HRSkraps/CVE-2016-3714&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3749
 &lt;div id="cve-2016-3749" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3749" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
server/LockSettingsService.java in LockSettingsService in Android 6.x before 2016-07-01 allows attackers to modify the screen-lock password or pattern via a crafted application, aka internal bug 28163930.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nirdev/CVE-2016-3749-PoC" target="_blank" rel="noreferrer"&gt;nirdev/CVE-2016-3749-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3955
 &lt;div id="cve-2016-3955" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3955" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted length value in a USB/IP packet.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pqsec/uboatdemo" target="_blank" rel="noreferrer"&gt;pqsec/uboatdemo&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3957
 &lt;div id="cve-2016-3957" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3957" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sj/web2py-e94946d-CVE-2016-3957" target="_blank" rel="noreferrer"&gt;sj/web2py-e94946d-CVE-2016-3957&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3959
 &lt;div id="cve-2016-3959" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3959" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alexmullins/dsa" target="_blank" rel="noreferrer"&gt;alexmullins/dsa&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-3962
 &lt;div id="cve-2016-3962" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-3962" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via a crafted parameter in a POST request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2016-3962-Exploit" target="_blank" rel="noreferrer"&gt;securifera/CVE-2016-3962-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4010
 &lt;div id="cve-2016-4010" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4010" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/brianwrf/Magento-CVE-2016-4010" target="_blank" rel="noreferrer"&gt;brianwrf/Magento-CVE-2016-4010&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4117
 &lt;div id="cve-2016-4117" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4117" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/amit-raut/CVE-2016-4117-Report" target="_blank" rel="noreferrer"&gt;amit-raut/CVE-2016-4117-Report&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hybridious/CVE-2016-4117" target="_blank" rel="noreferrer"&gt;hybridious/CVE-2016-4117&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4438
 &lt;div id="cve-2016-4438" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4438" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jason3e7/CVE-2016-4438" target="_blank" rel="noreferrer"&gt;jason3e7/CVE-2016-4438&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2016-4438" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2016-4438&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4463
 &lt;div id="cve-2016-4463" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4463" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/arntsonl/CVE-2016-4463" target="_blank" rel="noreferrer"&gt;arntsonl/CVE-2016-4463&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4622
 &lt;div id="cve-2016-4622" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4622" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/saelo/jscpwn" target="_blank" rel="noreferrer"&gt;saelo/jscpwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hdbreaker/WebKit-CVE-2016-4622" target="_blank" rel="noreferrer"&gt;hdbreaker/WebKit-CVE-2016-4622&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4631
 &lt;div id="cve-2016-4631" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4631" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hansnielsen/tiffdisabler" target="_blank" rel="noreferrer"&gt;hansnielsen/tiffdisabler&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4655
 &lt;div id="cve-2016-4655" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4655" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jndok/PegasusX" target="_blank" rel="noreferrer"&gt;jndok/PegasusX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Cryptiiiic/skybreak" target="_blank" rel="noreferrer"&gt;Cryptiiiic/skybreak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4657
 &lt;div id="cve-2016-4657" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4657" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Mimoja/CVE-2016-4657-NintendoSwitch" target="_blank" rel="noreferrer"&gt;Mimoja/CVE-2016-4657-NintendoSwitch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Traiver/CVE-2016-4657-Switch-Browser-Binary" target="_blank" rel="noreferrer"&gt;Traiver/CVE-2016-4657-Switch-Browser-Binary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iDaN5x/Switcheroo" target="_blank" rel="noreferrer"&gt;iDaN5x/Switcheroo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vigneshyaadav27/webkit-vulnerability" target="_blank" rel="noreferrer"&gt;vigneshyaadav27/webkit-vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4669
 &lt;div id="cve-2016-4669" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4669" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the &amp;quot;Kernel&amp;quot; component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system crash) via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/i-o-s/CVE-2016-4669" target="_blank" rel="noreferrer"&gt;i-o-s/CVE-2016-4669&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4845
 &lt;div id="cve-2016-4845" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4845" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kaito834/cve-2016-4845_csrf" target="_blank" rel="noreferrer"&gt;kaito834/cve-2016-4845_csrf&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4861
 &lt;div id="cve-2016-4861" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4861" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-4861" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-4861&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4971
 &lt;div id="cve-2016-4971" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4971" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BlueCocoa/CVE-2016-4971" target="_blank" rel="noreferrer"&gt;BlueCocoa/CVE-2016-4971&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mbadanoiu/CVE-2016-4971" target="_blank" rel="noreferrer"&gt;mbadanoiu/CVE-2016-4971&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-4977
 &lt;div id="cve-2016-4977" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-4977" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GEIGEI123/CVE-2016-4977-POC" target="_blank" rel="noreferrer"&gt;GEIGEI123/CVE-2016-4977-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5195
 &lt;div id="cve-2016-5195" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5195" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka &amp;quot;Dirty COW.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ASRTeam/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;ASRTeam/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/timwr/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;timwr/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xlucas/dirtycow.cr" target="_blank" rel="noreferrer"&gt;xlucas/dirtycow.cr&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/istenrot/centos-dirty-cow-ansible" target="_blank" rel="noreferrer"&gt;istenrot/centos-dirty-cow-ansible&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pgporada/ansible-role-cve" target="_blank" rel="noreferrer"&gt;pgporada/ansible-role-cve&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sideeffect42/DirtyCOWTester" target="_blank" rel="noreferrer"&gt;sideeffect42/DirtyCOWTester&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/scumjr/dirtycow-vdso" target="_blank" rel="noreferrer"&gt;scumjr/dirtycow-vdso&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gbonacini/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;gbonacini/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DavidBuchanan314/cowroot" target="_blank" rel="noreferrer"&gt;DavidBuchanan314/cowroot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aishee/scan-dirtycow" target="_blank" rel="noreferrer"&gt;aishee/scan-dirtycow&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/oleg-fiksel/ansible_CVE-2016-5195_check" target="_blank" rel="noreferrer"&gt;oleg-fiksel/ansible_CVE-2016-5195_check&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ldenevi/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;ldenevi/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/whu-enjoy/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;whu-enjoy/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ndobson/inspec_CVE-2016-5195" target="_blank" rel="noreferrer"&gt;ndobson/inspec_CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/linhlt247/DirtyCOW_CVE-2016-5195" target="_blank" rel="noreferrer"&gt;linhlt247/DirtyCOW_CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sribaba/android-CVE-2016-5195" target="_blank" rel="noreferrer"&gt;sribaba/android-CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/esc0rtd3w/org.cowpoop.moooooo" target="_blank" rel="noreferrer"&gt;esc0rtd3w/org.cowpoop.moooooo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nu11secur1ty/Protect-CVE-2016-5195-DirtyCow" target="_blank" rel="noreferrer"&gt;nu11secur1ty/Protect-CVE-2016-5195-DirtyCow&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hyln9/VIKIROOT" target="_blank" rel="noreferrer"&gt;hyln9/VIKIROOT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/droidvoider/dirtycow-replacer" target="_blank" rel="noreferrer"&gt;droidvoider/dirtycow-replacer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FloridSleeves/os-experiment-4" target="_blank" rel="noreferrer"&gt;FloridSleeves/os-experiment-4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/arbll/dirtycow" target="_blank" rel="noreferrer"&gt;arbll/dirtycow&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/titanhp/Dirty-COW-CVE-2016-5195-Testing" target="_blank" rel="noreferrer"&gt;titanhp/Dirty-COW-CVE-2016-5195-Testing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/acidburnmi/CVE-2016-5195-master" target="_blank" rel="noreferrer"&gt;acidburnmi/CVE-2016-5195-master&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xpcmdshell/derpyc0w" target="_blank" rel="noreferrer"&gt;xpcmdshell/derpyc0w&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Brucetg/DirtyCow-EXP" target="_blank" rel="noreferrer"&gt;Brucetg/DirtyCow-EXP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2016-5195" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2016-5195&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/imust6226/dirtcow" target="_blank" rel="noreferrer"&gt;imust6226/dirtcow&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5345
 &lt;div id="cve-2016-5345" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5345" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted application, aka Android internal bug 32639452 and Qualcomm internal bug CR1079713.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/NickStephens/cve-2016-5345" target="_blank" rel="noreferrer"&gt;NickStephens/cve-2016-5345&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5639
 &lt;div id="cve-2016-5639" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5639" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xfox64x/CVE-2016-5639" target="_blank" rel="noreferrer"&gt;xfox64x/CVE-2016-5639&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5640
 &lt;div id="cve-2016-5640" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5640" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vpnguy-zz/CrestCrack" target="_blank" rel="noreferrer"&gt;vpnguy-zz/CrestCrack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xfox64x/CVE-2016-5640" target="_blank" rel="noreferrer"&gt;xfox64x/CVE-2016-5640&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5696
 &lt;div id="cve-2016-5696" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5696" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Gnoxter/mountain_goat" target="_blank" rel="noreferrer"&gt;Gnoxter/mountain_goat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/violentshell/rover" target="_blank" rel="noreferrer"&gt;violentshell/rover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jduck/challack" target="_blank" rel="noreferrer"&gt;jduck/challack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bplinux/chackd" target="_blank" rel="noreferrer"&gt;bplinux/chackd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nogoegst/grill" target="_blank" rel="noreferrer"&gt;nogoegst/grill&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5699
 &lt;div id="cve-2016-5699" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5699" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bunseokbot/CVE-2016-5699-poc" target="_blank" rel="noreferrer"&gt;bunseokbot/CVE-2016-5699-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shajinzheng/cve-2016-5699-jinzheng-sha" target="_blank" rel="noreferrer"&gt;shajinzheng/cve-2016-5699-jinzheng-sha&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-5734
 &lt;div id="cve-2016-5734" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-5734" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-5734" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-5734&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6187
 &lt;div id="cve-2016-6187" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6187" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vnik5287/cve-2016-6187-poc" target="_blank" rel="noreferrer"&gt;vnik5287/cve-2016-6187-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6210
 &lt;div id="cve-2016-6210" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6210" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/justlce/CVE-2016-6210-Exploit" target="_blank" rel="noreferrer"&gt;justlce/CVE-2016-6210-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6271
 &lt;div id="cve-2016-6271" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6271" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing HVI check on DHPart2 packet reception.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gteissier/CVE-2016-6271" target="_blank" rel="noreferrer"&gt;gteissier/CVE-2016-6271&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6317
 &lt;div id="cve-2016-6317" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6317" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain &amp;quot;[nil]&amp;quot; values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kavgan/vuln_test_repo_public_ruby_gemfile_cve-2016-6317" target="_blank" rel="noreferrer"&gt;kavgan/vuln_test_repo_public_ruby_gemfile_cve-2016-6317&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6366
 &lt;div id="cve-2016-6366" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6366" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RiskSense-Ops/CVE-2016-6366" target="_blank" rel="noreferrer"&gt;RiskSense-Ops/CVE-2016-6366&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6515
 &lt;div id="cve-2016-6515" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6515" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-CVE-2016-6515" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-CVE-2016-6515&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2016-6515" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2016-6515&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6516
 &lt;div id="cve-2016-6516" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6516" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a &amp;quot;double fetch&amp;quot; vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/wpengfei/CVE-2016-6516-exploit" target="_blank" rel="noreferrer"&gt;wpengfei/CVE-2016-6516-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6584
 &lt;div id="cve-2016-6584" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6584" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ViralSecurityGroup/KNOXout" target="_blank" rel="noreferrer"&gt;ViralSecurityGroup/KNOXout&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6662
 &lt;div id="cve-2016-6662" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6662" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/konstantin-kelemen/mysqld_safe-CVE-2016-6662-patch" target="_blank" rel="noreferrer"&gt;konstantin-kelemen/mysqld_safe-CVE-2016-6662-patch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/meersjo/ansible-mysql-cve-2016-6662" target="_blank" rel="noreferrer"&gt;meersjo/ansible-mysql-cve-2016-6662&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-6662" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-6662&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Ashrafdev/MySQL-Remote-Root-Code-Execution" target="_blank" rel="noreferrer"&gt;Ashrafdev/MySQL-Remote-Root-Code-Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/boompig/cve-2016-6662" target="_blank" rel="noreferrer"&gt;boompig/cve-2016-6662&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MAYASEVEN/CVE-2016-6662" target="_blank" rel="noreferrer"&gt;MAYASEVEN/CVE-2016-6662&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6663
 &lt;div id="cve-2016-6663" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6663" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17 allows local users with certain permissions to gain privileges by leveraging use of my_copystat by REPAIR TABLE to repair a MyISAM table.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/firebroo/CVE-2016-6663" target="_blank" rel="noreferrer"&gt;firebroo/CVE-2016-6663&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6754
 &lt;div id="cve-2016-6754" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6754" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/secmob/BadKernel" target="_blank" rel="noreferrer"&gt;secmob/BadKernel&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6798
 &lt;div id="cve-2016-6798" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6798" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2016-6798" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2016-6798&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-6801
 &lt;div id="cve-2016-6801" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-6801" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/TSNGL21/CVE-2016-6801" target="_blank" rel="noreferrer"&gt;TSNGL21/CVE-2016-6801&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7117
 &lt;div id="cve-2016-7117" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7117" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-7117" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-7117&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7190
 &lt;div id="cve-2016-7190" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7190" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability,&amp;quot; a different vulnerability than CVE-2016-3386, CVE-2016-3389, and CVE-2016-7194.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xcl/cve-2016-7190" target="_blank" rel="noreferrer"&gt;0xcl/cve-2016-7190&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7200
 &lt;div id="cve-2016-7200" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7200" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka &amp;quot;Scripting Engine Memory Corruption Vulnerability,&amp;quot; a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/theori-io/chakra-2016-11" target="_blank" rel="noreferrer"&gt;theori-io/chakra-2016-11&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7255
 &lt;div id="cve-2016-7255" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7255" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/heh3/CVE-2016-7255" target="_blank" rel="noreferrer"&gt;heh3/CVE-2016-7255&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FSecureLABS/CVE-2016-7255" target="_blank" rel="noreferrer"&gt;FSecureLABS/CVE-2016-7255&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/homjxi0e/CVE-2016-7255" target="_blank" rel="noreferrer"&gt;homjxi0e/CVE-2016-7255&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yuvatia/page-table-exploitation" target="_blank" rel="noreferrer"&gt;yuvatia/page-table-exploitation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bbolmin/cve-2016-7255_x86_x64" target="_blank" rel="noreferrer"&gt;bbolmin/cve-2016-7255_x86_x64&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7434
 &lt;div id="cve-2016-7434" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7434" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-CVE-2016-7434" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-CVE-2016-7434&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shekkbuilder/CVE-2016-7434" target="_blank" rel="noreferrer"&gt;shekkbuilder/CVE-2016-7434&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2016-7434" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2016-7434&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7608
 &lt;div id="cve-2016-7608" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7608" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the &amp;quot;IOFireWireFamily&amp;quot; component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bazad/IOFireWireFamily-overflow" target="_blank" rel="noreferrer"&gt;bazad/IOFireWireFamily-overflow&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-7855
 &lt;div id="cve-2016-7855" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-7855" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/swagatbora90/CheckFlashPlayerVersion" target="_blank" rel="noreferrer"&gt;swagatbora90/CheckFlashPlayerVersion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8007
 &lt;div id="cve-2016-8007" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8007" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry keys via specific conditions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dmaasland/mcafee-hip-CVE-2016-8007" target="_blank" rel="noreferrer"&gt;dmaasland/mcafee-hip-CVE-2016-8007&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8016
 &lt;div id="cve-2016-8016" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8016" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on the system via a URL parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-CVE-2016-8016-25" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-CVE-2016-8016-25&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8367
 &lt;div id="cve-2016-8367" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8367" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0xICF/PanelShock" target="_blank" rel="noreferrer"&gt;0xICF/PanelShock&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8462
 &lt;div id="cve-2016-8462" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8462" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: N/A. Android ID: A-32510383.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CunningLogic/PixelDump_CVE-2016-8462" target="_blank" rel="noreferrer"&gt;CunningLogic/PixelDump_CVE-2016-8462&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8467
 &lt;div id="cve-2016-8467" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8467" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely permanent or requiring re-flashing the entire operating system). Product: Android. Versions: N/A. Android ID: A-30308784.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/roeeh/bootmodechecker" target="_blank" rel="noreferrer"&gt;roeeh/bootmodechecker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8610
 &lt;div id="cve-2016-8610" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8610" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cujanovic/CVE-2016-8610-PoC" target="_blank" rel="noreferrer"&gt;cujanovic/CVE-2016-8610-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8636
 &lt;div id="cve-2016-8636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the &amp;quot;RDMA protocol over infiniband&amp;quot; (aka Soft RoCE) technology.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jigerjain/Integer-Overflow-test" target="_blank" rel="noreferrer"&gt;jigerjain/Integer-Overflow-test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8655
 &lt;div id="cve-2016-8655" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8655" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/scarvell/cve-2016-8655" target="_blank" rel="noreferrer"&gt;scarvell/cve-2016-8655&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LakshmiDesai/CVE-2016-8655" target="_blank" rel="noreferrer"&gt;LakshmiDesai/CVE-2016-8655&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KosukeShimofuji/CVE-2016-8655" target="_blank" rel="noreferrer"&gt;KosukeShimofuji/CVE-2016-8655&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/agkunkle/chocobo" target="_blank" rel="noreferrer"&gt;agkunkle/chocobo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/martinmullins/CVE-2016-8655_Android" target="_blank" rel="noreferrer"&gt;martinmullins/CVE-2016-8655_Android&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8735
 &lt;div id="cve-2016-8735" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8735" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2016-8735" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2016-8735&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8740
 &lt;div id="cve-2016-8740" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8740" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lcfpadilha/mac0352-ep4" target="_blank" rel="noreferrer"&gt;lcfpadilha/mac0352-ep4&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8776
 &lt;div id="cve-2016-8776" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8776" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization and perform operations to update the Google account.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/maviroxz/CVE-2016-8776" target="_blank" rel="noreferrer"&gt;maviroxz/CVE-2016-8776&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8858
 &lt;div id="cve-2016-8858" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8858" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that &amp;quot;OpenSSH upstream does not consider this as a security issue.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dag-erling/kexkill" target="_blank" rel="noreferrer"&gt;dag-erling/kexkill&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8869
 &lt;div id="cve-2016-8869" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8869" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sunsunza2009/Joomla-3.4.4-3.6.4_CVE-2016-8869_and_CVE-2016-8870" target="_blank" rel="noreferrer"&gt;sunsunza2009/Joomla-3.4.4-3.6.4_CVE-2016-8869_and_CVE-2016-8870&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rustyJ4ck/JoomlaCVE20168869" target="_blank" rel="noreferrer"&gt;rustyJ4ck/JoomlaCVE20168869&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2016-8869" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2016-8869&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-8870
 &lt;div id="cve-2016-8870" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-8870" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2016-8870" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2016-8870&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-9066
 &lt;div id="cve-2016-9066" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-9066" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird &amp;lt; 45.5, Firefox ESR &amp;lt; 45.5, and Firefox &amp;lt; 50.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/saelo/foxpwn" target="_blank" rel="noreferrer"&gt;saelo/foxpwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-9079
 &lt;div id="cve-2016-9079" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-9079" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox &amp;lt; 50.0.2, Firefox ESR &amp;lt; 45.5.1, and Thunderbird &amp;lt; 45.5.1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/LakshmiDesai/CVE-2016-9079" target="_blank" rel="noreferrer"&gt;LakshmiDesai/CVE-2016-9079&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dangokyo/CVE-2016-9079" target="_blank" rel="noreferrer"&gt;dangokyo/CVE-2016-9079&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-9192
 &lt;div id="cve-2016-9192" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-9192" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/serializingme/cve-2016-9192" target="_blank" rel="noreferrer"&gt;serializingme/cve-2016-9192&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-9244
 &lt;div id="cve-2016-9244" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-9244" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EgeBalci/Ticketbleed" target="_blank" rel="noreferrer"&gt;EgeBalci/Ticketbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/glestel/minion-ticket-bleed-plugin" target="_blank" rel="noreferrer"&gt;glestel/minion-ticket-bleed-plugin&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-9838
 &lt;div id="cve-2016-9838" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-9838" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's account and reset the user's group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2016-9838" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2016-9838&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2016-9920
 &lt;div id="cve-2016-9920" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2016-9920" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/t0kx/exploit-CVE-2016-9920" target="_blank" rel="noreferrer"&gt;t0kx/exploit-CVE-2016-9920&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2015
 &lt;div id="2015" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2015" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0006
 &lt;div id="cve-2015-0006" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0006" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka &amp;quot;NLA Security Feature Bypass Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bugch3ck/imposter" target="_blank" rel="noreferrer"&gt;bugch3ck/imposter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0057
 &lt;div id="cve-2015-0057" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0057" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/55-AA/CVE-2015-0057" target="_blank" rel="noreferrer"&gt;55-AA/CVE-2015-0057&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0072
 &lt;div id="cve-2015-0072" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0072" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka &amp;quot;Universal XSS (UXSS).&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dbellavista/uxss-poc" target="_blank" rel="noreferrer"&gt;dbellavista/uxss-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0204
 &lt;div id="cve-2015-0204" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0204" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the &amp;quot;FREAK&amp;quot; issue. NOTE: the scope of this CVE is only client code based on OpenSSL, not EXPORT_RSA issues associated with servers or other TLS implementations.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/felmoltor/FreakVulnChecker" target="_blank" rel="noreferrer"&gt;felmoltor/FreakVulnChecker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/scottjpack/Freak-Scanner" target="_blank" rel="noreferrer"&gt;scottjpack/Freak-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AbhishekGhosh/FREAK-Attack-CVE-2015-0204-Testing-Script" target="_blank" rel="noreferrer"&gt;AbhishekGhosh/FREAK-Attack-CVE-2015-0204-Testing-Script&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/niccoX/patch-openssl-CVE-2014-0291_CVE-2015-0204" target="_blank" rel="noreferrer"&gt;niccoX/patch-openssl-CVE-2014-0291_CVE-2015-0204&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0231
 &lt;div id="cve-2015-0231" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0231" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/3xp10it/php_cve-2014-8142_cve-2015-0231" target="_blank" rel="noreferrer"&gt;3xp10it/php_cve-2014-8142_cve-2015-0231&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0235
 &lt;div id="cve-2015-0235" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0235" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka &amp;quot;GHOST.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fser/ghost-checker" target="_blank" rel="noreferrer"&gt;fser/ghost-checker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mikesplain/CVE-2015-0235-cookbook" target="_blank" rel="noreferrer"&gt;mikesplain/CVE-2015-0235-cookbook&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aaronfay/CVE-2015-0235-test" target="_blank" rel="noreferrer"&gt;aaronfay/CVE-2015-0235-test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/piyokango/ghost" target="_blank" rel="noreferrer"&gt;piyokango/ghost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/LyricalSecurity/GHOSTCHECK-cve-2015-0235" target="_blank" rel="noreferrer"&gt;LyricalSecurity/GHOSTCHECK-cve-2015-0235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mholzinger/CVE-2015-0235_GHOST" target="_blank" rel="noreferrer"&gt;mholzinger/CVE-2015-0235_GHOST&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/adherzog/ansible-CVE-2015-0235-GHOST" target="_blank" rel="noreferrer"&gt;adherzog/ansible-CVE-2015-0235-GHOST&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/favoretti/lenny-libc6" target="_blank" rel="noreferrer"&gt;favoretti/lenny-libc6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nickanderson/cfengine-CVE_2015_0235" target="_blank" rel="noreferrer"&gt;nickanderson/cfengine-CVE_2015_0235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/koudaiii-archives/cookbook-update-glibc" target="_blank" rel="noreferrer"&gt;koudaiii-archives/cookbook-update-glibc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/F88/ghostbusters15" target="_blank" rel="noreferrer"&gt;F88/ghostbusters15&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JustDenisYT/ghosttester" target="_blank" rel="noreferrer"&gt;JustDenisYT/ghosttester&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tobyzxj/CVE-2015-0235" target="_blank" rel="noreferrer"&gt;tobyzxj/CVE-2015-0235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/makelinux/CVE-2015-0235-workaround" target="_blank" rel="noreferrer"&gt;makelinux/CVE-2015-0235-workaround&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/arm13/ghost_exploit" target="_blank" rel="noreferrer"&gt;arm13/ghost_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/alanmeyer/CVE-glibc" target="_blank" rel="noreferrer"&gt;alanmeyer/CVE-glibc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r0otshell/CVE-2015-0235" target="_blank" rel="noreferrer"&gt;r0otshell/CVE-2015-0235&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/chayim/GHOSTCHECK-cve-2015-0235" target="_blank" rel="noreferrer"&gt;chayim/GHOSTCHECK-cve-2015-0235&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0313
 &lt;div id="cve-2015-0313" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0313" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SecurityObscurity/cve-2015-0313" target="_blank" rel="noreferrer"&gt;SecurityObscurity/cve-2015-0313&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0345
 &lt;div id="cve-2015-0345" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0345" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Update 5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BishopFox/coldfusion-10-11-xss" target="_blank" rel="noreferrer"&gt;BishopFox/coldfusion-10-11-xss&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0568
 &lt;div id="cve-2015-0568" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0568" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/betalphafai/CVE-2015-0568" target="_blank" rel="noreferrer"&gt;betalphafai/CVE-2015-0568&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-0816
 &lt;div id="cve-2015-0816" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-0816" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Afudadi/Firefox-35-37-Exploit" target="_blank" rel="noreferrer"&gt;Afudadi/Firefox-35-37-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1130
 &lt;div id="cve-2015-1130" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1130" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Shmoopi/RootPipe-Demo" target="_blank" rel="noreferrer"&gt;Shmoopi/RootPipe-Demo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sideeffect42/RootPipeTester" target="_blank" rel="noreferrer"&gt;sideeffect42/RootPipeTester&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1140
 &lt;div id="cve-2015-1140" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1140" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kpwn/vpwn" target="_blank" rel="noreferrer"&gt;kpwn/vpwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1157
 &lt;div id="cve-2015-1157" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1157" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/perillamint/CVE-2015-1157" target="_blank" rel="noreferrer"&gt;perillamint/CVE-2015-1157&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1318
 &lt;div id="cve-2015-1318" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1318" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ScottyBauer/CVE-2015-1318" target="_blank" rel="noreferrer"&gt;ScottyBauer/CVE-2015-1318&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1427
 &lt;div id="cve-2015-1427" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1427" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/t0kx/exploit-CVE-2015-1427" target="_blank" rel="noreferrer"&gt;t0kx/exploit-CVE-2015-1427&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2015-1427" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2015-1427&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1474
 &lt;div id="cve-2015-1474" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1474" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trigger a large number of (1) file descriptors or (2) integer values.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/p1gl3t/CVE-2015-1474_poc" target="_blank" rel="noreferrer"&gt;p1gl3t/CVE-2015-1474_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1528
 &lt;div id="cve-2015-1528" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1528" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted application, aka internal bug 19334482.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/secmob/PoCForCVE-2015-1528" target="_blank" rel="noreferrer"&gt;secmob/PoCForCVE-2015-1528&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kanpol/PoCForCVE-2015-1528" target="_blank" rel="noreferrer"&gt;kanpol/PoCForCVE-2015-1528&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1538
 &lt;div id="cve-2015-1538" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1538" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/oguzhantopgul/cve-2015-1538-1" target="_blank" rel="noreferrer"&gt;oguzhantopgul/cve-2015-1538-1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/renjithsasidharan/cve-2015-1538-1" target="_blank" rel="noreferrer"&gt;renjithsasidharan/cve-2015-1538-1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jduck/cve-2015-1538-1" target="_blank" rel="noreferrer"&gt;jduck/cve-2015-1538-1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marZiiw/Stagefright_CVE-2015-1538-1" target="_blank" rel="noreferrer"&gt;marZiiw/Stagefright_CVE-2015-1538-1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/niranjanshr13/Stagefright-cve-2015-1538-1" target="_blank" rel="noreferrer"&gt;niranjanshr13/Stagefright-cve-2015-1538-1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1560
 &lt;div id="cve-2015-1560" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1560" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Iansus/Centreon-CVE-2015-1560_1561" target="_blank" rel="noreferrer"&gt;Iansus/Centreon-CVE-2015-1560_1561&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1579
 &lt;div id="cve-2015-1579" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1579" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/paralelo14/WordPressMassExploiter" target="_blank" rel="noreferrer"&gt;paralelo14/WordPressMassExploiter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/paralelo14/CVE-2015-1579" target="_blank" rel="noreferrer"&gt;paralelo14/CVE-2015-1579&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1592
 &lt;div id="cve-2015-1592" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1592" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lightsey/cve-2015-1592" target="_blank" rel="noreferrer"&gt;lightsey/cve-2015-1592&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1635
 &lt;div id="cve-2015-1635" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1635" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka &amp;quot;HTTP.sys Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xPaw/HTTPsys" target="_blank" rel="noreferrer"&gt;xPaw/HTTPsys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Zx7ffa4512-Python/Project-CVE-2015-1635" target="_blank" rel="noreferrer"&gt;Zx7ffa4512-Python/Project-CVE-2015-1635&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/technion/erlvulnscan" target="_blank" rel="noreferrer"&gt;technion/erlvulnscan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wiredaem0n/chk-ms15-034" target="_blank" rel="noreferrer"&gt;wiredaem0n/chk-ms15-034&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/1337r00t/Remove-IIS-RIIS" target="_blank" rel="noreferrer"&gt;1337r00t/Remove-IIS-RIIS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bongbongco/MS15-034" target="_blank" rel="noreferrer"&gt;bongbongco/MS15-034&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/aedoo/CVE-2015-1635-POC" target="_blank" rel="noreferrer"&gt;aedoo/CVE-2015-1635-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/limkokhole/CVE-2015-1635" target="_blank" rel="noreferrer"&gt;limkokhole/CVE-2015-1635&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1641
 &lt;div id="cve-2015-1641" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1641" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka &amp;quot;Microsoft Office Memory Corruption Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Cyberclues/rtf_exploit_extractor" target="_blank" rel="noreferrer"&gt;Cyberclues/rtf_exploit_extractor&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1701
 &lt;div id="cve-2015-1701" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1701" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka &amp;quot;Win32k Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hfiref0x/CVE-2015-1701" target="_blank" rel="noreferrer"&gt;hfiref0x/CVE-2015-1701&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1805
 &lt;div id="cve-2015-1805" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1805" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an &amp;quot;I/O vector array overrun.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/panyu6325/CVE-2015-1805" target="_blank" rel="noreferrer"&gt;panyu6325/CVE-2015-1805&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dosomder/iovyroot" target="_blank" rel="noreferrer"&gt;dosomder/iovyroot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FloatingGuy/cve-2015-1805" target="_blank" rel="noreferrer"&gt;FloatingGuy/cve-2015-1805&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mobilelinux/iovy_root_research" target="_blank" rel="noreferrer"&gt;mobilelinux/iovy_root_research&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-1855
 &lt;div id="cve-2015-1855" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-1855" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vpereira/CVE-2015-1855" target="_blank" rel="noreferrer"&gt;vpereira/CVE-2015-1855&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2080
 &lt;div id="cve-2015-2080" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2080" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BizarreNULL/CVE-2015-2080" target="_blank" rel="noreferrer"&gt;BizarreNULL/CVE-2015-2080&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2153
 &lt;div id="cve-2015-2153" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2153" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via a crafted header length in an RPKI-RTR Protocol Data Unit (PDU).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/arntsonl/CVE-2015-2153" target="_blank" rel="noreferrer"&gt;arntsonl/CVE-2015-2153&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2208
 &lt;div id="cve-2015-2208" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2208" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ptantiku/cve-2015-2208" target="_blank" rel="noreferrer"&gt;ptantiku/cve-2015-2208&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2231
 &lt;div id="cve-2015-2231" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2231" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rednaga/adups-get-super-serial" target="_blank" rel="noreferrer"&gt;rednaga/adups-get-super-serial&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2291
 &lt;div id="cve-2015-2291" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2291" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Tare05/Intel-CVE-2015-2291" target="_blank" rel="noreferrer"&gt;Tare05/Intel-CVE-2015-2291&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2315
 &lt;div id="cve-2015-2315" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2315" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/weidongl74/cve-2015-2315-report" target="_blank" rel="noreferrer"&gt;weidongl74/cve-2015-2315-report&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2546
 &lt;div id="cve-2015-2546" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2546" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka &amp;quot;Win32k Memory Corruption Elevation of Privilege Vulnerability,&amp;quot; a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/k0keoyo/CVE-2015-2546-Exploit" target="_blank" rel="noreferrer"&gt;k0keoyo/CVE-2015-2546-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2794
 &lt;div id="cve-2015-2794" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2794" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/styx00/DNN_CVE-2015-2794" target="_blank" rel="noreferrer"&gt;styx00/DNN_CVE-2015-2794&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wilsc0w/CVE-2015-2794-finder" target="_blank" rel="noreferrer"&gt;wilsc0w/CVE-2015-2794-finder&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2900
 &lt;div id="cve-2015-2900" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2900" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The AddUserFinding add_userfinding2 function in Medicomp MEDCIN Engine before 2.22.20153.226 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted packet on port 8190.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2015-2900-Exploit" target="_blank" rel="noreferrer"&gt;securifera/CVE-2015-2900-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-2925
 &lt;div id="cve-2015-2925" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-2925" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a &amp;quot;double-chroot attack.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Kagami/docker_cve-2015-2925" target="_blank" rel="noreferrer"&gt;Kagami/docker_cve-2015-2925&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3043
 &lt;div id="cve-2015-3043" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3043" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whitehairman/Exploit" target="_blank" rel="noreferrer"&gt;whitehairman/Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3073
 &lt;div id="cve-2015-3073" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3073" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/reigningshells/CVE-2015-3073" target="_blank" rel="noreferrer"&gt;reigningshells/CVE-2015-3073&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3152
 &lt;div id="cve-2015-3152" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3152" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a &amp;quot;BACKRONYM&amp;quot; attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/duo-labs/mysslstrip" target="_blank" rel="noreferrer"&gt;duo-labs/mysslstrip&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3224
 &lt;div id="cve-2015-3224" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3224" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2015-3224" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2015-3224&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xEval/cve-2015-3224" target="_blank" rel="noreferrer"&gt;0xEval/cve-2015-3224&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3306
 &lt;div id="cve-2015-3306" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3306" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chcx/cpx_proftpd" target="_blank" rel="noreferrer"&gt;chcx/cpx_proftpd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nootropics/propane" target="_blank" rel="noreferrer"&gt;nootropics/propane&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/t0kx/exploit-CVE-2015-3306" target="_blank" rel="noreferrer"&gt;t0kx/exploit-CVE-2015-3306&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/davidtavarez/CVE-2015-3306" target="_blank" rel="noreferrer"&gt;davidtavarez/CVE-2015-3306&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2015-3306" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2015-3306&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hackarada/cve-2015-3306" target="_blank" rel="noreferrer"&gt;hackarada/cve-2015-3306&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3337
 &lt;div id="cve-2015-3337" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3337" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2015-3337" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2015-3337&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3456
 &lt;div id="cve-2015-3456" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3456" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vincentbernat/cve-2015-3456" target="_blank" rel="noreferrer"&gt;vincentbernat/cve-2015-3456&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/MauroEldritch/venom" target="_blank" rel="noreferrer"&gt;MauroEldritch/venom&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3636
 &lt;div id="cve-2015-3636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/betalphafai/cve-2015-3636_crash" target="_blank" rel="noreferrer"&gt;betalphafai/cve-2015-3636_crash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/askk/libping_unhash_exploit_POC" target="_blank" rel="noreferrer"&gt;askk/libping_unhash_exploit_POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ludongxu/cve-2015-3636" target="_blank" rel="noreferrer"&gt;ludongxu/cve-2015-3636&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fi01/CVE-2015-3636" target="_blank" rel="noreferrer"&gt;fi01/CVE-2015-3636&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/android-rooting-tools/libpingpong_exploit" target="_blank" rel="noreferrer"&gt;android-rooting-tools/libpingpong_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/debugfan/rattle_root" target="_blank" rel="noreferrer"&gt;debugfan/rattle_root&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/a7vinx/CVE-2015-3636" target="_blank" rel="noreferrer"&gt;a7vinx/CVE-2015-3636&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3825
 &lt;div id="cve-2015-3825" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3825" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/roeeh/conscryptchecker" target="_blank" rel="noreferrer"&gt;roeeh/conscryptchecker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3837
 &lt;div id="cve-2015-3837" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3837" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an application that sends a crafted Intent, aka internal bug 21437603.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/itibs/IsildursBane" target="_blank" rel="noreferrer"&gt;itibs/IsildursBane&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3839
 &lt;div id="cve-2015-3839" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3839" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mabin004/cve-2015-3839_PoC" target="_blank" rel="noreferrer"&gt;mabin004/cve-2015-3839_PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-3864
 &lt;div id="cve-2015-3864" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-3864" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pwnaccelerator/stagefright-cve-2015-3864" target="_blank" rel="noreferrer"&gt;pwnaccelerator/stagefright-cve-2015-3864&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eudemonics/scaredycat" target="_blank" rel="noreferrer"&gt;eudemonics/scaredycat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/HenryVHuang/CVE-2015-3864" target="_blank" rel="noreferrer"&gt;HenryVHuang/CVE-2015-3864&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-4495
 &lt;div id="cve-2015-4495" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-4495" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vincd/CVE-2015-4495" target="_blank" rel="noreferrer"&gt;vincd/CVE-2015-4495&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-4852
 &lt;div id="cve-2015-4852" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-4852" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/roo7break/serialator" target="_blank" rel="noreferrer"&gt;roo7break/serialator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/AndersonSingh/serialization-vulnerability-scanner" target="_blank" rel="noreferrer"&gt;AndersonSingh/serialization-vulnerability-scanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-4870
 &lt;div id="cve-2015-4870" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-4870" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/OsandaMalith/CVE-2015-4870" target="_blank" rel="noreferrer"&gt;OsandaMalith/CVE-2015-4870&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5119
 &lt;div id="cve-2015-5119" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5119" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jvazquez-r7/CVE-2015-5119" target="_blank" rel="noreferrer"&gt;jvazquez-r7/CVE-2015-5119&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/portcullislabs/CVE-2015-5119_walkthrough" target="_blank" rel="noreferrer"&gt;portcullislabs/CVE-2015-5119_walkthrough&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dangokyo/CVE-2015-5119" target="_blank" rel="noreferrer"&gt;dangokyo/CVE-2015-5119&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5195
 &lt;div id="cve-2015-5195" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5195" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/theglife214/CVE-2015-5195" target="_blank" rel="noreferrer"&gt;theglife214/CVE-2015-5195&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5254
 &lt;div id="cve-2015-5254" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5254" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jas502n/CVE-2015-5254" target="_blank" rel="noreferrer"&gt;jas502n/CVE-2015-5254&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5290
 &lt;div id="cve-2015-5290" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5290" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/skyhighwings/CVE-2015-5290" target="_blank" rel="noreferrer"&gt;skyhighwings/CVE-2015-5290&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5374
 &lt;div id="cve-2015-5374" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5374" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions &amp;lt; V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions &amp;lt; V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions &amp;lt; V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions &amp;lt; V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions &amp;lt; 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/can/CVE-2015-5374-DoS-PoC" target="_blank" rel="noreferrer"&gt;can/CVE-2015-5374-DoS-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5454
 &lt;div id="cve-2015-5454" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5454" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/security-breachlock/CVE-2015-5454" target="_blank" rel="noreferrer"&gt;security-breachlock/CVE-2015-5454&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5477
 &lt;div id="cve-2015-5477" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5477" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/robertdavidgraham/cve-2015-5477" target="_blank" rel="noreferrer"&gt;robertdavidgraham/cve-2015-5477&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/elceef/tkeypoc" target="_blank" rel="noreferrer"&gt;elceef/tkeypoc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hmlio/vaas-cve-2015-5477" target="_blank" rel="noreferrer"&gt;hmlio/vaas-cve-2015-5477&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/knqyf263/cve-2015-5477" target="_blank" rel="noreferrer"&gt;knqyf263/cve-2015-5477&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ilanyu/cve-2015-5477" target="_blank" rel="noreferrer"&gt;ilanyu/cve-2015-5477&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/denmilu/ShareDoc_cve-2015-5477" target="_blank" rel="noreferrer"&gt;denmilu/ShareDoc_cve-2015-5477&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5602
 &lt;div id="cve-2015-5602" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5602" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by &amp;quot;/home/*/*/file.txt.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/t0kx/privesc-CVE-2015-5602" target="_blank" rel="noreferrer"&gt;t0kx/privesc-CVE-2015-5602&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2015-5602" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2015-5602&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5932
 &lt;div id="cve-2015-5932" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5932" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel in Apple OS X before 10.11.1 allows local users to gain privileges by leveraging an unspecified &amp;quot;type confusion&amp;quot; during Mach task processing.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jndok/tpwn-bis" target="_blank" rel="noreferrer"&gt;jndok/tpwn-bis&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-5995
 &lt;div id="cve-2015-5995" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-5995" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shaheemirza/TendaSpill" target="_blank" rel="noreferrer"&gt;shaheemirza/TendaSpill&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6086
 &lt;div id="cve-2015-6086" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6086" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka &amp;quot;Internet Explorer Information Disclosure Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/payatu/CVE-2015-6086" target="_blank" rel="noreferrer"&gt;payatu/CVE-2015-6086&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6095
 &lt;div id="cve-2015-6095" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6095" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to bypass authentication, and conduct decryption attacks against certain BitLocker configurations, by connecting to an unintended Key Distribution Center (KDC), aka &amp;quot;Windows Kerberos Security Feature Bypass.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JackOfMostTrades/bluebox" target="_blank" rel="noreferrer"&gt;JackOfMostTrades/bluebox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6132
 &lt;div id="cve-2015-6132" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6132" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka &amp;quot;Windows Library Loading Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hexx0r/CVE-2015-6132" target="_blank" rel="noreferrer"&gt;hexx0r/CVE-2015-6132&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6357
 &lt;div id="cve-2015-6357" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6357" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mattimustang/firepwner" target="_blank" rel="noreferrer"&gt;mattimustang/firepwner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6576
 &lt;div id="cve-2015-6576" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6576" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CallMeJonas/CVE-2015-6576" target="_blank" rel="noreferrer"&gt;CallMeJonas/CVE-2015-6576&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6606
 &lt;div id="cve-2015-6606" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6606" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/michaelroland/omapi-cve-2015-6606-exploit" target="_blank" rel="noreferrer"&gt;michaelroland/omapi-cve-2015-6606-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6612
 &lt;div id="cve-2015-6612" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6612" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/secmob/CVE-2015-6612" target="_blank" rel="noreferrer"&gt;secmob/CVE-2015-6612&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/flankerhqd/cve-2015-6612poc-forM" target="_blank" rel="noreferrer"&gt;flankerhqd/cve-2015-6612poc-forM&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6620
 &lt;div id="cve-2015-6620" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6620" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 24123723 and 24445127.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/flankerhqd/CVE-2015-6620-POC" target="_blank" rel="noreferrer"&gt;flankerhqd/CVE-2015-6620-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/flankerhqd/mediacodecoob" target="_blank" rel="noreferrer"&gt;flankerhqd/mediacodecoob&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6637
 &lt;div id="cve-2015-6637" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6637" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/betalphafai/CVE-2015-6637" target="_blank" rel="noreferrer"&gt;betalphafai/CVE-2015-6637&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6639
 &lt;div id="cve-2015-6639" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6639" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/laginimaineb/cve-2015-6639" target="_blank" rel="noreferrer"&gt;laginimaineb/cve-2015-6639&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/laginimaineb/ExtractKeyMaster" target="_blank" rel="noreferrer"&gt;laginimaineb/ExtractKeyMaster&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6640
 &lt;div id="cve-2015-6640" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6640" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/betalphafai/CVE-2015-6640" target="_blank" rel="noreferrer"&gt;betalphafai/CVE-2015-6640&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6835
 &lt;div id="cve-2015-6835" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6835" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ockeghem/CVE-2015-6835-checker" target="_blank" rel="noreferrer"&gt;ockeghem/CVE-2015-6835-checker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-6967
 &lt;div id="cve-2015-6967" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-6967" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/VanTekken/CVE-2015-6967" target="_blank" rel="noreferrer"&gt;VanTekken/CVE-2015-6967&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7214
 &lt;div id="cve-2015-7214" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7214" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/llamakko/CVE-2015-7214" target="_blank" rel="noreferrer"&gt;llamakko/CVE-2015-7214&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7297
 &lt;div id="cve-2015-7297" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7297" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/CCrashBandicot/ContentHistory" target="_blank" rel="noreferrer"&gt;CCrashBandicot/ContentHistory&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7501
 &lt;div id="cve-2015-7501" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7501" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ianxtianxt/CVE-2015-7501" target="_blank" rel="noreferrer"&gt;ianxtianxt/CVE-2015-7501&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7545
 &lt;div id="cve-2015-7545" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7545" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/avuserow/bug-free-chainsaw" target="_blank" rel="noreferrer"&gt;avuserow/bug-free-chainsaw&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7547
 &lt;div id="cve-2015-7547" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7547" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing &amp;quot;dual A/AAAA DNS queries&amp;quot; and the libnss_dns.so.2 NSS module.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fjserna/CVE-2015-7547" target="_blank" rel="noreferrer"&gt;fjserna/CVE-2015-7547&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cakuzo/CVE-2015-7547" target="_blank" rel="noreferrer"&gt;cakuzo/CVE-2015-7547&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/t0r0t0r0/CVE-2015-7547" target="_blank" rel="noreferrer"&gt;t0r0t0r0/CVE-2015-7547&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JustDenisYT/glibc-patcher" target="_blank" rel="noreferrer"&gt;JustDenisYT/glibc-patcher&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rexifiles/rex-sec-glibc" target="_blank" rel="noreferrer"&gt;rexifiles/rex-sec-glibc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/babykillerblack/CVE-2015-7547" target="_blank" rel="noreferrer"&gt;babykillerblack/CVE-2015-7547&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jgajek/cve-2015-7547" target="_blank" rel="noreferrer"&gt;jgajek/cve-2015-7547&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/eSentire/cve-2015-7547-public" target="_blank" rel="noreferrer"&gt;eSentire/cve-2015-7547-public&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bluebluelan/CVE-2015-7547-proj-master" target="_blank" rel="noreferrer"&gt;bluebluelan/CVE-2015-7547-proj-master&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/miracle03/CVE-2015-7547-master" target="_blank" rel="noreferrer"&gt;miracle03/CVE-2015-7547-master&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7755
 &lt;div id="cve-2015-7755" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7755" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hdm/juniper-cve-2015-7755" target="_blank" rel="noreferrer"&gt;hdm/juniper-cve-2015-7755&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cinno/CVE-2015-7755-POC" target="_blank" rel="noreferrer"&gt;cinno/CVE-2015-7755-POC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-7808
 &lt;div id="cve-2015-7808" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-7808" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Prajithp/CVE-2015-7808" target="_blank" rel="noreferrer"&gt;Prajithp/CVE-2015-7808&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8088
 &lt;div id="cve-2015-8088" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8088" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 and P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, GRA-CL10 before GRA-CL10C92B220, GRA-UL00 before GRA-UL00C00B220, and GRA-UL10 before GRA-UL10C00B220 allows attackers to cause a denial of service (reboot) or execute arbitrary code via a crafted application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Pray3r/CVE-2015-8088" target="_blank" rel="noreferrer"&gt;Pray3r/CVE-2015-8088&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8103
 &lt;div id="cve-2015-8103" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8103" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the &amp;quot;Groovy variant in 'ysoserial'&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2015-8103" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2015-8103&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8277
 &lt;div id="cve-2015-8277" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8277" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/securifera/CVE-2015-8277-Exploit" target="_blank" rel="noreferrer"&gt;securifera/CVE-2015-8277-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8299
 &lt;div id="cve-2015-8299" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8299" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted KNXnet/IP UDP packet.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kernoelpanic/CVE-2015-8299" target="_blank" rel="noreferrer"&gt;kernoelpanic/CVE-2015-8299&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8543
 &lt;div id="cve-2015-8543" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8543" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bittorrent3389/CVE-2015-8543_for_SLE12SP1" target="_blank" rel="noreferrer"&gt;bittorrent3389/CVE-2015-8543_for_SLE12SP1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8562
 &lt;div id="cve-2015-8562" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8562" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ZaleHack/joomla_rce_CVE-2015-8562" target="_blank" rel="noreferrer"&gt;ZaleHack/joomla_rce_CVE-2015-8562&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RobinHoutevelts/Joomla-CVE-2015-8562-PHP-POC" target="_blank" rel="noreferrer"&gt;RobinHoutevelts/Joomla-CVE-2015-8562-PHP-POC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/atcasanova/cve-2015-8562-exploit" target="_blank" rel="noreferrer"&gt;atcasanova/cve-2015-8562-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/thejackerz/scanner-exploit-joomla-CVE-2015-8562" target="_blank" rel="noreferrer"&gt;thejackerz/scanner-exploit-joomla-CVE-2015-8562&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/paralelo14/CVE-2015-8562" target="_blank" rel="noreferrer"&gt;paralelo14/CVE-2015-8562&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/VoidSec/Joomla_CVE-2015-8562" target="_blank" rel="noreferrer"&gt;VoidSec/Joomla_CVE-2015-8562&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xnorkl/Joomla_Payload" target="_blank" rel="noreferrer"&gt;xnorkl/Joomla_Payload&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8651
 &lt;div id="cve-2015-8651" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8651" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK &amp;amp; Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Gitlabpro/The-analysis-of-the-cve-2015-8651" target="_blank" rel="noreferrer"&gt;Gitlabpro/The-analysis-of-the-cve-2015-8651&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8660
 &lt;div id="cve-2015-8660" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8660" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whu-enjoy/CVE-2015-8660" target="_blank" rel="noreferrer"&gt;whu-enjoy/CVE-2015-8660&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-8710
 &lt;div id="cve-2015-8710" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-8710" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Karm/CVE-2015-8710" target="_blank" rel="noreferrer"&gt;Karm/CVE-2015-8710&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2015-9251
 &lt;div id="cve-2015-9251" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2015-9251" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/halkichi0308/CVE-2015-9251" target="_blank" rel="noreferrer"&gt;halkichi0308/CVE-2015-9251&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2014
 &lt;div id="2014" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2014" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0038
 &lt;div id="cve-2014-0038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/saelo/cve-2014-0038" target="_blank" rel="noreferrer"&gt;saelo/cve-2014-0038&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0050
 &lt;div id="cve-2014-0050" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0050" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jrrdev/cve-2014-0050" target="_blank" rel="noreferrer"&gt;jrrdev/cve-2014-0050&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0094
 &lt;div id="cve-2014-0094" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0094" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to &amp;quot;manipulate&amp;quot; the ClassLoader via the class parameter, which is passed to the getClass method.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HasegawaTadamitsu/CVE-2014-0094-test-program-for-struts1" target="_blank" rel="noreferrer"&gt;HasegawaTadamitsu/CVE-2014-0094-test-program-for-struts1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0114
 &lt;div id="cve-2014-0114" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0114" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to &amp;quot;manipulate&amp;quot; the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rgielen/struts1filter" target="_blank" rel="noreferrer"&gt;rgielen/struts1filter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ricedu/struts1-patch" target="_blank" rel="noreferrer"&gt;ricedu/struts1-patch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/anob3it/strutt-cve-2014-0114" target="_blank" rel="noreferrer"&gt;anob3it/strutt-cve-2014-0114&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0130
 &lt;div id="cve-2014-0130" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0130" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/omarkurt/cve-2014-0130" target="_blank" rel="noreferrer"&gt;omarkurt/cve-2014-0130&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0160
 &lt;div id="cve-2014-0160" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0160" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/FiloSottile/Heartbleed" target="_blank" rel="noreferrer"&gt;FiloSottile/Heartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/titanous/heartbleeder" target="_blank" rel="noreferrer"&gt;titanous/heartbleeder&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DominikTo/bleed" target="_blank" rel="noreferrer"&gt;DominikTo/bleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cyphar/heartthreader" target="_blank" rel="noreferrer"&gt;cyphar/heartthreader&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jdauphant/patch-openssl-CVE-2014-0160" target="_blank" rel="noreferrer"&gt;jdauphant/patch-openssl-CVE-2014-0160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/musalbas/heartbleed-masstest" target="_blank" rel="noreferrer"&gt;musalbas/heartbleed-masstest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/obayesshelton/CVE-2014-0160-Scanner" target="_blank" rel="noreferrer"&gt;obayesshelton/CVE-2014-0160-Scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Lekensteyn/pacemaker" target="_blank" rel="noreferrer"&gt;Lekensteyn/pacemaker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/isgroup-srl/openmagic" target="_blank" rel="noreferrer"&gt;isgroup-srl/openmagic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fb1h2s/CVE-2014-0160" target="_blank" rel="noreferrer"&gt;fb1h2s/CVE-2014-0160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/roganartu/heartbleedchecker-chrome" target="_blank" rel="noreferrer"&gt;roganartu/heartbleedchecker-chrome&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zouguangxian/heartbleed" target="_blank" rel="noreferrer"&gt;zouguangxian/heartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sensepost/heartbleed-poc" target="_blank" rel="noreferrer"&gt;sensepost/heartbleed-poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/proactiveRISK/heartbleed-extention" target="_blank" rel="noreferrer"&gt;proactiveRISK/heartbleed-extention&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/amerine/coronary" target="_blank" rel="noreferrer"&gt;amerine/coronary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x90/CVE-2014-0160" target="_blank" rel="noreferrer"&gt;0x90/CVE-2014-0160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ice-security88/CVE-2014-0160" target="_blank" rel="noreferrer"&gt;ice-security88/CVE-2014-0160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker" target="_blank" rel="noreferrer"&gt;waqasjamal-zz/HeartBleed-Vulnerability-Checker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/siddolo/knockbleed" target="_blank" rel="noreferrer"&gt;siddolo/knockbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sammyfung/openssl-heartbleed-fix" target="_blank" rel="noreferrer"&gt;sammyfung/openssl-heartbleed-fix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/a0726h77/heartbleed-test" target="_blank" rel="noreferrer"&gt;a0726h77/heartbleed-test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hreese/heartbleed-dtls" target="_blank" rel="noreferrer"&gt;hreese/heartbleed-dtls&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wwwiretap/bleeding_onions" target="_blank" rel="noreferrer"&gt;wwwiretap/bleeding_onions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/idkqh7/heatbleeding" target="_blank" rel="noreferrer"&gt;idkqh7/heatbleeding&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GeeksXtreme/ssl-heartbleed.nse" target="_blank" rel="noreferrer"&gt;GeeksXtreme/ssl-heartbleed.nse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xlucas/heartbleed" target="_blank" rel="noreferrer"&gt;xlucas/heartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/indiw0rm/-Heartbleed-" target="_blank" rel="noreferrer"&gt;indiw0rm/-Heartbleed-&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/einaros/heartbleed-tools" target="_blank" rel="noreferrer"&gt;einaros/heartbleed-tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mozilla-services/Heartbleed" target="_blank" rel="noreferrer"&gt;mozilla-services/Heartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/yryz/heartbleed.js" target="_blank" rel="noreferrer"&gt;yryz/heartbleed.js&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DisK0nn3cT/MaltegoHeartbleed" target="_blank" rel="noreferrer"&gt;DisK0nn3cT/MaltegoHeartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/OffensivePython/HeartLeak" target="_blank" rel="noreferrer"&gt;OffensivePython/HeartLeak&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vortextube/ssl_scanner" target="_blank" rel="noreferrer"&gt;vortextube/ssl_scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/heartbleed-PoC" target="_blank" rel="noreferrer"&gt;mpgn/heartbleed-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xanas/heartbleed.py" target="_blank" rel="noreferrer"&gt;xanas/heartbleed.py&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iSCInc/heartbleed" target="_blank" rel="noreferrer"&gt;iSCInc/heartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang" target="_blank" rel="noreferrer"&gt;marstornado/cve-2014-0160-Yunfeng-Jiang&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hmlio/vaas-cve-2014-0160" target="_blank" rel="noreferrer"&gt;hmlio/vaas-cve-2014-0160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hybridus/heartbleedscanner" target="_blank" rel="noreferrer"&gt;hybridus/heartbleedscanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin" target="_blank" rel="noreferrer"&gt;Xyl2k/CVE-2014-0160-Chrome-Plugin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kaosV20/Heartexploit" target="_blank" rel="noreferrer"&gt;kaosV20/Heartexploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC" target="_blank" rel="noreferrer"&gt;caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Saymeis/HeartBleed" target="_blank" rel="noreferrer"&gt;Saymeis/HeartBleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2014-0160" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2014-0160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cheese-hub/heartbleed" target="_blank" rel="noreferrer"&gt;cheese-hub/heartbleed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/artofscripting/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS" target="_blank" rel="noreferrer"&gt;artofscripting/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cldme/heartbleed-bug" target="_blank" rel="noreferrer"&gt;cldme/heartbleed-bug&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hack3r-0m/heartbleed_fix_updated" target="_blank" rel="noreferrer"&gt;hack3r-0m/heartbleed_fix_updated&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0166
 &lt;div id="cve-2014-0166" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0166" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Ettack/POC-CVE-2014-0166" target="_blank" rel="noreferrer"&gt;Ettack/POC-CVE-2014-0166&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0195
 &lt;div id="cve-2014-0195" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0195" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ricedu/CVE-2014-0195" target="_blank" rel="noreferrer"&gt;ricedu/CVE-2014-0195&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0196
 &lt;div id="cve-2014-0196" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0196" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the &amp;quot;LECHO &amp;amp; !OPOST&amp;quot; case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SunRain/CVE-2014-0196" target="_blank" rel="noreferrer"&gt;SunRain/CVE-2014-0196&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tempbottle/CVE-2014-0196" target="_blank" rel="noreferrer"&gt;tempbottle/CVE-2014-0196&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0224
 &lt;div id="cve-2014-0224" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0224" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the &amp;quot;CCS Injection&amp;quot; vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Tripwire/OpenSSL-CCS-Inject-Test" target="_blank" rel="noreferrer"&gt;Tripwire/OpenSSL-CCS-Inject-Test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iph0n3/CVE-2014-0224" target="_blank" rel="noreferrer"&gt;iph0n3/CVE-2014-0224&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/droptables/ccs-eval" target="_blank" rel="noreferrer"&gt;droptables/ccs-eval&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ssllabs/openssl-ccs-cve-2014-0224" target="_blank" rel="noreferrer"&gt;ssllabs/openssl-ccs-cve-2014-0224&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/secretnonempty/CVE-2014-0224" target="_blank" rel="noreferrer"&gt;secretnonempty/CVE-2014-0224&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0291
 &lt;div id="cve-2014-0291" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0291" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/niccoX/patch-openssl-CVE-2014-0291_CVE-2015-0204" target="_blank" rel="noreferrer"&gt;niccoX/patch-openssl-CVE-2014-0291_CVE-2015-0204&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0521
 &lt;div id="cve-2014-0521" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0521" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X do not properly implement JavaScript APIs, which allows remote attackers to obtain sensitive information via a crafted PDF document.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/molnarg/cve-2014-0521" target="_blank" rel="noreferrer"&gt;molnarg/cve-2014-0521&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0816
 &lt;div id="cve-2014-0816" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0816" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in Norman Security Suite 10.1 and earlier allows local users to gain privileges via unknown vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tandasat/CVE-2014-0816" target="_blank" rel="noreferrer"&gt;tandasat/CVE-2014-0816&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-0993
 &lt;div id="cve-2014-0993" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-0993" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/helpsystems/Embarcadero-Workaround" target="_blank" rel="noreferrer"&gt;helpsystems/Embarcadero-Workaround&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-10069
 &lt;div id="cve-2014-10069" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-10069" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrated by a password hash in the um_auth_account_password field.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Manouchehri/hitron-cfg-decrypter" target="_blank" rel="noreferrer"&gt;Manouchehri/hitron-cfg-decrypter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-1266
 &lt;div id="cve-2014-1266" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-1266" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple OS X 10.9.x before 10.9.2 does not check the signature in a TLS Server Key Exchange message, which allows man-in-the-middle attackers to spoof SSL servers by (1) using an arbitrary private key for the signing step or (2) omitting the signing step.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/landonf/Testability-CVE-2014-1266" target="_blank" rel="noreferrer"&gt;landonf/Testability-CVE-2014-1266&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/linusyang/SSLPatch" target="_blank" rel="noreferrer"&gt;linusyang/SSLPatch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gabrielg/CVE-2014-1266-poc" target="_blank" rel="noreferrer"&gt;gabrielg/CVE-2014-1266-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-1303
 &lt;div id="cve-2014-1303" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-1303" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RKX1209/CVE-2014-1303" target="_blank" rel="noreferrer"&gt;RKX1209/CVE-2014-1303&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-1322
 &lt;div id="cve-2014-1322" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-1322" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user space, which makes it easier for local users to bypass the ASLR protection mechanism by reading an unspecified attribute of the object.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/raymondpittman/IPC-Memory-Mac-OSX-Exploit" target="_blank" rel="noreferrer"&gt;raymondpittman/IPC-Memory-Mac-OSX-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-1447
 &lt;div id="cve-2014-1447" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-1447" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tagatac/libvirt-CVE-2014-1447" target="_blank" rel="noreferrer"&gt;tagatac/libvirt-CVE-2014-1447&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-160
 &lt;div id="cve-2014-160" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-160" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/menrcom/CVE-2014-160" target="_blank" rel="noreferrer"&gt;menrcom/CVE-2014-160&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GitMirar/heartbleed_exploit" target="_blank" rel="noreferrer"&gt;GitMirar/heartbleed_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-1677
 &lt;div id="cve-2014-1677" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-1677" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tihmstar/freePW_tc7200Eploit" target="_blank" rel="noreferrer"&gt;tihmstar/freePW_tc7200Eploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-1773
 &lt;div id="cve-2014-1773" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-1773" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka &amp;quot;Internet Explorer Memory Corruption Vulnerability,&amp;quot; a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/day6reak/CVE-2014-1773" target="_blank" rel="noreferrer"&gt;day6reak/CVE-2014-1773&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-2064
 &lt;div id="cve-2014-2064" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-2064" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Naramsim/Offensive" target="_blank" rel="noreferrer"&gt;Naramsim/Offensive&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-2323
 &lt;div id="cve-2014-2323" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-2323" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cirocosta/lighty-sqlinj-demo" target="_blank" rel="noreferrer"&gt;cirocosta/lighty-sqlinj-demo&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-2324
 &lt;div id="cve-2014-2324" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-2324" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sp4c30x1/uc_httpd_exploit" target="_blank" rel="noreferrer"&gt;sp4c30x1/uc_httpd_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-2630
 &lt;div id="cve-2014-2630" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-2630" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/redtimmy/perf-exploiter" target="_blank" rel="noreferrer"&gt;redtimmy/perf-exploiter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-2734
 &lt;div id="cve-2014-2734" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-2734" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to spoof signatures within the context of a Ruby script that attempts signature verification after performing a certain sequence of filesystem operations. NOTE: this issue has been disputed by the Ruby OpenSSL team and third parties, who state that the original demonstration PoC contains errors and redundant or unnecessarily-complex code that does not appear to be related to a demonstration of the issue. As of 20140502, CVE is not aware of any public comment by the original researcher.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gdisneyleugers/CVE-2014-2734" target="_blank" rel="noreferrer"&gt;gdisneyleugers/CVE-2014-2734&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/adrienthebo/cve-2014-2734" target="_blank" rel="noreferrer"&gt;adrienthebo/cve-2014-2734&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3120
 &lt;div id="cve-2014-3120" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3120" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jeffgeiger/es_inject" target="_blank" rel="noreferrer"&gt;jeffgeiger/es_inject&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/echohtp/ElasticSearch-CVE-2014-3120" target="_blank" rel="noreferrer"&gt;echohtp/ElasticSearch-CVE-2014-3120&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3153
 &lt;div id="cve-2014-3153" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3153" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/timwr/CVE-2014-3153" target="_blank" rel="noreferrer"&gt;timwr/CVE-2014-3153&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/android-rooting-tools/libfutex_exploit" target="_blank" rel="noreferrer"&gt;android-rooting-tools/libfutex_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/geekben/towelroot" target="_blank" rel="noreferrer"&gt;geekben/towelroot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lieanu/CVE-2014-3153" target="_blank" rel="noreferrer"&gt;lieanu/CVE-2014-3153&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zerodavinci/CVE-2014-3153-exploit" target="_blank" rel="noreferrer"&gt;zerodavinci/CVE-2014-3153-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/c3c/CVE-2014-3153" target="_blank" rel="noreferrer"&gt;c3c/CVE-2014-3153&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dangtunguyen/TowelRoot" target="_blank" rel="noreferrer"&gt;dangtunguyen/TowelRoot&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3341
 &lt;div id="cve-2014-3341" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3341" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ehabhussein/snmpvlan" target="_blank" rel="noreferrer"&gt;ehabhussein/snmpvlan&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3466
 &lt;div id="cve-2014-3466" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3466" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/azet/CVE-2014-3466_PoC" target="_blank" rel="noreferrer"&gt;azet/CVE-2014-3466_PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3566
 &lt;div id="cve-2014-3566" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3566" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the &amp;quot;POODLE&amp;quot; issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mikesplain/CVE-2014-3566-poodle-cookbook" target="_blank" rel="noreferrer"&gt;mikesplain/CVE-2014-3566-poodle-cookbook&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/stdevel/poodle_protector" target="_blank" rel="noreferrer"&gt;stdevel/poodle_protector&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ashmastaflash/mangy-beast" target="_blank" rel="noreferrer"&gt;ashmastaflash/mangy-beast&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/poodle-PoC" target="_blank" rel="noreferrer"&gt;mpgn/poodle-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3625
 &lt;div id="cve-2014-3625" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3625" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ilmila/springcss-cve-2014-3625" target="_blank" rel="noreferrer"&gt;ilmila/springcss-cve-2014-3625&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gforresu/SpringPathTraversal" target="_blank" rel="noreferrer"&gt;gforresu/SpringPathTraversal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-3704
 &lt;div id="cve-2014-3704" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-3704" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/happynote3966/CVE-2014-3704" target="_blank" rel="noreferrer"&gt;happynote3966/CVE-2014-3704&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4014
 &lt;div id="cve-2014-4014" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4014" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vnik5287/cve-2014-4014-privesc" target="_blank" rel="noreferrer"&gt;vnik5287/cve-2014-4014-privesc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4076
 &lt;div id="cve-2014-4076" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4076" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2) tcpip6.sys, aka &amp;quot;TCP/IP Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fungoshacks/CVE-2014-4076" target="_blank" rel="noreferrer"&gt;fungoshacks/CVE-2014-4076&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4109
 &lt;div id="cve-2014-4109" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4109" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka &amp;quot;Internet Explorer Memory Corruption Vulnerability,&amp;quot; a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4110, and CVE-2014-4111.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/day6reak/CVE-2014-4109" target="_blank" rel="noreferrer"&gt;day6reak/CVE-2014-4109&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4113
 &lt;div id="cve-2014-4113" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4113" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka &amp;quot;Win32k.sys Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/johnjohnsp1/CVE-2014-4113" target="_blank" rel="noreferrer"&gt;johnjohnsp1/CVE-2014-4113&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nsxz/Exploit-CVE-2014-4113" target="_blank" rel="noreferrer"&gt;nsxz/Exploit-CVE-2014-4113&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sam-b/CVE-2014-4113" target="_blank" rel="noreferrer"&gt;sam-b/CVE-2014-4113&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4140
 &lt;div id="cve-2014-4140" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4140" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka &amp;quot;Internet Explorer ASLR Bypass Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/day6reak/CVE-2014-4140" target="_blank" rel="noreferrer"&gt;day6reak/CVE-2014-4140&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4210
 &lt;div id="cve-2014-4210" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4210" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/NoneNotNull/SSRFX" target="_blank" rel="noreferrer"&gt;NoneNotNull/SSRFX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xn0ne/weblogicScanner" target="_blank" rel="noreferrer"&gt;0xn0ne/weblogicScanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4321
 &lt;div id="cve-2014-4321" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4321" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/android-rooting-tools/libmsm_vfe_read_exploit" target="_blank" rel="noreferrer"&gt;android-rooting-tools/libmsm_vfe_read_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4322
 &lt;div id="cve-2014-4322" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4322" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call, which allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/retme7/CVE-2014-4322_poc" target="_blank" rel="noreferrer"&gt;retme7/CVE-2014-4322_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/laginimaineb/cve-2014-4322" target="_blank" rel="noreferrer"&gt;laginimaineb/cve-2014-4322&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/askk/CVE-2014-4322_adaptation" target="_blank" rel="noreferrer"&gt;askk/CVE-2014-4322_adaptation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/koozxcv/CVE-2014-4322" target="_blank" rel="noreferrer"&gt;koozxcv/CVE-2014-4322&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4323
 &lt;div id="cve-2014-4323" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4323" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and length values within an ioctl call, which allows attackers to gain privileges via a crafted application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/marcograss/cve-2014-4323" target="_blank" rel="noreferrer"&gt;marcograss/cve-2014-4323&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4377
 &lt;div id="cve-2014-4377" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4377" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/feliam/CVE-2014-4377" target="_blank" rel="noreferrer"&gt;feliam/CVE-2014-4377&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/davidmurray/CVE-2014-4377" target="_blank" rel="noreferrer"&gt;davidmurray/CVE-2014-4377&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4378
 &lt;div id="cve-2014-4378" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4378" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted PDF document.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/feliam/CVE-2014-4378" target="_blank" rel="noreferrer"&gt;feliam/CVE-2014-4378&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4481
 &lt;div id="cve-2014-4481" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4481" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/feliam/CVE-2014-4481" target="_blank" rel="noreferrer"&gt;feliam/CVE-2014-4481&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4511
 &lt;div id="cve-2014-4511" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4511" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/michaelsss1/gitlist-RCE" target="_blank" rel="noreferrer"&gt;michaelsss1/gitlist-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4671
 &lt;div id="cve-2014-4671" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4671" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK &amp;amp; Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cph/rabl-old" target="_blank" rel="noreferrer"&gt;cph/rabl-old&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4699
 &lt;div id="cve-2014-4699" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4699" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vnik5287/cve-2014-4699-ptrace" target="_blank" rel="noreferrer"&gt;vnik5287/cve-2014-4699-ptrace&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4936
 &lt;div id="cve-2014-4936" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4936" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x3a/CVE-2014-4936" target="_blank" rel="noreferrer"&gt;0x3a/CVE-2014-4936&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-4943
 &lt;div id="cve-2014-4943" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-4943" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/redes-2015/l2tp-socket-bug" target="_blank" rel="noreferrer"&gt;redes-2015/l2tp-socket-bug&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-5284
 &lt;div id="cve-2014-5284" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-5284" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mbadanoiu/CVE-2014-5284" target="_blank" rel="noreferrer"&gt;mbadanoiu/CVE-2014-5284&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-6271
 &lt;div id="cve-2014-6271" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-6271" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka &amp;quot;ShellShock.&amp;quot; NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dlitz/bash-cve-2014-6271-fixes" target="_blank" rel="noreferrer"&gt;dlitz/bash-cve-2014-6271-fixes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/npm/ansible-bashpocalypse" target="_blank" rel="noreferrer"&gt;npm/ansible-bashpocalypse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ryancnelson/patched-bash-4.3" target="_blank" rel="noreferrer"&gt;ryancnelson/patched-bash-4.3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jblaine/cookbook-bash-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;jblaine/cookbook-bash-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rrreeeyyy/cve-2014-6271-spec" target="_blank" rel="noreferrer"&gt;rrreeeyyy/cve-2014-6271-spec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/scottjpack/shellshock_scanner" target="_blank" rel="noreferrer"&gt;scottjpack/shellshock_scanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Anklebiter87/Cgi-bin_bash_Reverse" target="_blank" rel="noreferrer"&gt;Anklebiter87/Cgi-bin_bash_Reverse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/justzx2011/bash-up" target="_blank" rel="noreferrer"&gt;justzx2011/bash-up&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mattclegg/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;mattclegg/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ilismal/Nessus_CVE-2014-6271_check" target="_blank" rel="noreferrer"&gt;ilismal/Nessus_CVE-2014-6271_check&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RainMak3r/Rainstorm" target="_blank" rel="noreferrer"&gt;RainMak3r/Rainstorm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gabemarshall/shocknaww" target="_blank" rel="noreferrer"&gt;gabemarshall/shocknaww&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/woltage/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;woltage/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ariarijp/vagrant-shellshock" target="_blank" rel="noreferrer"&gt;ariarijp/vagrant-shellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/themson/shellshock" target="_blank" rel="noreferrer"&gt;themson/shellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/securusglobal/BadBash" target="_blank" rel="noreferrer"&gt;securusglobal/BadBash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/villadora/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;villadora/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/APSL/salt-shellshock" target="_blank" rel="noreferrer"&gt;APSL/salt-shellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/teedeedubya/bash-fix-exploit" target="_blank" rel="noreferrer"&gt;teedeedubya/bash-fix-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/internero/debian-lenny-bash_3.2.52-cve-2014-6271" target="_blank" rel="noreferrer"&gt;internero/debian-lenny-bash_3.2.52-cve-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwnGuy/shellshock-shell" target="_blank" rel="noreferrer"&gt;pwnGuy/shellshock-shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vonnyfly/shellshock_crawler" target="_blank" rel="noreferrer"&gt;vonnyfly/shellshock_crawler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/u20024804/bash-3.2-fixed-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;u20024804/bash-3.2-fixed-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/u20024804/bash-4.2-fixed-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;u20024804/bash-4.2-fixed-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/u20024804/bash-4.3-fixed-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;u20024804/bash-4.3-fixed-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/francisck/shellshock-cgi" target="_blank" rel="noreferrer"&gt;francisck/shellshock-cgi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/proclnas/ShellShock-CGI-Scan" target="_blank" rel="noreferrer"&gt;proclnas/ShellShock-CGI-Scan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sch3m4/RIS" target="_blank" rel="noreferrer"&gt;sch3m4/RIS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ryeyao/CVE-2014-6271_Test" target="_blank" rel="noreferrer"&gt;ryeyao/CVE-2014-6271_Test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cj1324/CGIShell" target="_blank" rel="noreferrer"&gt;cj1324/CGIShell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/renanvicente/puppet-shellshock" target="_blank" rel="noreferrer"&gt;renanvicente/puppet-shellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/indiandragon/Shellshock-Vulnerability-Scan" target="_blank" rel="noreferrer"&gt;indiandragon/Shellshock-Vulnerability-Scan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ramnes/pyshellshock" target="_blank" rel="noreferrer"&gt;ramnes/pyshellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/akiraaisha/shellshocker-python" target="_blank" rel="noreferrer"&gt;akiraaisha/shellshocker-python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kelleykong/cve-2014-6271-mengjia-kong" target="_blank" rel="noreferrer"&gt;kelleykong/cve-2014-6271-mengjia-kong&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/huanlu/cve-2014-6271-huan-lu" target="_blank" rel="noreferrer"&gt;huanlu/cve-2014-6271-huan-lu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sunnyjiang/shellshocker-android" target="_blank" rel="noreferrer"&gt;sunnyjiang/shellshocker-android&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/P0cL4bs/ShellShock-CGI-Scan" target="_blank" rel="noreferrer"&gt;P0cL4bs/ShellShock-CGI-Scan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hmlio/vaas-cve-2014-6271" target="_blank" rel="noreferrer"&gt;hmlio/vaas-cve-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/opsxcq/exploit-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;opsxcq/exploit-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Pilou-Pilou/docker_CVE-2014-6271." target="_blank" rel="noreferrer"&gt;Pilou-Pilou/docker_CVE-2014-6271.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zalalov/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;zalalov/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0x00-0x00/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;0x00-0x00/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kowshik-sundararajan/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;kowshik-sundararajan/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/w4fz5uck5/ShockZaum-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;w4fz5uck5/ShockZaum-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Aruthw/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;Aruthw/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2014-6271" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/shawntns/exploit-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;shawntns/exploit-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sindadziy/cve-2014-6271" target="_blank" rel="noreferrer"&gt;Sindadziy/cve-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/wenyu1999/bash-shellshock" target="_blank" rel="noreferrer"&gt;wenyu1999/bash-shellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271" target="_blank" rel="noreferrer"&gt;Sindayifu/CVE-2019-14287-CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Any3ite/CVE-2014-6271" target="_blank" rel="noreferrer"&gt;Any3ite/CVE-2014-6271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/somhm-solutions/Shell-Shock" target="_blank" rel="noreferrer"&gt;somhm-solutions/Shell-Shock&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-6287
 &lt;div id="cve-2014-6287" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-6287" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/roughiz/cve-2014-6287.py" target="_blank" rel="noreferrer"&gt;roughiz/cve-2014-6287.py&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-6332
 &lt;div id="cve-2014-6332" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-6332" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka &amp;quot;Windows OLE Automation Array Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MarkoArmitage/metasploit-framework" target="_blank" rel="noreferrer"&gt;MarkoArmitage/metasploit-framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tjjh89017/cve-2014-6332" target="_blank" rel="noreferrer"&gt;tjjh89017/cve-2014-6332&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mourr/CVE-2014-6332" target="_blank" rel="noreferrer"&gt;mourr/CVE-2014-6332&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-6577
 &lt;div id="cve-2014-6577" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-6577" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the original researcher's claim that this is an XML external entity (XXE) vulnerability in the XML parser, which allows attackers to conduct internal port scanning, perform SSRF attacks, or cause a denial of service via a crafted (1) http: or (2) ftp: URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SecurityArtWork/oracle-xxe-sqli" target="_blank" rel="noreferrer"&gt;SecurityArtWork/oracle-xxe-sqli&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-6598
 &lt;div id="cve-2014-6598" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-6598" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KPN-CISO/DRA_writeup" target="_blank" rel="noreferrer"&gt;KPN-CISO/DRA_writeup&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-7169
 &lt;div id="cve-2014-7169" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-7169" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/chef-boneyard/bash-shellshock" target="_blank" rel="noreferrer"&gt;chef-boneyard/bash-shellshock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gina-alaska/bash-cve-2014-7169-cookbook" target="_blank" rel="noreferrer"&gt;gina-alaska/bash-cve-2014-7169-cookbook&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-7236
 &lt;div id="cve-2014-7236" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-7236" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/m0nad/CVE-2014-7236_Exploit" target="_blank" rel="noreferrer"&gt;m0nad/CVE-2014-7236_Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-7911
 &lt;div id="cve-2014-7911" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-7911" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deserialization will result in an object that met the requirements for serialization, which allows attackers to execute arbitrary code via a crafted finalize method for a serialized object in an ArrayMap Parcel within an intent sent to system_service, as demonstrated by the finalize method of android.os.BinderProxy, aka Bug 15874291.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/retme7/CVE-2014-7911_poc" target="_blank" rel="noreferrer"&gt;retme7/CVE-2014-7911_poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ele7enxxh/CVE-2014-7911" target="_blank" rel="noreferrer"&gt;ele7enxxh/CVE-2014-7911&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/heeeeen/CVE-2014-7911poc" target="_blank" rel="noreferrer"&gt;heeeeen/CVE-2014-7911poc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/GeneBlue/cve-2014-7911-exp" target="_blank" rel="noreferrer"&gt;GeneBlue/cve-2014-7911-exp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/koozxcv/CVE-2014-7911" target="_blank" rel="noreferrer"&gt;koozxcv/CVE-2014-7911&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/koozxcv/CVE-2014-7911-CVE-2014-4322_get_root_privilege" target="_blank" rel="noreferrer"&gt;koozxcv/CVE-2014-7911-CVE-2014-4322_get_root_privilege&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/mabin004/cve-2014-7911" target="_blank" rel="noreferrer"&gt;mabin004/cve-2014-7911&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CytQ/CVE-2014-7911_poc" target="_blank" rel="noreferrer"&gt;CytQ/CVE-2014-7911_poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-7920
 &lt;div id="cve-2014-7920" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-7920" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/laginimaineb/cve-2014-7920-7921" target="_blank" rel="noreferrer"&gt;laginimaineb/cve-2014-7920-7921&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Vinc3nt4H/cve-2014-7920-7921_update" target="_blank" rel="noreferrer"&gt;Vinc3nt4H/cve-2014-7920-7921_update&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8110
 &lt;div id="cve-2014-8110" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8110" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2014-8110" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2014-8110&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8142
 &lt;div id="cve-2014-8142" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8142" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/3xp10it/php_cve-2014-8142_cve-2015-0231" target="_blank" rel="noreferrer"&gt;3xp10it/php_cve-2014-8142_cve-2015-0231&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8244
 &lt;div id="cve-2014-8244" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8244" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/JollyJumbuckk/LinksysLeaks" target="_blank" rel="noreferrer"&gt;JollyJumbuckk/LinksysLeaks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8609
 &lt;div id="cve-2014-8609" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8609" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/locisvv/Vulnerable-CVE-2014-8609" target="_blank" rel="noreferrer"&gt;locisvv/Vulnerable-CVE-2014-8609&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8682
 &lt;div id="cve-2014-8682" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8682" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nihal1306/gogs" target="_blank" rel="noreferrer"&gt;nihal1306/gogs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8729
 &lt;div id="cve-2014-8729" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8729" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/inso-/TORQUE-Resource-Manager-2.5.x-2.5.13-stack-based-buffer-overflow-exploit-CVE-2014-8729-CVE-2014-878" target="_blank" rel="noreferrer"&gt;inso-/TORQUE-Resource-Manager-2.5.x-2.5.13-stack-based-buffer-overflow-exploit-CVE-2014-8729-CVE-2014-878&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-8757
 &lt;div id="cve-2014-8757" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-8757" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/irsl/lgosp-poc" target="_blank" rel="noreferrer"&gt;irsl/lgosp-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9016
 &lt;div id="cve-2014-9016" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9016" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c0r3dump3d/wp_drupal_timing_attack" target="_blank" rel="noreferrer"&gt;c0r3dump3d/wp_drupal_timing_attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Primus27/WordPress-Long-Password-Denial-of-Service" target="_blank" rel="noreferrer"&gt;Primus27/WordPress-Long-Password-Denial-of-Service&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9222
 &lt;div id="cve-2014-9222" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9222" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the &amp;quot;Misfortune Cookie&amp;quot; vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BenChaliah/MIPS-CVE-2014-9222" target="_blank" rel="noreferrer"&gt;BenChaliah/MIPS-CVE-2014-9222&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9295
 &lt;div id="cve-2014-9295" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9295" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MacMiniVault/NTPUpdateSnowLeopard" target="_blank" rel="noreferrer"&gt;MacMiniVault/NTPUpdateSnowLeopard&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9301
 &lt;div id="cve-2014-9301" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9301" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in the endpoint parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ottimo/burp-alfresco-referer-proxy-cve-2014-9301" target="_blank" rel="noreferrer"&gt;ottimo/burp-alfresco-referer-proxy-cve-2014-9301&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9322
 &lt;div id="cve-2014-9322" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9322" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RKX1209/CVE-2014-9322" target="_blank" rel="noreferrer"&gt;RKX1209/CVE-2014-9322&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9390
 &lt;div id="cve-2014-9390" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9390" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine; libgit2; Egit; and JGit allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mmetince/CVE-2014-9390" target="_blank" rel="noreferrer"&gt;mmetince/CVE-2014-9390&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hakatashi/CVE-2014-9390" target="_blank" rel="noreferrer"&gt;hakatashi/CVE-2014-9390&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2014-9707
 &lt;div id="cve-2014-9707" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2014-9707" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zhw-01/cve-2014-9707" target="_blank" rel="noreferrer"&gt;zhw-01/cve-2014-9707&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2013
 &lt;div id="2013" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2013" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2013-0156
 &lt;div id="cve-2013-0156" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-0156" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/terracatta/name_reverser" target="_blank" rel="noreferrer"&gt;terracatta/name_reverser&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/heroku/heroku-CVE-2013-0156" target="_blank" rel="noreferrer"&gt;heroku/heroku-CVE-2013-0156&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/josal/crack-0.1.8-fixed" target="_blank" rel="noreferrer"&gt;josal/crack-0.1.8-fixed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bsodmike/rails-exploit-cve-2013-0156" target="_blank" rel="noreferrer"&gt;bsodmike/rails-exploit-cve-2013-0156&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/R3dKn33/CVE-2013-0156" target="_blank" rel="noreferrer"&gt;R3dKn33/CVE-2013-0156&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-0229
 &lt;div id="cve-2013-0229" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-0229" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lochiiconnectivity/vulnupnp" target="_blank" rel="noreferrer"&gt;lochiiconnectivity/vulnupnp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-0269
 &lt;div id="cve-2013-0269" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-0269" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;quot;Unsafe Object Creation Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/heroku/heroku-CVE-2013-0269" target="_blank" rel="noreferrer"&gt;heroku/heroku-CVE-2013-0269&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-0333
 &lt;div id="cve-2013-0333" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-0333" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/heroku/heroku-CVE-2013-0333" target="_blank" rel="noreferrer"&gt;heroku/heroku-CVE-2013-0333&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1081
 &lt;div id="cve-2013-1081" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1081" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/steponequit/CVE-2013-1081" target="_blank" rel="noreferrer"&gt;steponequit/CVE-2013-1081&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1300
 &lt;div id="cve-2013-1300" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1300" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka &amp;quot;Win32k Memory Allocation Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Meatballs1/cve-2013-1300" target="_blank" rel="noreferrer"&gt;Meatballs1/cve-2013-1300&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1488
 &lt;div id="cve-2013-1488" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1488" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, &amp;quot;improper toString calls,&amp;quot; and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/v-p-b/buherablog-cve-2013-1488" target="_blank" rel="noreferrer"&gt;v-p-b/buherablog-cve-2013-1488&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1491
 &lt;div id="cve-2013-1491" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1491" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related to 2D, as demonstrated by Joshua Drake during a Pwn2Own competition at CanSecWest 2013.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guhe120/CVE20131491-JIT" target="_blank" rel="noreferrer"&gt;guhe120/CVE20131491-JIT&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1690
 &lt;div id="cve-2013-1690" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1690" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vlad902/annotated-fbi-tbb-exploit" target="_blank" rel="noreferrer"&gt;vlad902/annotated-fbi-tbb-exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1775
 &lt;div id="cve-2013-1775" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1775" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bekhzod0725/perl-CVE-2013-1775" target="_blank" rel="noreferrer"&gt;bekhzod0725/perl-CVE-2013-1775&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-1965
 &lt;div id="cve-2013-1965" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-1965" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cinno/CVE-2013-1965" target="_blank" rel="noreferrer"&gt;cinno/CVE-2013-1965&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2028
 &lt;div id="cve-2013-2028" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2028" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/danghvu/nginx-1.4.0" target="_blank" rel="noreferrer"&gt;danghvu/nginx-1.4.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kitctf/nginxpwn" target="_blank" rel="noreferrer"&gt;kitctf/nginxpwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC" target="_blank" rel="noreferrer"&gt;tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2072
 &lt;div id="cve-2013-2072" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2072" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bl4ck5un/cve-2013-2072" target="_blank" rel="noreferrer"&gt;bl4ck5un/cve-2013-2072&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2094
 &lt;div id="cve-2013-2094" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2094" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/realtalk/cve-2013-2094" target="_blank" rel="noreferrer"&gt;realtalk/cve-2013-2094&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hiikezoe/libperf_event_exploit" target="_blank" rel="noreferrer"&gt;hiikezoe/libperf_event_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Pashkela/CVE-2013-2094" target="_blank" rel="noreferrer"&gt;Pashkela/CVE-2013-2094&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tarunyadav/fix-cve-2013-2094" target="_blank" rel="noreferrer"&gt;tarunyadav/fix-cve-2013-2094&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/timhsutw/cve-2013-2094" target="_blank" rel="noreferrer"&gt;timhsutw/cve-2013-2094&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vnik5287/CVE-2013-2094" target="_blank" rel="noreferrer"&gt;vnik5287/CVE-2013-2094&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2186
 &lt;div id="cve-2013-2186" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2186" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GrrrDog/ACEDcup" target="_blank" rel="noreferrer"&gt;GrrrDog/ACEDcup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SPlayer1248/Payload_CVE_2013_2186" target="_blank" rel="noreferrer"&gt;SPlayer1248/Payload_CVE_2013_2186&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SPlayer1248/CVE_2013_2186" target="_blank" rel="noreferrer"&gt;SPlayer1248/CVE_2013_2186&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2217
 &lt;div id="cve-2013-2217" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2217" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Osirium/suds" target="_blank" rel="noreferrer"&gt;Osirium/suds&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-225
 &lt;div id="cve-2013-225" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-225" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ninj4c0d3r/ShellEvil" target="_blank" rel="noreferrer"&gt;ninj4c0d3r/ShellEvil&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2595
 &lt;div id="cve-2013-2595" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2595" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which allows attackers to gain privileges via a crafted application.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fi01/libmsm_cameraconfig_exploit" target="_blank" rel="noreferrer"&gt;fi01/libmsm_cameraconfig_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2596
 &lt;div id="cve-2013-2596" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2596" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hiikezoe/libfb_mem_exploit" target="_blank" rel="noreferrer"&gt;hiikezoe/libfb_mem_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2597
 &lt;div id="cve-2013-2597" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2597" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fi01/libmsm_acdb_exploit" target="_blank" rel="noreferrer"&gt;fi01/libmsm_acdb_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2729
 &lt;div id="cve-2013-2729" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2729" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/feliam/CVE-2013-2729" target="_blank" rel="noreferrer"&gt;feliam/CVE-2013-2729&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2730
 &lt;div id="cve-2013-2730" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2730" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/feliam/CVE-2013-2730" target="_blank" rel="noreferrer"&gt;feliam/CVE-2013-2730&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2842
 &lt;div id="cve-2013-2842" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2842" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/173210/spider" target="_blank" rel="noreferrer"&gt;173210/spider&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-2977
 &lt;div id="cve-2013-2977" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-2977" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1 on Linux, allows remote attackers to execute arbitrary code via a malformed PNG image in a previewed e-mail message, aka SPR NPEI96K82Q.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lagartojuancho/CVE-2013-2977" target="_blank" rel="noreferrer"&gt;lagartojuancho/CVE-2013-2977&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-3319
 &lt;div id="cve-2013-3319" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-3319" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/integrity-sa/cve-2013-3319" target="_blank" rel="noreferrer"&gt;integrity-sa/cve-2013-3319&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-3651
 &lt;div id="cve-2013-3651" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-3651" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/motikan2010/CVE-2013-3651" target="_blank" rel="noreferrer"&gt;motikan2010/CVE-2013-3651&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-3664
 &lt;div id="cve-2013-3664" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-3664" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lagartojuancho/CVE-2013-3664_MAC" target="_blank" rel="noreferrer"&gt;lagartojuancho/CVE-2013-3664_MAC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lagartojuancho/CVE-2013-3664_BMP" target="_blank" rel="noreferrer"&gt;lagartojuancho/CVE-2013-3664_BMP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-4002
 &lt;div id="cve-2013-4002" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-4002" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2013-4002" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2013-4002&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-4175
 &lt;div id="cve-2013-4175" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-4175" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
MySecureShell 1.31 has a Local Denial of Service Vulnerability
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hartwork/mysecureshell-issues" target="_blank" rel="noreferrer"&gt;hartwork/mysecureshell-issues&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-4348
 &lt;div id="cve-2013-4348" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-4348" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bl4ck5un/cve-2013-4348" target="_blank" rel="noreferrer"&gt;bl4ck5un/cve-2013-4348&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-4378
 &lt;div id="cve-2013-4378" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-4378" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/theratpack/grails-javamelody-sample-app" target="_blank" rel="noreferrer"&gt;theratpack/grails-javamelody-sample-app&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-4434
 &lt;div id="cve-2013-4434" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-4434" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/styx00/Dropbear_CVE-2013-4434" target="_blank" rel="noreferrer"&gt;styx00/Dropbear_CVE-2013-4434&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-4784
 &lt;div id="cve-2013-4784" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-4784" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alexoslabs/ipmitest" target="_blank" rel="noreferrer"&gt;alexoslabs/ipmitest&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-5065
 &lt;div id="cve-2013-5065" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-5065" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Friarfukd/RobbinHood" target="_blank" rel="noreferrer"&gt;Friarfukd/RobbinHood&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-5211
 &lt;div id="cve-2013-5211" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-5211" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dani87/ntpscanner" target="_blank" rel="noreferrer"&gt;dani87/ntpscanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/suedadam/ntpscanner" target="_blank" rel="noreferrer"&gt;suedadam/ntpscanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sepehrdaddev/ntpdos" target="_blank" rel="noreferrer"&gt;sepehrdaddev/ntpdos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-5664
 &lt;div id="cve-2013-5664" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-5664" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/phusion/rails-cve-2012-5664-test" target="_blank" rel="noreferrer"&gt;phusion/rails-cve-2012-5664-test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-5842
 &lt;div id="cve-2013-5842" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-5842" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5850.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/guhe120/CVE-2013-5842" target="_blank" rel="noreferrer"&gt;guhe120/CVE-2013-5842&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-6117
 &lt;div id="cve-2013-6117" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-6117" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/milo2012/CVE-2013-6117" target="_blank" rel="noreferrer"&gt;milo2012/CVE-2013-6117&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-6282
 &lt;div id="cve-2013-6282" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-6282" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fi01/libput_user_exploit" target="_blank" rel="noreferrer"&gt;fi01/libput_user_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fi01/libget_user_exploit" target="_blank" rel="noreferrer"&gt;fi01/libget_user_exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jeboo/bypasslkm" target="_blank" rel="noreferrer"&gt;jeboo/bypasslkm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/timwr/CVE-2013-6282" target="_blank" rel="noreferrer"&gt;timwr/CVE-2013-6282&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-6375
 &lt;div id="cve-2013-6375" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-6375" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an &amp;quot;inverted boolean parameter.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bl4ck5un/cve-2013-6375" target="_blank" rel="noreferrer"&gt;bl4ck5un/cve-2013-6375&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-6668
 &lt;div id="cve-2013-6668" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-6668" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sdneon/CveTest" target="_blank" rel="noreferrer"&gt;sdneon/CveTest&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2013-6987
 &lt;div id="cve-2013-6987" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2013-6987" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Sciota/CVE-2013-6987" target="_blank" rel="noreferrer"&gt;Sciota/CVE-2013-6987&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2012
 &lt;div id="2012" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2012" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2012-0003
 &lt;div id="cve-2012-0003" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-0003" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka &amp;quot;MIDI Remote Code Execution Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/k0keoyo/CVE-2012-0003_eXP" target="_blank" rel="noreferrer"&gt;k0keoyo/CVE-2012-0003_eXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-0056
 &lt;div id="cve-2012-0056" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-0056" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/&amp;lt;pid&amp;gt;/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/srclib/CVE-2012-0056" target="_blank" rel="noreferrer"&gt;srclib/CVE-2012-0056&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pythonone/CVE-2012-0056" target="_blank" rel="noreferrer"&gt;pythonone/CVE-2012-0056&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-0152
 &lt;div id="cve-2012-0152" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-0152" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka &amp;quot;Terminal Server Denial of Service Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rutvijjethwa/RDP_jammer" target="_blank" rel="noreferrer"&gt;rutvijjethwa/RDP_jammer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-1675
 &lt;div id="cve-2012-1675" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-1675" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka &amp;quot;TNS Poison.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bongbongco/CVE-2012-1675" target="_blank" rel="noreferrer"&gt;bongbongco/CVE-2012-1675&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-1723
 &lt;div id="cve-2012-1723" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-1723" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/EthanNJC/CVE-2012-1723" target="_blank" rel="noreferrer"&gt;EthanNJC/CVE-2012-1723&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-1823
 &lt;div id="cve-2012-1823" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-1823" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/drone789/CVE-2012-1823" target="_blank" rel="noreferrer"&gt;drone789/CVE-2012-1823&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gamamaru6005/oscp_scripts-1" target="_blank" rel="noreferrer"&gt;gamamaru6005/oscp_scripts-1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/noondi/metasploitable2" target="_blank" rel="noreferrer"&gt;noondi/metasploitable2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-1876
 &lt;div id="cve-2012-1876" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-1876" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka &amp;quot;Col Element Remote Code Execution Vulnerability,&amp;quot; as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/WizardVan/CVE-2012-1876" target="_blank" rel="noreferrer"&gt;WizardVan/CVE-2012-1876&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-1889
 &lt;div id="cve-2012-1889" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-1889" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whu-enjoy/CVE-2012-1889" target="_blank" rel="noreferrer"&gt;whu-enjoy/CVE-2012-1889&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/l-iberty/cve-2012-1889" target="_blank" rel="noreferrer"&gt;l-iberty/cve-2012-1889&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-2122
 &lt;div id="cve-2012-2122" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-2122" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Avinza/CVE-2012-2122-scanner" target="_blank" rel="noreferrer"&gt;Avinza/CVE-2012-2122-scanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-2688
 &lt;div id="cve-2012-2688" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-2688" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an &amp;quot;overflow.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shelld3v/CVE-2012-2688" target="_blank" rel="noreferrer"&gt;shelld3v/CVE-2012-2688&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-3137
 &lt;div id="cve-2012-3137" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-3137" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka &amp;quot;stealth password cracking vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hantwister/o5logon-fetch" target="_blank" rel="noreferrer"&gt;hantwister/o5logon-fetch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/r1-/cve-2012-3137" target="_blank" rel="noreferrer"&gt;r1-/cve-2012-3137&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-3153
 &lt;div id="cve-2012-3153" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-3153" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Mekanismen/pwnacle-fusion" target="_blank" rel="noreferrer"&gt;Mekanismen/pwnacle-fusion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-3716
 &lt;div id="cve-2012-3716" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-3716" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/d4rkcat/killosx" target="_blank" rel="noreferrer"&gt;d4rkcat/killosx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-4220
 &lt;div id="cve-2012-4220" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-4220" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments in a local diagchar_ioctl call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hiikezoe/diaggetroot" target="_blank" rel="noreferrer"&gt;hiikezoe/diaggetroot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/poliva/root-zte-open" target="_blank" rel="noreferrer"&gt;poliva/root-zte-open&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-4431
 &lt;div id="cve-2012-4431" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-4431" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Michael-Main/CVE-2012-4431" target="_blank" rel="noreferrer"&gt;Michael-Main/CVE-2012-4431&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-4681
 &lt;div id="cve-2012-4681" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-4681" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using &amp;quot;reflection with a trusted immediate caller&amp;quot; to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/benjholla/CVE-2012-4681-Armoring" target="_blank" rel="noreferrer"&gt;benjholla/CVE-2012-4681-Armoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ZH3FENG/PoCs-CVE_2012_4681" target="_blank" rel="noreferrer"&gt;ZH3FENG/PoCs-CVE_2012_4681&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-4792
 &lt;div id="cve-2012-4792" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-4792" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/WizardVan/CVE-2012-4792" target="_blank" rel="noreferrer"&gt;WizardVan/CVE-2012-4792&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-4929
 &lt;div id="cve-2012-4929" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-4929" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a &amp;quot;CRIME&amp;quot; attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/CRIME-poc" target="_blank" rel="noreferrer"&gt;mpgn/CRIME-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-5106
 &lt;div id="cve-2012-5106" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-5106" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2012-5106" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2012-5106&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-5575
 &lt;div id="cve-2012-5575" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-5575" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka &amp;quot;XML Encryption backwards compatibility attack.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tafamace/CVE-2012-5575" target="_blank" rel="noreferrer"&gt;tafamace/CVE-2012-5575&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-5613
 &lt;div id="cve-2012-5613" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-5613" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Hood3dRob1n/MySQL-Fu.rb" target="_blank" rel="noreferrer"&gt;Hood3dRob1n/MySQL-Fu.rb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/w4fz5uck5/UDFPwn-CVE-2012-5613" target="_blank" rel="noreferrer"&gt;w4fz5uck5/UDFPwn-CVE-2012-5613&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-5664
 &lt;div id="cve-2012-5664" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-5664" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/phusion/rails-cve-2012-5664-test" target="_blank" rel="noreferrer"&gt;phusion/rails-cve-2012-5664-test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-5958
 &lt;div id="cve-2012-5958" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-5958" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/lochiiconnectivity/vulnupnp" target="_blank" rel="noreferrer"&gt;lochiiconnectivity/vulnupnp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-5960
 &lt;div id="cve-2012-5960" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-5960" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a long UDN (aka upnp:rootdevice) field in a UDP packet.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/finn79426/CVE-2012-5960-PoC" target="_blank" rel="noreferrer"&gt;finn79426/CVE-2012-5960-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-6066
 &lt;div id="cve-2012-6066" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-6066" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bongbongco/CVE-2012-6066" target="_blank" rel="noreferrer"&gt;bongbongco/CVE-2012-6066&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2012-6636
 &lt;div id="cve-2012-6636" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2012-6636" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xckevin/AndroidWebviewInjectDemo" target="_blank" rel="noreferrer"&gt;xckevin/AndroidWebviewInjectDemo&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2011
 &lt;div id="2011" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2011" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2011-0228
 &lt;div id="cve-2011-0228" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-0228" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jan0/isslfix" target="_blank" rel="noreferrer"&gt;jan0/isslfix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1237
 &lt;div id="cve-2011-1237" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1237" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other &amp;quot;Vulnerability Type 1&amp;quot; CVEs listed in MS11-034, aka &amp;quot;Win32k Use After Free Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BrunoPujos/CVE-2011-1237" target="_blank" rel="noreferrer"&gt;BrunoPujos/CVE-2011-1237&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1473
 &lt;div id="cve-2011-1473" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1473" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
** DISPUTED ** OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/c826/bash-tls-reneg-attack" target="_blank" rel="noreferrer"&gt;c826/bash-tls-reneg-attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zjt674449039/cve-2011-1473" target="_blank" rel="noreferrer"&gt;zjt674449039/cve-2011-1473&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1475
 &lt;div id="cve-2011-1475" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1475" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to &amp;quot;a mix-up of responses for requests from different users.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/samaujs/CVE-2011-1475" target="_blank" rel="noreferrer"&gt;samaujs/CVE-2011-1475&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1485
 &lt;div id="cve-2011-1485" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1485" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Pashkela/CVE-2011-1485" target="_blank" rel="noreferrer"&gt;Pashkela/CVE-2011-1485&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1571
 &lt;div id="cve-2011-1571" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1571" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/noobpk/CVE-2011-1571" target="_blank" rel="noreferrer"&gt;noobpk/CVE-2011-1571&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1575
 &lt;div id="cve-2011-1575" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1575" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a &amp;quot;plaintext command injection&amp;quot; attack, a similar issue to CVE-2011-0411.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/masamoon/cve-2011-1575-poc" target="_blank" rel="noreferrer"&gt;masamoon/cve-2011-1575-poc&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1720
 &lt;div id="cve-2011-1720" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1720" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nbeguier/postfix_exploit" target="_blank" rel="noreferrer"&gt;nbeguier/postfix_exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-1974
 &lt;div id="cve-2011-1974" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-1974" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka &amp;quot;NDISTAPI Elevation of Privilege Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hittlle/CVE-2011-1974-PoC" target="_blank" rel="noreferrer"&gt;hittlle/CVE-2011-1974-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-2461
 &lt;div id="cve-2011-2461" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-2461" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in the Adobe Flex SDK 3.x and 4.x before 4.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the loading of modules from different domains.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ikkisoft/ParrotNG" target="_blank" rel="noreferrer"&gt;ikkisoft/ParrotNG&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/u-maxx/magento-swf-patched-CVE-2011-2461" target="_blank" rel="noreferrer"&gt;u-maxx/magento-swf-patched-CVE-2011-2461&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/edmondscommerce/CVE-2011-2461_Magento_Patch" target="_blank" rel="noreferrer"&gt;edmondscommerce/CVE-2011-2461_Magento_Patch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-2894
 &lt;div id="cve-2011-2894" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-2894" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/pwntester/SpringBreaker" target="_blank" rel="noreferrer"&gt;pwntester/SpringBreaker&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-3026
 &lt;div id="cve-2011-3026" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-3026" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/argp/cve-2011-3026-firefox" target="_blank" rel="noreferrer"&gt;argp/cve-2011-3026-firefox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-3192
 &lt;div id="cve-2011-3192" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-3192" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tkisason/KillApachePy" target="_blank" rel="noreferrer"&gt;tkisason/KillApachePy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/limkokhole/CVE-2011-3192" target="_blank" rel="noreferrer"&gt;limkokhole/CVE-2011-3192&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/stcmjp/cve-2011-3192" target="_blank" rel="noreferrer"&gt;stcmjp/cve-2011-3192&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-3368
 &lt;div id="cve-2011-3368" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-3368" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2011-3368" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2011-3368&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/colorblindpentester/CVE-2011-3368" target="_blank" rel="noreferrer"&gt;colorblindpentester/CVE-2011-3368&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-3389
 &lt;div id="cve-2011-3389" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-3389" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a &amp;quot;BEAST&amp;quot; attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mpgn/BEAST-PoC" target="_blank" rel="noreferrer"&gt;mpgn/BEAST-PoC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-3556
 &lt;div id="cve-2011-3556" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-3556" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sk4la/cve_2011_3556" target="_blank" rel="noreferrer"&gt;sk4la/cve_2011_3556&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-3872
 &lt;div id="cve-2011-3872" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-3872" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka &amp;quot;AltNames Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/puppetlabs/puppetlabs-cve20113872" target="_blank" rel="noreferrer"&gt;puppetlabs/puppetlabs-cve20113872&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-4107
 &lt;div id="cve-2011-4107" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-4107" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2011-4107" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2011-4107&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-4862
 &lt;div id="cve-2011-4862" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-4862" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hdbreaker/GO-CVE-2011-4862" target="_blank" rel="noreferrer"&gt;hdbreaker/GO-CVE-2011-4862&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lol-fi/cve-2011-4862" target="_blank" rel="noreferrer"&gt;lol-fi/cve-2011-4862&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kpawar2410/CVE-2011-4862" target="_blank" rel="noreferrer"&gt;kpawar2410/CVE-2011-4862&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-4872
 &lt;div id="cve-2011-4872" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-4872" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Chiggins/CVE-2011-4872" target="_blank" rel="noreferrer"&gt;Chiggins/CVE-2011-4872&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-4905
 &lt;div id="cve-2011-4905" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-4905" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Michael-Main/CVE-2011-4905" target="_blank" rel="noreferrer"&gt;Michael-Main/CVE-2011-4905&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2011-4919
 &lt;div id="cve-2011-4919" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2011-4919" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hartwork/mpacktrafficripper" target="_blank" rel="noreferrer"&gt;hartwork/mpacktrafficripper&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2010
 &lt;div id="2010" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2010" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2010-0426
 &lt;div id="cve-2010-0426" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-0426" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/t0kx/privesc-CVE-2010-0426" target="_blank" rel="noreferrer"&gt;t0kx/privesc-CVE-2010-0426&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cved-sources/cve-2010-0426" target="_blank" rel="noreferrer"&gt;cved-sources/cve-2010-0426&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-0738
 &lt;div id="cve-2010-0738" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-0738" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ChristianPapathanasiou/jboss-autopwn" target="_blank" rel="noreferrer"&gt;ChristianPapathanasiou/jboss-autopwn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/gitcollect/jboss-autopwn" target="_blank" rel="noreferrer"&gt;gitcollect/jboss-autopwn&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-1205
 &lt;div id="cve-2010-1205" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-1205" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mk219533/CVE-2010-1205" target="_blank" rel="noreferrer"&gt;mk219533/CVE-2010-1205&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-1411
 &lt;div id="cve-2010-1411" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-1411" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/MAVProxyUser/httpfuzz-robomiller" target="_blank" rel="noreferrer"&gt;MAVProxyUser/httpfuzz-robomiller&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-2075
 &lt;div id="cve-2010-2075" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-2075" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/M4LV0/UnrealIRCd-3.2.8.1-RCE" target="_blank" rel="noreferrer"&gt;M4LV0/UnrealIRCd-3.2.8.1-RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3332
 &lt;div id="cve-2010-3332" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3332" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka &amp;quot;ASP.NET Padding Oracle Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bongbongco/MS10-070" target="_blank" rel="noreferrer"&gt;bongbongco/MS10-070&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3333
 &lt;div id="cve-2010-3333" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3333" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka &amp;quot;RTF Stack Buffer Overflow Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whiteHat001/cve-2010-3333" target="_blank" rel="noreferrer"&gt;whiteHat001/cve-2010-3333&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3437
 &lt;div id="cve-2010-3437" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3437" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/huang-emily/CVE-2010-3437" target="_blank" rel="noreferrer"&gt;huang-emily/CVE-2010-3437&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3490
 &lt;div id="cve-2010-3490" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3490" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/moayadalmalat/CVE-2010-3490" target="_blank" rel="noreferrer"&gt;moayadalmalat/CVE-2010-3490&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3600
 &lt;div id="cve-2010-3600" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3600" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue involves an exposed JSP script that accepts XML uploads in conjunction with NULL bytes in an unspecified parameter that allow execution of arbitrary code.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/LAITRUNGMINHDUC/CVE-2010-3600-PythonHackOracle11gR2" target="_blank" rel="noreferrer"&gt;LAITRUNGMINHDUC/CVE-2010-3600-PythonHackOracle11gR2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3847
 &lt;div id="cve-2010-3847" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3847" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/magisterquis/cve-2010-3847" target="_blank" rel="noreferrer"&gt;magisterquis/cve-2010-3847&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3904
 &lt;div id="cve-2010-3904" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3904" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/redhatkaty/-cve-2010-3904-report" target="_blank" rel="noreferrer"&gt;redhatkaty/-cve-2010-3904-report&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-3971
 &lt;div id="cve-2010-3971" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-3971" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka &amp;quot;CSS Memory Corruption Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nektra/CVE-2010-3971-hotpatch" target="_blank" rel="noreferrer"&gt;nektra/CVE-2010-3971-hotpatch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-4221
 &lt;div id="cve-2010-4221" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-4221" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/M31MOTH/cve-2010-4221" target="_blank" rel="noreferrer"&gt;M31MOTH/cve-2010-4221&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-4258
 &lt;div id="cve-2010-4258" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-4258" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/johnreginald/CVE-2010-4258" target="_blank" rel="noreferrer"&gt;johnreginald/CVE-2010-4258&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-4476
 &lt;div id="cve-2010-4476" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-4476" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/grzegorzblaszczyk/CVE-2010-4476-check" target="_blank" rel="noreferrer"&gt;grzegorzblaszczyk/CVE-2010-4476-check&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-4669
 &lt;div id="cve-2010-4669" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-4669" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/quinn-samuel-perry/CVE-2010-4669" target="_blank" rel="noreferrer"&gt;quinn-samuel-perry/CVE-2010-4669&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-4804
 &lt;div id="cve-2010-4804" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-4804" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/thomascannon/android-cve-2010-4804" target="_blank" rel="noreferrer"&gt;thomascannon/android-cve-2010-4804&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2010-5327
 &lt;div id="cve-2010-5327" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2010-5327" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Michael-Main/CVE-2010-5327" target="_blank" rel="noreferrer"&gt;Michael-Main/CVE-2010-5327&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2009
 &lt;div id="2009" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2009" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2009-0473
 &lt;div id="cve-2009-0473" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-0473" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/akbarq/CVE-2009-0473" target="_blank" rel="noreferrer"&gt;akbarq/CVE-2009-0473&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-0689
 &lt;div id="cve-2009-0689" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-0689" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Fullmetal5/str2hax" target="_blank" rel="noreferrer"&gt;Fullmetal5/str2hax&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-1151
 &lt;div id="cve-2009-1151" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-1151" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/minervais/pocs" target="_blank" rel="noreferrer"&gt;minervais/pocs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-1244
 &lt;div id="cve-2009-1244" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-1244" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/piotrbania/vmware_exploit_pack_CVE-2009-1244" target="_blank" rel="noreferrer"&gt;piotrbania/vmware_exploit_pack_CVE-2009-1244&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-1324
 &lt;div id="cve-2009-1324" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-1324" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2009-1324" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2009-1324&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-1330
 &lt;div id="cve-2009-1330" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-1330" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/adenkiewicz/CVE-2009-1330" target="_blank" rel="noreferrer"&gt;adenkiewicz/CVE-2009-1330&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2009-1330" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2009-1330&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/exploitwritter/CVE-2009-1330_EasyRMToMp3Converter" target="_blank" rel="noreferrer"&gt;exploitwritter/CVE-2009-1330_EasyRMToMp3Converter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-1437
 &lt;div id="cve-2009-1437" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-1437" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/HanseSecure/CVE-2009-1437" target="_blank" rel="noreferrer"&gt;HanseSecure/CVE-2009-1437&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-1904
 &lt;div id="cve-2009-1904" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-1904" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/NZKoz/bigdecimal-segfault-fix" target="_blank" rel="noreferrer"&gt;NZKoz/bigdecimal-segfault-fix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-2692
 &lt;div id="cve-2009-2692" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-2692" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jdvalentini/CVE-2009-2692" target="_blank" rel="noreferrer"&gt;jdvalentini/CVE-2009-2692&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-2698
 &lt;div id="cve-2009-2698" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-2698" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xiaoxiaoleo/CVE-2009-2698" target="_blank" rel="noreferrer"&gt;xiaoxiaoleo/CVE-2009-2698&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-3103
 &lt;div id="cve-2009-3103" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-3103" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an &amp;amp; (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka &amp;quot;SMBv2 Negotiation Vulnerability.&amp;quot; NOTE: some of these details are obtained from third party information.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mazding/ms09050" target="_blank" rel="noreferrer"&gt;mazding/ms09050&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-4092
 &lt;div id="cve-2009-4092" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-4092" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and users for requests that change passwords.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/xiaoyu-iid/Simplog-Exploit" target="_blank" rel="noreferrer"&gt;xiaoyu-iid/Simplog-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-4118
 &lt;div id="cve-2009-4118" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-4118" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2009-4118" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2009-4118&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-4137
 &lt;div id="cve-2009-4137" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-4137" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserialize function, which allows remote attackers to execute arbitrary code or upload arbitrary files via vectors related to the __destruct function in the Piwik_Config class; php://filter URIs; the __destruct functions in Zend Framework, as demonstrated by the Zend_Log destructor; the shutdown functions in Zend Framework, as demonstrated by the Zend_Log_Writer_Mail class; the render function in the Piwik_View class; Smarty templates; and the _eval function in Smarty.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Alexeyan/CVE-2009-4137" target="_blank" rel="noreferrer"&gt;Alexeyan/CVE-2009-4137&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-4660
 &lt;div id="cve-2009-4660" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-4660" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2009-4660" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2009-4660&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2009-5147
 &lt;div id="cve-2009-5147" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2009-5147" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/vpereira/CVE-2009-5147" target="_blank" rel="noreferrer"&gt;vpereira/CVE-2009-5147&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/zhangyongbo100/-Ruby-dl-handle.c-CVE-2009-5147-" target="_blank" rel="noreferrer"&gt;zhangyongbo100/-Ruby-dl-handle.c-CVE-2009-5147-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2008
 &lt;div id="2008" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2008" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2008-0128
 &lt;div id="cve-2008-0128" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-0128" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ngyanch/4062-1" target="_blank" rel="noreferrer"&gt;ngyanch/4062-1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-0166
 &lt;div id="cve-2008-0166" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-0166" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/g0tmi1k/debian-ssh" target="_blank" rel="noreferrer"&gt;g0tmi1k/debian-ssh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/avarx/vulnkeys" target="_blank" rel="noreferrer"&gt;avarx/vulnkeys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nu11secur1ty/debian-ssh" target="_blank" rel="noreferrer"&gt;nu11secur1ty/debian-ssh&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-0228
 &lt;div id="cve-2008-0228" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-0228" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SpiderLabs/TWSL2011-007_iOS_code_workaround" target="_blank" rel="noreferrer"&gt;SpiderLabs/TWSL2011-007_iOS_code_workaround&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-1611
 &lt;div id="cve-2008-1611" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-1611" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Axua/CVE-2008-1611" target="_blank" rel="noreferrer"&gt;Axua/CVE-2008-1611&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-1613
 &lt;div id="cve-2008-1613" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-1613" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2008-1613" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2008-1613&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-2938
 &lt;div id="cve-2008-2938" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-2938" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Naramsim/Offensive" target="_blank" rel="noreferrer"&gt;Naramsim/Offensive&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-4250
 &lt;div id="cve-2008-4250" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-4250" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka &amp;quot;Server Service Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/thunderstrike9090/Conflicker_analysis_scripts" target="_blank" rel="noreferrer"&gt;thunderstrike9090/Conflicker_analysis_scripts&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-4609
 &lt;div id="cve-2008-4609" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-4609" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/marcelki/sockstress" target="_blank" rel="noreferrer"&gt;marcelki/sockstress&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-4654
 &lt;div id="cve-2008-4654" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-4654" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bongbongco/CVE-2008-4654" target="_blank" rel="noreferrer"&gt;bongbongco/CVE-2008-4654&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/KernelErr/VLC-CVE-2008-4654-Exploit" target="_blank" rel="noreferrer"&gt;KernelErr/VLC-CVE-2008-4654-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-5416
 &lt;div id="cve-2008-5416" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-5416" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and Windows Internal Database (WYukon) SP2 allows remote authenticated users to cause a denial of service (access violation exception) or execute arbitrary code by calling the sp_replwritetovarbin extended stored procedure with a set of invalid parameters that trigger memory overwrite, aka &amp;quot;SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/SECFORCE/CVE-2008-5416" target="_blank" rel="noreferrer"&gt;SECFORCE/CVE-2008-5416&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-6827
 &lt;div id="cve-2008-6827" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-6827" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a &amp;quot;Shatter&amp;quot; style attack on the &amp;quot;command prompt&amp;quot; hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2008-6827" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2008-6827&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-6970
 &lt;div id="cve-2008-6970" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-6970" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/KyomaHooin/CVE-2008-6970" target="_blank" rel="noreferrer"&gt;KyomaHooin/CVE-2008-6970&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2008-7220
 &lt;div id="cve-2008-7220" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2008-7220" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make &amp;quot;cross-site ajax requests&amp;quot; via unknown vectors.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/followboy1999/CVE-2008-7220" target="_blank" rel="noreferrer"&gt;followboy1999/CVE-2008-7220&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2007
 &lt;div id="2007" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2007" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2007-0038
 &lt;div id="cve-2007-0038" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-0038" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Axua/CVE-2007-0038" target="_blank" rel="noreferrer"&gt;Axua/CVE-2007-0038&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-0843
 &lt;div id="cve-2007-0843" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-0843" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/z3APA3A/spydir" target="_blank" rel="noreferrer"&gt;z3APA3A/spydir&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-1567
 &lt;div id="cve-2007-1567" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-1567" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2007-1567" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2007-1567&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-2447
 &lt;div id="cve-2007-2447" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-2447" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the &amp;quot;username map script&amp;quot; smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/noondi/metasploitable2" target="_blank" rel="noreferrer"&gt;noondi/metasploitable2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/amriunix/CVE-2007-2447" target="_blank" rel="noreferrer"&gt;amriunix/CVE-2007-2447&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b1fair/smb_usermap" target="_blank" rel="noreferrer"&gt;b1fair/smb_usermap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Unam3dd/exploit_smb_usermap_script" target="_blank" rel="noreferrer"&gt;Unam3dd/exploit_smb_usermap_script&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/JoseBarrios/CVE-2007-2447" target="_blank" rel="noreferrer"&gt;JoseBarrios/CVE-2007-2447&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/3x1t1um/CVE-2007-2447" target="_blank" rel="noreferrer"&gt;3x1t1um/CVE-2007-2447&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-3830
 &lt;div id="cve-2007-3830" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-3830" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2007-3830" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2007-3830&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-3831
 &lt;div id="cve-2007-3831" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-3831" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2007-3831" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2007-3831&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-4607
 &lt;div id="cve-2007-4607" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-4607" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/joeyrideout/CVE-2007-4607" target="_blank" rel="noreferrer"&gt;joeyrideout/CVE-2007-4607&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-5036
 &lt;div id="cve-2007-5036" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-5036" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the &amp;quot;files filter.&amp;quot;
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2007-5036" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2007-5036&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2007-6638
 &lt;div id="cve-2007-6638" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2007-6638" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2007-6638" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2007-6638&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2006
 &lt;div id="2006" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2006" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2006-1236
 &lt;div id="cve-2006-1236" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2006-1236" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Axua/CVE-2006-1236" target="_blank" rel="noreferrer"&gt;Axua/CVE-2006-1236&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2006-3592
 &lt;div id="cve-2006-3592" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2006-3592" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving &amp;quot;certain CLI commands,&amp;quot; aka bug CSCse11005.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/adenkiewicz/CVE-2006-3592" target="_blank" rel="noreferrer"&gt;adenkiewicz/CVE-2006-3592&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2006-3747
 &lt;div id="cve-2006-3747" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2006-3747" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/spinfoo/CVE-2006-3747" target="_blank" rel="noreferrer"&gt;spinfoo/CVE-2006-3747&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2006-4777
 &lt;div id="cve-2006-4777" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2006-4777" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Mario1234/js-driveby-download-CVE-2006-4777" target="_blank" rel="noreferrer"&gt;Mario1234/js-driveby-download-CVE-2006-4777&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2006-4814
 &lt;div id="cve-2006-4814" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2006-4814" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tagatac/linux-CVE-2006-4814" target="_blank" rel="noreferrer"&gt;tagatac/linux-CVE-2006-4814&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2006-6184
 &lt;div id="cve-2006-6184" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2006-6184" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/shauntdergrigorian/cve-2006-6184" target="_blank" rel="noreferrer"&gt;shauntdergrigorian/cve-2006-6184&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/b03902043/CVE-2006-6184" target="_blank" rel="noreferrer"&gt;b03902043/CVE-2006-6184&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2005
 &lt;div id="2005" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2005" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2005-1125
 &lt;div id="cve-2005-1125" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2005-1125" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/tagatac/libsafe-CVE-2005-1125" target="_blank" rel="noreferrer"&gt;tagatac/libsafe-CVE-2005-1125&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2005-2428
 &lt;div id="cve-2005-2428" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2005-2428" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Lotus Domino R5 and R6 WebMail, with &amp;quot;Generate HTML for all fields&amp;quot; enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/schwankner/CVE-2005-2428-IBM-Lotus-Domino-R8-Password-Hash-Extraction-Exploit" target="_blank" rel="noreferrer"&gt;schwankner/CVE-2005-2428-IBM-Lotus-Domino-R8-Password-Hash-Extraction-Exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2004
 &lt;div id="2004" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2004" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2004-0558
 &lt;div id="cve-2004-0558" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2004-0558" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fibonascii/CVE-2004-0558" target="_blank" rel="noreferrer"&gt;fibonascii/CVE-2004-0558&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2004-1561
 &lt;div id="cve-2004-1561" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2004-1561" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ivanitlearning/CVE-2004-1561" target="_blank" rel="noreferrer"&gt;ivanitlearning/CVE-2004-1561&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2004-1769
 &lt;div id="cve-2004-1769" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2004-1769" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
The &amp;quot;Allow cPanel users to reset their password via email&amp;quot; feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sinkaroid/shiguresh" target="_blank" rel="noreferrer"&gt;sinkaroid/shiguresh&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2004-2167
 &lt;div id="cve-2004-2167" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2004-2167" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) TranslateCommand.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/uzzzval/cve-2004-2167" target="_blank" rel="noreferrer"&gt;uzzzval/cve-2004-2167&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2004-2271
 &lt;div id="cve-2004-2271" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2004-2271" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kkirsche/CVE-2004-2271" target="_blank" rel="noreferrer"&gt;kkirsche/CVE-2004-2271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow" target="_blank" rel="noreferrer"&gt;PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2004-2271" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2004-2271&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwncone/CVE-2004-2271-MiniShare-1.4.1-BOF" target="_blank" rel="noreferrer"&gt;pwncone/CVE-2004-2271-MiniShare-1.4.1-BOF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2004-2549
 &lt;div id="cve-2004-2549" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2004-2549" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and (2) the HTTP service on TCP port 80, possibly due to a buffer overflow.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2004-2549" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2004-2549&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2003
 &lt;div id="2003" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2003" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2003-0222
 &lt;div id="cve-2003-0222" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2003-0222" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a &amp;quot;CREATE DATABASE LINK&amp;quot; query containing a connect string with a long USING parameter.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/phamthanhsang280477/CVE-2003-0222" target="_blank" rel="noreferrer"&gt;phamthanhsang280477/CVE-2003-0222&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2003-0264
 &lt;div id="cve-2003-0264" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2003-0264" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/adenkiewicz/CVE-2003-0264" target="_blank" rel="noreferrer"&gt;adenkiewicz/CVE-2003-0264&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fyoderxx/slmail-exploit" target="_blank" rel="noreferrer"&gt;fyoderxx/slmail-exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/war4uthor/CVE-2003-0264" target="_blank" rel="noreferrer"&gt;war4uthor/CVE-2003-0264&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwncone/CVE-2003-0264-SLmail-5.5" target="_blank" rel="noreferrer"&gt;pwncone/CVE-2003-0264-SLmail-5.5&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2002
 &lt;div id="2002" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2002" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0200
 &lt;div id="cve-2002-0200" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0200" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0200" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0200&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0201
 &lt;div id="cve-2002-0201" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0201" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0201" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0201&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0288
 &lt;div id="cve-2002-0288" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0288" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0288" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0288&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0289
 &lt;div id="cve-2002-0289" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0289" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0289" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0289&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0346
 &lt;div id="cve-2002-0346" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0346" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0346" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0346&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0347
 &lt;div id="cve-2002-0347" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0347" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0347" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0347&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0348
 &lt;div id="cve-2002-0348" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0348" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0348" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0348&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0448
 &lt;div id="cve-2002-0448" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0448" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many &amp;quot;C:/&amp;quot; sequences.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0448" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0448&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0740
 &lt;div id="cve-2002-0740" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0740" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0740" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0740&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2002-0991
 &lt;div id="cve-2002-0991" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2002-0991" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2002-0991" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2002-0991&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2001
 &lt;div id="2001" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2001" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2001-0680
 &lt;div id="cve-2001-0680" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-0680" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a &amp;quot;dot dot&amp;quot; attack in a LIST (ls) command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-0680" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-0680&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2001-0758
 &lt;div id="cve-2001-0758" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-0758" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via &amp;quot;CWD ...&amp;quot; command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-0758" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-0758&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2001-0931
 &lt;div id="cve-2001-0931" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-0931" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-0931" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-0931&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2001-0932
 &lt;div id="cve-2001-0932" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-0932" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-0932" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-0932&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2001-0933
 &lt;div id="cve-2001-0933" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-0933" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. &amp;quot;ls C:&amp;quot;.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-0933" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-0933&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2001-0934
 &lt;div id="cve-2001-0934" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-0934" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-0934" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-0934&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2001-1442
 &lt;div id="cve-2001-1442" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2001-1442" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the &amp;quot;news&amp;quot; group to gain privileges via a long -c command line argument.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/alt3kx/CVE-2001-1442" target="_blank" rel="noreferrer"&gt;alt3kx/CVE-2001-1442&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;2000
 &lt;div id="2000" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2000" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-2000-0170
 &lt;div id="cve-2000-0170" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2000-0170" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mike182/exploit" target="_blank" rel="noreferrer"&gt;mike182/exploit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CVE-2000-0979
 &lt;div id="cve-2000-0979" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-2000-0979" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;code&gt;
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the &amp;quot;Share Level Password&amp;quot; vulnerability.
&lt;/code&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Z6543/CVE-2000-0979" target="_blank" rel="noreferrer"&gt;Z6543/CVE-2000-0979&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;1999
 &lt;div id="1999" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#1999" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;CVE-1999-0532
 &lt;div id="cve-1999-0532" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cve-1999-0532" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/websecnl/Bulk_CVE-1999-0532_Scanner" target="_blank" rel="noreferrer"&gt;websecnl/Bulk_CVE-1999-0532_Scanner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>free-podcasts-screencasts</title><link>https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/</link><pubDate>Wed, 18 Mar 2020 17:09:00 +0000</pubDate><guid>https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/</guid><description>&lt;h3 class="relative group"&gt;Index
 &lt;div id="index" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#index" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#android" &gt;Android&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#golang" &gt;Golang&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#gulp" &gt;Gulp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#haskell" &gt;Haskell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#javascript" &gt;Javascript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#nodejs" &gt;Node.js&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#php" &gt;PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#qa" &gt;QA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#reactjs" &gt;React.js&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#ruby" &gt;Ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#webpack" &gt;Webpack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#%d0%98%d0%bd%d1%84%d0%be%d1%80%d0%bc%d0%b0%d1%86%d0%b8%d0%be%d0%bd%d0%bd%d1%8b%d0%b5-%d1%82%d0%b5%d1%85%d0%bd%d0%be%d0%bb%d0%be%d0%b3%d0%b8%d0%b8-%d0%b8-%d0%b1%d0%b5%d0%b7%d0%be%d0%bf%d0%b0%d1%81%d0%bd%d0%be%d1%81%d1%82%d1%8c" &gt;Информационные технологии и безопасность&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-podcasts-screencasts-ru/#%d0%9d%d0%be%d0%b2%d0%be%d1%81%d1%82%d0%b8-%d0%b8-%d0%a0%d0%b0%d0%b7%d1%80%d0%b0%d0%b1%d0%be%d1%82%d0%ba%d0%b0-%d0%9f%d0%9e" &gt;Новости и Разработка ПО&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Android
 &lt;div id="android" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#android" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://apptractor.ru/AndroidDev" target="_blank" rel="noreferrer"&gt;Android Dev&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Golang
 &lt;div id="golang" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#golang" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://golangshow.com" target="_blank" rel="noreferrer"&gt;GolangShow&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Gulp
 &lt;div id="gulp" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#gulp" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://learn.javascript.ru/screencast/gulp" target="_blank" rel="noreferrer"&gt;Скринкаст по Gulp&lt;/a&gt; - Илья Кантор (Screencast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Haskell
 &lt;div id="haskell" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#haskell" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bananasandlenses.net" target="_blank" rel="noreferrer"&gt;Бананы и Линзы&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Javascript
 &lt;div id="javascript" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#javascript" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://soundcloud.com/devschacht" target="_blank" rel="noreferrer"&gt;Devschacht&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://frontflip.me" target="_blank" rel="noreferrer"&gt;Frontflip&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.magisters.org/education/course/js-for-beginners" target="_blank" rel="noreferrer"&gt;Javascript для начинающих&lt;/a&gt; (Screencast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://radiojs.ru" target="_blank" rel="noreferrer"&gt;RadioJS&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://soundcloud.com/web-standards" target="_blank" rel="noreferrer"&gt;Webstandards&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Node.js
 &lt;div id="nodejs" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#nodejs" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://learn.javascript.ru/screencast/nodejs" target="_blank" rel="noreferrer"&gt;Скринкаст Node.JS&lt;/a&gt; - Илья Кантор (Screencast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;PHP
 &lt;div id="php" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#php" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://5minphp.ru" target="_blank" rel="noreferrer"&gt;Пятиминутка PHP&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;QA
 &lt;div id="qa" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#qa" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://automation-remarks.com/podcast" target="_blank" rel="noreferrer"&gt;QAGuild&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://radio-qa.com" target="_blank" rel="noreferrer"&gt;Подкаст тестировщиков&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;React.js
 &lt;div id="reactjs" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#reactjs" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://learn.javascript.ru/screencast/react" target="_blank" rel="noreferrer"&gt;Основы React.js&lt;/a&gt; - Роман Якобчук (Screencast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://5minreact.ru" target="_blank" rel="noreferrer"&gt;Пятиминутка React&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Ruby
 &lt;div id="ruby" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#ruby" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://rubynoname.ru" target="_blank" rel="noreferrer"&gt;RubyNoName Podcast&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rubyschool.us" target="_blank" rel="noreferrer"&gt;RubySchool (Ruby, Rails)&lt;/a&gt; - Роман Пушкин (Screencast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rwpod.com" target="_blank" rel="noreferrer"&gt;RWPod Podcast&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Scala
 &lt;div id="scala" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#scala" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://scalalaz.ru" target="_blank" rel="noreferrer"&gt;Русскоязычный подкаст о Scala&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Webpack
 &lt;div id="webpack" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#webpack" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://learn.javascript.ru/screencast/webpack" target="_blank" rel="noreferrer"&gt;Скринкаст Webpack&lt;/a&gt; - Илья Кантор (Screencast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Информационные технологии и безопасность
 &lt;div id="информационные-технологии-и-безопасность" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%b8%d0%bd%d1%84%d0%be%d1%80%d0%bc%d0%b0%d1%86%d0%b8%d0%be%d0%bd%d0%bd%d1%8b%d0%b5-%d1%82%d0%b5%d1%85%d0%bd%d0%be%d0%bb%d0%be%d0%b3%d0%b8%d0%b8-%d0%b8-%d0%b1%d0%b5%d0%b7%d0%be%d0%bf%d0%b0%d1%81%d0%bd%d0%be%d1%81%d1%82%d1%8c" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://linkmeup.ru" target="_blank" rel="noreferrer"&gt;LinkMeUp&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://noisebit.podster.fm" target="_blank" rel="noreferrer"&gt;Noise Security Bit&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://uwebdesign.ru" target="_blank" rel="noreferrer"&gt;uWebDesign&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://soundcloud.com/nikita-remezov" target="_blank" rel="noreferrer"&gt;Квант безопасности&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Новости и Разработка ПО
 &lt;div id="новости-и-разработка-по" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%bd%d0%be%d0%b2%d0%be%d1%81%d1%82%d0%b8-%d0%b8-%d1%80%d0%b0%d0%b7%d1%80%d0%b0%d0%b1%d0%be%d1%82%d0%ba%d0%b0-%d0%bf%d0%be" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://ctocast.com" target="_blank" rel="noreferrer"&gt;CTOcast&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://devzen.ru" target="_blank" rel="noreferrer"&gt;DevZen Podcast&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sdcast.ksdaemon.ru" target="_blank" rel="noreferrer"&gt;Software Development podCAST&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://theartofprogramming.podbean.com" target="_blank" rel="noreferrer"&gt;The Art Of Programming&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.2capitals.space" target="_blank" rel="noreferrer"&gt;Две Столицы - Уютный подкаст IT панков&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://kdicast.com" target="_blank" rel="noreferrer"&gt;Как делают игры&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://radio-t.com" target="_blank" rel="noreferrer"&gt;Радио-Т&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://razbor-poletov.com" target="_blank" rel="noreferrer"&gt;Разбор полётов&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://radioma.org" target="_blank" rel="noreferrer"&gt;Развлекательный IT подкаст&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://it.asm0dey.ru" target="_blank" rel="noreferrer"&gt;Слава + Паша&lt;/a&gt; (Podcast)&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>free-programming-books</title><link>https://dominicusin.github.io/2020/03/18/free-programming-books-ru/</link><pubDate>Wed, 18 Mar 2020 17:06:00 +0000</pubDate><guid>https://dominicusin.github.io/2020/03/18/free-programming-books-ru/</guid><description>&lt;h3 class="relative group"&gt;Index
 &lt;div id="index" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#index" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#0---language-agnostic" &gt;0 - Language Agnostic&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#open-source-ecosystem" &gt;Open Source Ecosystem&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#%d0%9e%d0%b1%d0%bb%d0%b0%d1%87%d0%bd%d1%8b%d0%b5-%d0%b2%d1%8b%d1%87%d0%b8%d1%81%d0%bb%d0%b5%d0%bd%d0%b8%d1%8f" &gt;Облачные Вычисления&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#%d0%9f%d0%b0%d1%80%d0%b0%d0%b4%d0%b8%d0%b3%d0%bc%d1%8b-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d0%b8%d1%80%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d1%8f" &gt;Парадигмы Программирования&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#%d0%a0%d0%b0%d0%b1%d0%be%d1%82%d0%b0-%d1%81-%d1%81%d0%b5%d1%82%d1%8c%d1%8e" &gt;Работа c cетью&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#%d0%a3%d0%bf%d1%80%d0%b0%d0%b2%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d0%ba%d0%be%d0%bd%d1%84%d0%b8%d0%b3%d1%83%d1%80%d0%b0%d1%86%d0%b8%d1%8f%d0%bc%d0%b8" &gt;Управление конфигурациями&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#angular" &gt;Angular&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#assembly" &gt;Assembly&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#bash" &gt;Bash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#c" &gt;C&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#c-sharp" &gt;C#&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#c-1" &gt;C++&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#clojure" &gt;Clojure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#coffeescript" &gt;CoffeeScript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#elasticsearch" &gt;Elasticsearch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#elixir" &gt;Elixir&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#erlang" &gt;Erlang&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#git" &gt;Git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#go" &gt;Go&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#haskell" &gt;Haskell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#html--css" &gt;HTML / CSS&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#bootstrap" &gt;Bootstrap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#java" &gt;Java&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#android" &gt;Android&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#easymock" &gt;EasyMock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#hibernate" &gt;Hibernate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#jdbc" &gt;JDBC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#junit" &gt;JUnit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#maven" &gt;Maven&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#spring" &gt;Spring&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#javascript" &gt;JavaScript&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#angularjs" &gt;AngularJS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#jquery" &gt;jQuery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#nodejs" &gt;Node.js&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#nuxtjs" &gt;nuxt.js&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#react" &gt;React&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#vuejs" &gt;vue.js&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#kotlin" &gt;Kotlin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#latex" &gt;LaTeX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#lisp" &gt;Lisp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#metapost" &gt;MetaPost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#net" &gt;.NET&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#nosql" &gt;NoSQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#objective-c" &gt;Objective-C&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#perl" &gt;Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#php" &gt;PHP&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#cakephp" &gt;CakePHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#codeigniter" &gt;CodeIgniter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#laravel" &gt;Laravel&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#python" &gt;Python&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#django" &gt;Django&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#r" &gt;R&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#reverse-engineering" &gt;Reverse engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#ruby" &gt;Ruby&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#rspec" &gt;RSpec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#ruby-on-rails" &gt;Ruby on Rails&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#rust" &gt;Rust&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#scala" &gt;Scala&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#scilab" &gt;Scilab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#scratch" &gt;Scratch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#smalltalk" &gt;Smalltalk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#sql" &gt;SQL&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#postgresql" &gt;PostgreSQL&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#typescript" &gt;TypeScript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#unix" &gt;Unix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-programming-books-ru/#vim" &gt;Vim&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;0 - Language Agnostic
 &lt;div id="0---language-agnostic" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#0---language-agnostic" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://younglinux.info/blender.php" target="_blank" rel="noreferrer"&gt;3D-моделирование в Blender&lt;/a&gt; - C. Шапошникова&lt;/li&gt;
&lt;li&gt;&lt;a href="http://e-maxx.ru/upload/e-maxx_algo.pdf" target="_blank" rel="noreferrer"&gt;E-maxx.ru: Сборник алгоритмов с примерами на C++&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://scrum.org.ua/wp-content/uploads/2008/12/scrum_xp-from-the-trenches-rus-final.pdf" target="_blank" rel="noreferrer"&gt;Scrum и XP: заметки с передовой&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://dsabook.mkurnosov.net" target="_blank" rel="noreferrer"&gt;Введение в структуры и алгоритмы обработки данных&lt;/a&gt; - Михаил Курносов (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://padabum.com/x.php?id=35055" target="_blank" rel="noreferrer"&gt;Занимательное программирование. Самоучитель&lt;/a&gt; - Мозговой М.В. (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vseloved.github.io/pdf/os-ru.pdf" target="_blank" rel="noreferrer"&gt;Операционные системы&lt;/a&gt; - Всеволод Дёмкин (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.inp.nsk.su/~baldin/Parallel/index.html" target="_blank" rel="noreferrer"&gt;Параллельные технологии&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://stolyarov.info/books/programming_intro" target="_blank" rel="noreferrer"&gt;Программирование: введение в профессию&lt;/a&gt; - Столяров Андрей Викторович (:construction: &lt;em&gt;в процессе написания&lt;/em&gt;) (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/http-tutorial" target="_blank" rel="noreferrer"&gt;Руководство по HTTP&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/soap-tutorial" target="_blank" rel="noreferrer"&gt;Руководство по SOAP&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://newstar.rinet.ru/~goga/sicp/sicp-ru-screen.pdf" target="_blank" rel="noreferrer"&gt;Структура и интерпретация компьютерных программ&lt;/a&gt; - Гарольд Абельсон, Джералд Джей Сассман (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://svyatoslav.biz/software_testing_book/" target="_blank" rel="noreferrer"&gt;Тестирование программного обеспечения. Базовый курс.&lt;/a&gt; - Святослав Куликов (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://discopal.ispras.ru/Ru.book-advanced-algorithms.htm" target="_blank" rel="noreferrer"&gt;Эффективные алгоритмы и сложность вычислений&lt;/a&gt; - Кузюрин Н.Н., Фомин С.А.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Работа с сетью
 &lt;div id="работа-с-сетью" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d1%80%d0%b0%d0%b1%d0%be%d1%82%d0%b0-%d1%81-%d1%81%d0%b5%d1%82%d1%8c%d1%8e" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/site/yartikhiy/home/ipv6book" target="_blank" rel="noreferrer"&gt;IPv6 для знатоков IPv4&lt;/a&gt; - Ярослав Тихий (PDF, HTML, EPUB)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vlet/http2-explained/blob/master/http2.ru.pdf?raw=true" target="_blank" rel="noreferrer"&gt;Разъяснение HTTP2&lt;/a&gt; - Даниэль Штенберг (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Open Source Ecosystem
 &lt;div id="open-source-ecosystem" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#open-source-ecosystem" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://rus-linux.net/MyLDP/BOOKS/Architecture-Open-Source-Applications/index.html" target="_blank" rel="noreferrer"&gt;Архитектура приложений с открытым исходным кодом&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Облачные вычисления
 &lt;div id="облачные-вычисления" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%be%d0%b1%d0%bb%d0%b0%d1%87%d0%bd%d1%8b%d0%b5-%d0%b2%d1%8b%d1%87%d0%b8%d1%81%d0%bb%d0%b5%d0%bd%d0%b8%d1%8f" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.microsoft.com/ru-ru/download/details.aspx?id=29263" target="_blank" rel="noreferrer"&gt;Разработка мультитенантных приложений для облака, издание 3-е&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Парадигмы программирования
 &lt;div id="парадигмы-программирования" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%bf%d0%b0%d1%80%d0%b0%d0%b4%d0%b8%d0%b3%d0%bc%d1%8b-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d0%b8%d1%80%d0%be%d0%b2%d0%b0%d0%bd%d0%b8%d1%8f" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://funprog-ru.github.io" target="_blank" rel="noreferrer"&gt;Введение в функциональное программирование&lt;/a&gt; - John Harrison&lt;/li&gt;
&lt;li&gt;&lt;a href="http://fprog.ru" target="_blank" rel="noreferrer"&gt;Практика функционального программирования&lt;/a&gt; - журнал&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Управление конфигурациями
 &lt;div id="управление-конфигурациями" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d1%83%d0%bf%d1%80%d0%b0%d0%b2%d0%bb%d0%b5%d0%bd%d0%b8%d0%b5-%d0%ba%d0%be%d0%bd%d1%84%d0%b8%d0%b3%d1%83%d1%80%d0%b0%d1%86%d0%b8%d1%8f%d0%bc%d0%b8" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/freetonik/ansible-tuto-rus" target="_blank" rel="noreferrer"&gt;Пособие по Ansible&lt;/a&gt; - Michel Blanc&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Angular
 &lt;div id="angular" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#angular" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bxnotes.ru/conspect/angular-5-the-complete-guide/" target="_blank" rel="noreferrer"&gt;Angular 5. Полное руководство&lt;/a&gt; - Maximilian Schwarzmüller&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/angular2" target="_blank" rel="noreferrer"&gt;Руководство по Angular&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Assembly
 &lt;div id="assembly" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#assembly" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://ru.wikibooks.org/wiki/%D0%90%D1%81%D1%81%D0%B5%D0%BC%D0%B1%D0%BB%D0%B5%D1%80_%D0%B2_Linux_%D0%B4%D0%BB%D1%8F_%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D0%B8%D1%81%D1%82%D0%BE%D0%B2_C" target="_blank" rel="noreferrer"&gt;Ассемблер в Linux для программистов C&lt;/a&gt; - Викиучебник&lt;/li&gt;
&lt;li&gt;&lt;a href="http://av-assembler.ru/asm/afd/assembler-for-dummy.htm" target="_blank" rel="noreferrer"&gt;Ассемблер для чайников&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.mcst.ru/doc/book_121130.pdf" target="_blank" rel="noreferrer"&gt;Микропроцессоры и вычислительные комплексы семейства &amp;ldquo;Эльбрус&amp;rdquo;&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.stolyarov.info/books/pdf/nasm_unix.pdf" target="_blank" rel="noreferrer"&gt;Программирование на языке ассемблера NASM для ОС Unix&lt;/a&gt; - Андрей Столяров (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Bash
 &lt;div id="bash" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#bash" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://rus-linux.net/MyLDP/BOOKS/abs-guide/flat/abs-book.html" target="_blank" rel="noreferrer"&gt;Advanced Bash-Scripting Guide&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;C
 &lt;div id="c" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#c" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://yurichev.com/writings/C-notes-ru.pdf" target="_blank" rel="noreferrer"&gt;Заметки о языке программирования Си/Си++&lt;/a&gt; - Денис Юричев (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://younglinux.info/%D1%81" target="_blank" rel="noreferrer"&gt;Особенности языка C. Учебное пособие&lt;/a&gt; - C. Шапошникова (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://zed.karelia.ru/mmedia/docs/nets.pdf" target="_blank" rel="noreferrer"&gt;Разработка сетевых приложений&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/cpp/c" target="_blank" rel="noreferrer"&gt;Руководство по языку программирования C&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://ermak.cs.nstu.ru/cprog/html" target="_blank" rel="noreferrer"&gt;Си/Си++. От дилетанта до профессионала&lt;/a&gt; - Романов Е.Л.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ru.wikibooks.org/wiki/%D0%AF%D0%B7%D1%8B%D0%BA_%D0%A1%D0%B8_%D0%B2_%D0%BF%D1%80%D0%B8%D0%BC%D0%B5%D1%80%D0%B0%D1%85" target="_blank" rel="noreferrer"&gt;Язык Си в примерах&lt;/a&gt; - Викиучебник&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;C Sharp
 &lt;div id="c-sharp" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#c-sharp" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/patterns" target="_blank" rel="noreferrer"&gt;Паттерны проектирования в C# и .NET&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/tutorial" target="_blank" rel="noreferrer"&gt;Полное руководство по языку программирования С# 7.0 и платформе .NET 4.7&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/net" target="_blank" rel="noreferrer"&gt;Сетевое программирование в С# и .NET&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;C++
 &lt;div id="c-1" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#c-1" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://lib.ru/CPPHB/cpptut.txt_with-big-pictures.html" target="_blank" rel="noreferrer"&gt;Введение в язык программирования С++&lt;/a&gt; - Бьерн Страуструп&lt;/li&gt;
&lt;li&gt;&lt;a href="http://stolyarov.info/books/cppintro" target="_blank" rel="noreferrer"&gt;Введение в язык Си++&lt;/a&gt; - Андрей Столяров (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://ru.wikibooks.org/wiki/%D0%A1%D0%B8-%D0%BF%D0%BB%D1%8E%D1%81-%D0%BF%D0%BB%D1%8E%D1%81" target="_blank" rel="noreferrer"&gt;Вводный курс по объектно-ориентированному программированию на языке Си++&lt;/a&gt; - Викиучебник&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/cpp/tutorial" target="_blank" rel="noreferrer"&gt;Руководство по языку программирования C++&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lib.ru/CPPHB/cppref.txt_with-big-pictures.html" target="_blank" rel="noreferrer"&gt;Справочное руководство по C++&lt;/a&gt; - Бьерн Страуструп&lt;/li&gt;
&lt;li&gt;&lt;a href="https://code.google.com/archive/p/gl33lessons/" target="_blank" rel="noreferrer"&gt;Уроки по OpenGL 3&lt;/a&gt; - Гуревич Артём&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Clojure
 &lt;div id="clojure" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#clojure" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://alexott.net/ru/clojure/clojure-intro" target="_blank" rel="noreferrer"&gt;Введение в Clojure&lt;/a&gt; - Алексей Отт&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;CoffeeScript
 &lt;div id="coffeescript" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#coffeescript" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/andrew--r/the-little-book-on-coffeescript" target="_blank" rel="noreferrer"&gt;The Little Book on CoffeeScript&lt;/a&gt; - перевод Андрея Романова&lt;/li&gt;
&lt;li&gt;&lt;a href="http://cidocs.ru/coffeescript" target="_blank" rel="noreferrer"&gt;Документация CoffeeScript&lt;/a&gt; - Jeremy Ashkenas&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Elasticsearch
 &lt;div id="elasticsearch" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#elasticsearch" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://codedzen.ru/category/uroki/elasticsearch" target="_blank" rel="noreferrer"&gt;Уроки по Elasticsearch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Elixir
 &lt;div id="elixir" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#elixir" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://elixirschool.com/ru" target="_blank" rel="noreferrer"&gt;Уроки программирования на языке Elixir&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Erlang
 &lt;div id="erlang" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#erlang" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dyp2000/Russian-Armstrong-Erlang" target="_blank" rel="noreferrer"&gt;Программирование на Эрланге&lt;/a&gt; - Джо Армстронг&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Git
 &lt;div id="git" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#git" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://git-scm.com/book/ru/v2" target="_blank" rel="noreferrer"&gt;Pro Git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www-cs-students.stanford.edu/~blynn/gitmagic/intl/ru" target="_blank" rel="noreferrer"&gt;Волшебство Git&lt;/a&gt; - Ben Lynn&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rogerdudler.github.io/git-guide/index.ru.html" target="_blank" rel="noreferrer"&gt;Простое руководство по работе с Git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/git" target="_blank" rel="noreferrer"&gt;Руководство по Git&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Go
 &lt;div id="go" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#go" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gobyexample.ru" target="_blank" rel="noreferrer"&gt;Go в примерах&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sefus.ru/little-go-book" target="_blank" rel="noreferrer"&gt;The Little Go Book (перевод)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://golang-book.ru" target="_blank" rel="noreferrer"&gt;Введение в программирование на Go&lt;/a&gt; - Калеб Докси&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/go/tutorial" target="_blank" rel="noreferrer"&gt;Руководство по языку Go&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Konstantin8105/Effective_Go_RU" target="_blank" rel="noreferrer"&gt;Эффективный Go&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Haskell
 &lt;div id="haskell" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#haskell" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bitbucket.org/darkus/yesod/downloads" target="_blank" rel="noreferrer"&gt;Developing Web Applications with Haskell and Yesod&lt;/a&gt; - Майкл Сноймен&lt;/li&gt;
&lt;li&gt;&lt;a href="https://wiki.nsunc.com/_export/html/haskell" target="_blank" rel="noreferrer"&gt;Haskell: введение в функциональное программирование&lt;/a&gt; - В.Н. Власов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ohaskell.guide" target="_blank" rel="noreferrer"&gt;О Haskell по-человечески&lt;/a&gt; - Денис Шевченко&lt;/li&gt;
&lt;li&gt;&lt;a href="http://anton-k.github.io/ru-haskell-book/book/home.html" target="_blank" rel="noreferrer"&gt;Учебник по Haskell&lt;/a&gt; - Антон Холомьёв&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.haskell.ru" target="_blank" rel="noreferrer"&gt;Язык и библиотеки Haskell 98&lt;/a&gt; - Simon Peyton Jones&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Number571/Haskell/tree/master/Book" target="_blank" rel="noreferrer"&gt;Язык программирования Haskell: Учимся быть ленивыми&lt;/a&gt; - Г. Коваленко&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;HTML / CSS
 &lt;div id="html--css" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#html--css" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://html5book.ru/css-css3" target="_blank" rel="noreferrer"&gt;CSS и CSS3&lt;/a&gt; - Елена Назарова&lt;/li&gt;
&lt;li&gt;&lt;a href="https://html5book.ru/html-html5" target="_blank" rel="noreferrer"&gt;HTML и HTML5&lt;/a&gt; - Елена Назарова&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/html5" target="_blank" rel="noreferrer"&gt;Руководство по HTML5 и CSS3&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://htmlbook.ru/css" target="_blank" rel="noreferrer"&gt;Справочник CSS&lt;/a&gt; - Влад Мержевич&lt;/li&gt;
&lt;li&gt;&lt;a href="http://htmlbook.ru/html" target="_blank" rel="noreferrer"&gt;Справочник по HTML&lt;/a&gt; - Влад Мержевич&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Bootstrap
 &lt;div id="bootstrap" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#bootstrap" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://getbootstrap.ru/docs/v4-alpha" target="_blank" rel="noreferrer"&gt;Bootstrap 4&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Java
 &lt;div id="java" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#java" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.fandroid.info/tutorial-po-osnovam-yazyka-programmirovaniya-java-dlya-nachinayushhih/" target="_blank" rel="noreferrer"&gt;Java Basics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://myflex.org/books/java4kids/java4kids.htm" target="_blank" rel="noreferrer"&gt;Java Programming for Kids, Parents and Grandparents&lt;/a&gt; - Yakov Fain&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/java-core" target="_blank" rel="noreferrer"&gt;Руководство по Java Core&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/servlets" target="_blank" rel="noreferrer"&gt;Руководство по Servlets&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/java/tutorial" target="_blank" rel="noreferrer"&gt;Руководство по языку программирования Java&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vertex-academy.com/tutorials/ru/samouchitel-po-java-s-nulya/" target="_blank" rel="noreferrer"&gt;Самоучитель по Java с нуля&lt;/a&gt; - Vertex Academy&lt;/li&gt;
&lt;li&gt;&lt;a href="http://javastudy.ru/interview/list-of-question-java-interview" target="_blank" rel="noreferrer"&gt;Собеседование по Java Core&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://javastudy.ru/interview/list-of-questions-javaee-interview" target="_blank" rel="noreferrer"&gt;Собеседование по Java EE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://urvanov.ru/2016/03/23/%D1%83%D1%87%D0%B5%D0%B1%D0%BD%D0%B8%D0%BA-java-8" target="_blank" rel="noreferrer"&gt;Учебник Java 8&lt;/a&gt; - Фёдор Урванов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vertex-academy.com/tutorials/ru/java-8-uchebnik/" target="_blank" rel="noreferrer"&gt;Учебник по Java 8&lt;/a&gt; - Vertex Academy&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vertex-academy.com/tutorials/ru/java-9-uchebnik-teoriya-primery/" target="_blank" rel="noreferrer"&gt;Учебник по Java 9&lt;/a&gt; - Vertex Academy&lt;/li&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/java/yazyk-java/" target="_blank" rel="noreferrer"&gt;Язык Java 8&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Android
 &lt;div id="android" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#android" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://metanit.com/java/android" target="_blank" rel="noreferrer"&gt;Программирование под Android&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://startandroid.ru/ru/uroki/vse-uroki-spiskom.html" target="_blank" rel="noreferrer"&gt;Уроки по Android&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;EasyMock
 &lt;div id="easymock" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#easymock" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/testirovanie/easymock/" target="_blank" rel="noreferrer"&gt;EasyMock 3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Hibernate
 &lt;div id="hibernate" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#hibernate" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/data/hibernate/" target="_blank" rel="noreferrer"&gt;Hibernate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/hibernate-tutorial" target="_blank" rel="noreferrer"&gt;Руководство по Hibernate&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;JDBC
 &lt;div id="jdbc" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#jdbc" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/data/jdbc/" target="_blank" rel="noreferrer"&gt;JDBC и Spring JDBC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/jdbc" target="_blank" rel="noreferrer"&gt;Руководство по JDBC&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;JUnit
 &lt;div id="junit" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#junit" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/testirovanie/junit-2/" target="_blank" rel="noreferrer"&gt;JUnit 4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/junit" target="_blank" rel="noreferrer"&gt;Руководство по JUnit&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Maven
 &lt;div id="maven" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#maven" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/ekosistema/sredstva-sborki/apache-maven/" target="_blank" rel="noreferrer"&gt;Apache Maven&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/maven" target="_blank" rel="noreferrer"&gt;Руководство по Maven&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Spring
 &lt;div id="spring" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#spring" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://easyjava.ru/spring/" target="_blank" rel="noreferrer"&gt;Spring Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/spring-tutorial-full-version" target="_blank" rel="noreferrer"&gt;Руководство по Spring&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;JavaScript
 &lt;div id="javascript" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#javascript" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://bonsaiden.github.io/JavaScript-Garden/ru" target="_blank" rel="noreferrer"&gt;JavaScript Garden&lt;/a&gt; - Иво Ветцель&lt;/li&gt;
&lt;li&gt;&lt;a href="https://html5book.ru/javascript-jquery" target="_blank" rel="noreferrer"&gt;JavaScript и jQuery&lt;/a&gt; - Елена Назарова&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/karmazzin/eloquentjavascript_ru" target="_blank" rel="noreferrer"&gt;Выразительный JavaScript&lt;/a&gt; - Marijn Haverbeke&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bxnotes.ru/conspect/kurs-sovremennogo-javascript/" target="_blank" rel="noreferrer"&gt;Курс современного JavaScript&lt;/a&gt; - bxnotes&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/webgl" target="_blank" rel="noreferrer"&gt;Онлайн-книга по WebGL&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://largescalejs.ru" target="_blank" rel="noreferrer"&gt;Паттерны для масштабируемых JavaScript-приложений&lt;/a&gt; - Эдди Османи&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/javascript" target="_blank" rel="noreferrer"&gt;Руководство по JavaScript&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://learn.javascript.ru" target="_blank" rel="noreferrer"&gt;Современный учебник JavaScript&lt;/a&gt; - Илья Кантор&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;AngularJS
 &lt;div id="angularjs" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#angularjs" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/angular" target="_blank" rel="noreferrer"&gt;Онлайн-руководство по AngularJS&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://angular-doc.herokuapp.com" target="_blank" rel="noreferrer"&gt;Перевод документации&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;jQuery
 &lt;div id="jquery" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#jquery" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://anton.shevchuk.name/jquery-book" target="_blank" rel="noreferrer"&gt;jQuery для начинающих&lt;/a&gt; - Антон Шевчук&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/jquery" target="_blank" rel="noreferrer"&gt;Онлайн-книга &amp;ldquo;Изучаем jQuery&amp;rdquo;&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://jquery-docs.ru" target="_blank" rel="noreferrer"&gt;Русская документация по API jQuery&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Node.js
 &lt;div id="nodejs" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#nodejs" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://nodebeginner.ru" target="_blank" rel="noreferrer"&gt;Node.js для начинающих&lt;/a&gt; - Manuel Kiessling&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/nodejs" target="_blank" rel="noreferrer"&gt;Руководство по Node.js&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Nuxt.js
 &lt;div id="nuxtjs" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#nuxtjs" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://ru.nuxtjs.org" target="_blank" rel="noreferrer"&gt;Перевод документации&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;React
 &lt;div id="react" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#react" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://leanpub.com/the-road-to-learn-react-russian" target="_blank" rel="noreferrer"&gt;Путь к изучению React&lt;/a&gt; - Алексей Пыльцын (PDF, ePub, MOBI) &lt;em&gt;(Требуется аккаунт на Leanpub или действительный адрес электронной почты)&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/react" target="_blank" rel="noreferrer"&gt;Руководство по React&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://codedzen.ru/category/uroki/react" target="_blank" rel="noreferrer"&gt;Уроки по React&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Vue.js
 &lt;div id="vuejs" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#vuejs" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://ru.vuejs.org" target="_blank" rel="noreferrer"&gt;Перевод документации&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/vuejs" target="_blank" rel="noreferrer"&gt;Руководство по Vue.js&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Kotlin
 &lt;div id="kotlin" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#kotlin" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://kotlinlang.ru" target="_blank" rel="noreferrer"&gt;Руководство по языку Kotlin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/java/kotlin" target="_blank" rel="noreferrer"&gt;Руководство по языку Kotlin&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;LaTeX
 &lt;div id="latex" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#latex" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.inp.nsk.su/~baldin/LaTeX/index.html" target="_blank" rel="noreferrer"&gt;LaTeX, GNU/Linux и русский стиль (сборник статей)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.stolyarov.info/books/pdf/latex3days.pdf" target="_blank" rel="noreferrer"&gt;LaTeX за три дня&lt;/a&gt; - Андрей Столяров (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Lisp
 &lt;div id="lisp" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#lisp" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://lisper.ru/wiki/Cookbook" target="_blank" rel="noreferrer"&gt;Common Lisp Cookbook (перевод)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ilammy/lisp" target="_blank" rel="noreferrer"&gt;Lisp In Small Pieces (translation)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lisper.ru/pcl/" target="_blank" rel="noreferrer"&gt;Practical Common Lisp (перевод)&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;MetaPost
 &lt;div id="metapost" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#metapost" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.inp.nsk.su/~baldin/mpost/index.html" target="_blank" rel="noreferrer"&gt;Создание иллюстраций в MetaPost&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;.NET
 &lt;div id="net" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#net" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/adonet" target="_blank" rel="noreferrer"&gt;Руководство по ADO.NET и работе с базами данных&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/aspnet5" target="_blank" rel="noreferrer"&gt;Руководство по ASP.NET Core 2.0&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/mvc5" target="_blank" rel="noreferrer"&gt;Руководство по ASP.NET MVC 5&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/aspnet_webapi" target="_blank" rel="noreferrer"&gt;Руководство по ASP.NET Web API 2&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/entityframeworkcore" target="_blank" rel="noreferrer"&gt;Руководство по EF Core&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sharp/entityframework" target="_blank" rel="noreferrer"&gt;Руководство по Entity Framework&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;NoSQL
 &lt;div id="nosql" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#nosql" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.pvsm.ru/download/mongodb-ru.pdf" target="_blank" rel="noreferrer"&gt;Маленькая книга о MongoDB&lt;/a&gt; - Карл Сегуин (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kondratovich/the-little-redis-book/blob/master/ru/redis.md" target="_blank" rel="noreferrer"&gt;Маленькая книга о Redis&lt;/a&gt; - Карл Сегуин&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/mongodb" target="_blank" rel="noreferrer"&gt;Руководство по MongoDB&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Objective-C
 &lt;div id="objective-c" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#objective-c" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://yadi.sk/d/ugz7jW4RXLGTN" target="_blank" rel="noreferrer"&gt;Become an XCoder&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://maleevdimka.files.wordpress.com/2013/04/ios-patterns-cliff-notes2.pdf" target="_blank" rel="noreferrer"&gt;Хрестоматия iOS паттернов&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://habrahabr.ru/post/149090/" target="_blank" rel="noreferrer"&gt;Цикл статей разработки под Apple iOS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Perl
 &lt;div id="perl" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#perl" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://pragmaticperl.com" target="_blank" rel="noreferrer"&gt;Pragmatic Perl&lt;/a&gt; - журнал&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/perl-maslov/" target="_blank" rel="noreferrer"&gt;Введение в Perl&lt;/a&gt; - Маслов Владимир Викторович&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/perl_help/" target="_blank" rel="noreferrer"&gt;Краткий экскурс в Perl-программирование&lt;/a&gt; - Докучаев Дмитрий&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;PHP
 &lt;div id="php" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#php" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://getjump.github.io/ru-php-the-right-way" target="_blank" rel="noreferrer"&gt;PHP: Правильный Путь&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://docs.php.net/manual/ru" target="_blank" rel="noreferrer"&gt;Руководство по PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://phpunit.readthedocs.io/ru/latest/" target="_blank" rel="noreferrer"&gt;Руководство по PHPUnit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.php-s.ru/self-teacher" target="_blank" rel="noreferrer"&gt;Самоучитель (учебник) по PHP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;CakePHP
 &lt;div id="cakephp" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cakephp" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://book.cakephp.org/3.0/ru/index.html" target="_blank" rel="noreferrer"&gt;Руководство&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;CodeIgniter
 &lt;div id="codeigniter" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#codeigniter" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://codeigniter3.info" target="_blank" rel="noreferrer"&gt;CodeIgniter&lt;/a&gt; - Игорь Букша&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Laravel
 &lt;div id="laravel" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#laravel" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://laravel.ru/docs/v5" target="_blank" rel="noreferrer"&gt;Документация 5.x&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://laravel.su/docs" target="_blank" rel="noreferrer"&gt;Перевод документации&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Python
 &lt;div id="python" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#python" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aliev.github.io/runestone" target="_blank" rel="noreferrer"&gt;Problem Solving with Algorithms and Data Structures&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://devpractice.ru/book-python-unittest" target="_blank" rel="noreferrer"&gt;Python. unittest&lt;/a&gt; - Абдрахманов М.И&lt;/li&gt;
&lt;li&gt;&lt;a href="https://younglinux.info/oopython.php" target="_blank" rel="noreferrer"&gt;Python. Введение в объектно-ориентированное программирование&lt;/a&gt; - C. Шапошникова&lt;/li&gt;
&lt;li&gt;&lt;a href="https://younglinux.info/python.php" target="_blank" rel="noreferrer"&gt;Python. Введение в программирование&lt;/a&gt; - C. Шапошникова&lt;/li&gt;
&lt;li&gt;&lt;a href="https://devpractice.ru/book-python-lessons" target="_blank" rel="noreferrer"&gt;Python. Уроки&lt;/a&gt; - Абдрахманов М.И.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://younglinux.info/tkinter.php" target="_blank" rel="noreferrer"&gt;Tkinter. Программирование графического интерфейса&lt;/a&gt; - C. Шапошникова&lt;/li&gt;
&lt;li&gt;&lt;a href="http://ru.diveintopython.net/toc.html" target="_blank" rel="noreferrer"&gt;Вглубь языка Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://dfedorov.spb.ru/python3" target="_blank" rel="noreferrer"&gt;Основы программирования на Python&lt;/a&gt; - Дмитрий Фёдоров (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/python/tutorial" target="_blank" rel="noreferrer"&gt;Руководство по языку программирования Python&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://pythonworld.ru/samouchitel-python" target="_blank" rel="noreferrer"&gt;Самоучитель Python&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://wombat.org.ua/AByteOfPython" target="_blank" rel="noreferrer"&gt;Укус Питона&lt;/a&gt; - Swaroop C H&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ru.wikibooks.org/wiki/%D0%A3%D1%87%D0%B5%D0%B1%D0%BD%D0%B8%D0%BA_Python_2.6" target="_blank" rel="noreferrer"&gt;Учебник Python 2.6&lt;/a&gt; - Викиучебник&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Django
 &lt;div id="django" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#django" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://tutorial.djangogirls.org/ru" target="_blank" rel="noreferrer"&gt;Руководство Django Girls&lt;/a&gt; (1.11) (HTML) (:construction: &lt;em&gt;в процессе написания&lt;/em&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/python/django" target="_blank" rel="noreferrer"&gt;Руководство по веб-фреймворку Django&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;R
 &lt;div id="r" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#r" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.inp.nsk.su/~baldin/DataAnalysis/index.html" target="_blank" rel="noreferrer"&gt;Анализ данных с R&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.ievbras.ru/ecostat/Kiril/Article/A32/Starb.pdf" target="_blank" rel="noreferrer"&gt;Рандомизация и бутстреп: статистический анализ в биологии и экологии с использованием R.&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Reverse engineering
 &lt;div id="reverse-engineering" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#reverse-engineering" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://beginners.re/RE4B-RU.pdf" target="_blank" rel="noreferrer"&gt;Введение в reverse engineering для начинающих&lt;/a&gt; - Денис Юричев (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Ruby
 &lt;div id="ruby" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#ruby" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://ru.wikibooks.org/wiki/Ruby" target="_blank" rel="noreferrer"&gt;Ruby&lt;/a&gt; - Викиучебник&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Krugloff/rus_ruby_book" target="_blank" rel="noreferrer"&gt;Ruby Book&lt;/a&gt; - Круглов А.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.ruby-lang.org/ru/documentation/quickstart" target="_blank" rel="noreferrer"&gt;Ruby за двадцать минут&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://linux.yaroslavl.ru/docs/prog/ruby.html" target="_blank" rel="noreferrer"&gt;Руководство пользователя&lt;/a&gt; - matz&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.shokhirev.com/mikhail/ruby/ltp/title.html" target="_blank" rel="noreferrer"&gt;Учись программировать&lt;/a&gt; - Крис Пайн&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;RSpec
 &lt;div id="rspec" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#rspec" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://betterspecs.org/ru" target="_blank" rel="noreferrer"&gt;Better Specs (RSpec Guidelines with Ruby)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Ruby on Rails
 &lt;div id="ruby-on-rails" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#ruby-on-rails" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://railstutorial.ru/chapters/4_0/beginning" target="_blank" rel="noreferrer"&gt;Ruby on Rails Tutorial. Изучение Rails на Примерах&lt;/a&gt; Майкл Хартл&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rusrails.ru" target="_blank" rel="noreferrer"&gt;Ruby on Rails по-русски&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Rust
 &lt;div id="rust" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#rust" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rurust.github.io/rust-by-example-ru" target="_blank" rel="noreferrer"&gt;Rust на примерах&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ruRust/rustonomicon" target="_blank" rel="noreferrer"&gt;Растономикон&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rurust.github.io/rust_book_ru" target="_blank" rel="noreferrer"&gt;Язык программирования Rust&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Scala
 &lt;div id="scala" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#scala" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://twitter.github.io/effectivescala/index-ru.html" target="_blank" rel="noreferrer"&gt;Effective Scala&lt;/a&gt; - Marius Eriksen&lt;/li&gt;
&lt;li&gt;&lt;a href="http://twitter.github.io/scala_school/ru" target="_blank" rel="noreferrer"&gt;Scala Школа!&lt;/a&gt; - Twitter&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/anton-k/ru-neophyte-guide-to-scala" target="_blank" rel="noreferrer"&gt;Путеводитель неофита по Scala (перевод серии статей Даниеля Вестсайда)&lt;/a&gt; - Антон Холомьёв&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/scala" target="_blank" rel="noreferrer"&gt;Руководство по Scala&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Scilab
 &lt;div id="scilab" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#scilab" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://forge.scilab.org/index.php/p/docintrotoscilab/downloads" target="_blank" rel="noreferrer"&gt;Введение в Scilab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://forge.scilab.org/index.php/p/docprogscilab/downloads" target="_blank" rel="noreferrer"&gt;Программирование в Scilab&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Scratch
 &lt;div id="scratch" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#scratch" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.dropbox.com/s/qsthpk5r6gqmi6u/CreativeComputing_RUS_june2016.pdf?dl=0" target="_blank" rel="noreferrer"&gt;Креативное программирование&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Smalltalk
 &lt;div id="smalltalk" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#smalltalk" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/site/polyglotsqueak" target="_blank" rel="noreferrer"&gt;Смолток: Язык и его реализация&lt;/a&gt; - Адэль Голдберг, Дэвид Робсон&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;SQL
 &lt;div id="sql" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#sql" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://svyatoslav.biz/database_book/" target="_blank" rel="noreferrer"&gt;Работа с MySQL, MS SQL Server и Oracle в примерах&lt;/a&gt; - Святослав Куликов (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/sql/sqlserver" target="_blank" rel="noreferrer"&gt;Руководство по MS SQL Server 2017&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://proselyte.net/tutorials/sql" target="_blank" rel="noreferrer"&gt;Руководство по SQL&lt;/a&gt; - Евгений Сулейманов&lt;/li&gt;
&lt;li&gt;&lt;a href="https://postgrespro.ru/education/books/sqlprimer" target="_blank" rel="noreferrer"&gt;Язык SQL. Базовый курс&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;PostgreSQL
 &lt;div id="postgresql" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#postgresql" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://postgrespro.ru/education/books/introbook" target="_blank" rel="noreferrer"&gt;PostgreSQL для начинающих&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://postgrespro.ru/docs/postgresql" target="_blank" rel="noreferrer"&gt;Документация&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.inp.nsk.su/~baldin/PostgreSQL/index.html" target="_blank" rel="noreferrer"&gt;История о PostgreSQL&lt;/a&gt; - Linux Format&lt;/li&gt;
&lt;li&gt;&lt;a href="http://postgresql.leopard.in.ua" target="_blank" rel="noreferrer"&gt;Работа с PostgreSQL - настройка и масштабирование&lt;/a&gt; - А. Ю. Васильев&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;TypeScript
 &lt;div id="typescript" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#typescript" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://typescript-lang.ru/docs/index.html" target="_blank" rel="noreferrer"&gt;Перевод официальной документации Typescript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://metanit.com/web/typescript" target="_blank" rel="noreferrer"&gt;Руководство по TypeScript&lt;/a&gt; - Евгений Попов&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Unix
 &lt;div id="unix" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#unix" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://rus-linux.net/nlib.php?name=/MyLDP/BOOKS/BLFS-ru/blfs-ru-index.html" target="_blank" rel="noreferrer"&gt;Beyond Linux From Scratch (version 2011-12-30)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rus-linux.net/nlib.php?name=/MyLDP/BOOKS/LFS-BOOK-6.8-ru/lfs-6.8-ru-index.html" target="_blank" rel="noreferrer"&gt;Linux From Scratch (version 6.8)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/lkmpg26" target="_blank" rel="noreferrer"&gt;The Linux Kernel Module Programming Guide&lt;/a&gt; - Peter Jay Salzman, Michael Burian, Ori Pomerantz&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lib.ru/BACH" target="_blank" rel="noreferrer"&gt;Архитектура операционной системы Unix&lt;/a&gt; - Maurice J. Bach&lt;/li&gt;
&lt;li&gt;&lt;a href="https://younglinux.info/linuxintro" target="_blank" rel="noreferrer"&gt;Введение в Linux. Руководство по работе&lt;/a&gt; - Machtelt Garrels&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lib.ru/unixhelp" target="_blank" rel="noreferrer"&gt;Введение в системное администрирование UNIX&lt;/a&gt; - Мошков Максим Евгеньевич&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/lki" target="_blank" rel="noreferrer"&gt;Внутреннее устройство Ядра Linux 2.4&lt;/a&gt; - Tigran Aivazian&lt;/li&gt;
&lt;li&gt;&lt;a href="http://man-pages-ru.sourceforge.net" target="_blank" rel="noreferrer"&gt;Перевод Linux kernel and C library.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/zlp" target="_blank" rel="noreferrer"&gt;Программирование в Linux с нуля&lt;/a&gt; - Nikolay N. Ivanov&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/Lpg" target="_blank" rel="noreferrer"&gt;Руководство программиста для Linux&lt;/a&gt; - Sven Goldt, Matt Welsh&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/lpg" target="_blank" rel="noreferrer"&gt;Энциклопедия программиста Linux&lt;/a&gt; - Алексей Паутов&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/lkmpg" target="_blank" rel="noreferrer"&gt;Энциклопедия разработчика модулей ядра Linux&lt;/a&gt; - Ori Pomerantz&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Vim
 &lt;div id="vim" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#vim" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.opennet.ru/docs/RUS/vim_cookbook" target="_blank" rel="noreferrer"&gt;Поваренная Книга Vim&lt;/a&gt; - Steve Oualline&lt;/li&gt;
&lt;li&gt;&lt;a href="http://rus-linux.net/MyLDP/BOOKS/Vim/prosto-o-vim.pdf" target="_blank" rel="noreferrer"&gt;Просто о Vim&lt;/a&gt; (PDF)&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>free-courses</title><link>https://dominicusin.github.io/2020/03/18/free-courses-ru/</link><pubDate>Wed, 18 Mar 2020 16:55:00 +0000</pubDate><guid>https://dominicusin.github.io/2020/03/18/free-courses-ru/</guid><description>&lt;h3 class="relative group"&gt;Index
 &lt;div id="index" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#index" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-courses-ru/#clojure" &gt;Clojure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-courses-ru/#java" &gt;Java&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-courses-ru/#php" &gt;PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-courses-ru/#postgresql" &gt;PostgreSQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-courses-ru/#python" &gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2020/03/18/free-courses-ru/#react" &gt;React&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Уровни
 &lt;div id="уровни" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d1%83%d1%80%d0%be%d0%b2%d0%bd%d0%b8" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;BEG - новичок. Основы.&lt;br&gt;
INT - средний. Расширенные возможности.&lt;br&gt;
ADV - продвинутый. Тонкости.&lt;/p&gt;</description></item><item><title>Advs for programmer</title><link>https://dominicusin.github.io/2020/03/18/advices/</link><pubDate>Wed, 18 Mar 2020 00:37:00 +0000</pubDate><guid>https://dominicusin.github.io/2020/03/18/advices/</guid><description>&lt;p&gt;getting from &lt;a href="https://www.zoonman.com/blog/seven-golden-advices/" target="_blank" rel="noreferrer"&gt;Seven golden advices for programmer&lt;/a&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Never trust yourself It&amp;rsquo;s about the code. Everytime, when I have an error somewhere but can&amp;rsquo;t find it, I begin blame everything: interpreter, environment, language. But this is always the error in code, mostly this error is simple, like similar name of variable or just silly typo. In such moment I always trying to change state of my mind, switch environment, write unit test, grab cup of coffee or go for a walk.&lt;/p&gt;</description></item><item><title>programmers</title><link>https://dominicusin.github.io/2020/03/08/russian_programmers/</link><pubDate>Sun, 08 Mar 2020 20:49:00 +0000</pubDate><guid>https://dominicusin.github.io/2020/03/08/russian_programmers/</guid><description>&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Good programmers never read manuals and rarely use online help - they easily get a grasp of a new program, simply because they have already tried every single program in this field before.&lt;/p&gt;</description></item><item><title>HipChat Alternatives</title><link>https://dominicusin.github.io/2019/12/16/hipchatalternatives/</link><pubDate>Mon, 16 Dec 2019 03:42:00 +0000</pubDate><guid>https://dominicusin.github.io/2019/12/16/hipchatalternatives/</guid><description>&lt;h2 class="relative group"&gt;HipChat Alternatives
 &lt;div id="hipchat-alternatives" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#hipchat-alternatives" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h4 class="relative group"&gt;Why?
 &lt;div id="why" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#why" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;p&gt;HipChat is fantastic, however:&lt;/p&gt;</description></item><item><title>gcloud cheat sheet</title><link>https://dominicusin.github.io/2019/07/25/gcloud-cheat-sheet/</link><pubDate>Thu, 25 Jul 2019 01:55:00 +0000</pubDate><guid>https://dominicusin.github.io/2019/07/25/gcloud-cheat-sheet/</guid><description>&lt;h2 class="relative group"&gt;References
 &lt;div id="references" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#references" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloudplatform.googleblog.com/2016/06/filtering-and-formatting-fun-with.html" target="_blank" rel="noreferrer"&gt;have fun with them&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/sdk/gcloud/reference/topic/projections" target="_blank" rel="noreferrer"&gt;projections&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/sdk/gcloud/reference/topic/filters" target="_blank" rel="noreferrer"&gt;filters&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/sdk/gcloud/reference/topic/resource-keys" target="_blank" rel="noreferrer"&gt;resource-keys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/sdk/docs/scripting-gcloud" target="_blank" rel="noreferrer"&gt;scripting-gcloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://cloudplatform.googleblog.com/2018/03/introducing-GCPs-new-interactive-CLI.html" target="_blank" rel="noreferrer"&gt;gcloud alpha interactive&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://medium.com/@Joachim8675309/getting-started-with-gcloud-sdk-part-1-114924737" target="_blank" rel="noreferrer"&gt;https://medium.com/@Joachim8675309/getting-started-with-gcloud-sdk-part-1-114924737&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://medium.com/@Joachim8675309/getting-started-with-gcloud-sdk-part-2-4d049a656f1a" target="_blank" rel="noreferrer"&gt;https://medium.com/@Joachim8675309/getting-started-with-gcloud-sdk-part-2-4d049a656f1a&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/bborysenko/97749fe0514b819a5a87611e6aea3db8" target="_blank" rel="noreferrer"&gt;https://gist.github.com/bborysenko/97749fe0514b819a5a87611e6aea3db8&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;Other cheatsheets
 &lt;div id="other-cheatsheets" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#other-cheatsheets" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/dennyzhang/cheatsheet-gcp-A4" target="_blank" rel="noreferrer"&gt;https://github.com/dennyzhang/cheatsheet-gcp-A4&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;multiple gcloud config configurations
 &lt;div id="multiple-gcloud-config-configurations" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#multiple-gcloud-config-configurations" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.jhanley.com/google-cloud-understanding-gcloud-configurations/" target="_blank" rel="noreferrer"&gt;https://www.jhanley.com/google-cloud-understanding-gcloud-configurations/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://medium.com/infrastructure-adventures/working-with-multiple-environment-in-gcloud-cli-93b2d4e8cf1e" target="_blank" rel="noreferrer"&gt;https://medium.com/infrastructure-adventures/working-with-multiple-environment-in-gcloud-cli-93b2d4e8cf1e&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config configurations create pythonrocks
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config configurations list
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config configurations activate pythonrocks
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set core/account pythonrocks@gmail.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud auth login
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud projects list
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set project dev-193420&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h3 class="relative group"&gt;switch gcloud context with gcloud config
 &lt;div id="switch-gcloud-context-with-gcloud-config" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#switch-gcloud-context-with-gcloud-config" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config list
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set account pythonrocksk8s201702@gmail.com 
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set project salt-163215
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set compute/region us-west1
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set compute/zone us-west1-a
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;alias demo=&amp;#39;gcloud config set account pythonrocksk8s201702@gmail.com &amp;amp;&amp;amp; gcloud config set project salt-163215 &amp;amp;&amp;amp; gcloud config set compute/region us-west1 &amp;amp;&amp;amp; gcloud config set compute/zone us-west1-a&amp;#39;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;cluster=$(gcloud config get-value container/cluster 2&amp;gt; /dev/null)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;zone=$(gcloud config get-value compute/zone 2&amp;gt; /dev/null)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;project=$(gcloud config get-value core/project 2&amp;gt; /dev/null)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;# switch project based on the name
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud config set project $(gcloud projects list --filter=&amp;#39;name:wordpress-dev&amp;#39; --format=&amp;#39;value(project_id)&amp;#39;)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;command -v gcloud &amp;gt;/dev/null 2&amp;gt;&amp;amp;1 || { \
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &amp;gt;&amp;amp;2 &amp;#34;I require gcloud but it&amp;#39;s not installed. Aborting.&amp;#34;; exit 1; }
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;REGION=$(gcloud config get-value compute/region)
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;if [[ -z &amp;#34;${REGION}&amp;#34; ]]; then
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &amp;#34;https://cloud.google.com/compute/docs/regions-zones/changing-default-zone-region&amp;#34; 1&amp;gt;&amp;amp;2
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &amp;#34;gcloud cli must be configured with a default region.&amp;#34; 1&amp;gt;&amp;amp;2
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &amp;#34;run &amp;#39;gcloud config set compute/region REGION&amp;#39;.&amp;#34; 1&amp;gt;&amp;amp;2
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; echo &amp;#34;replace &amp;#39;REGION&amp;#39; with the region name like us-west1.&amp;#34; 1&amp;gt;&amp;amp;2
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; exit 1;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;fi&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h2 class="relative group"&gt;auth
 &lt;div id="auth" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#auth" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud auth list
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud auth login
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gcloud auth activate-service-account --key-file=sa_key.json&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;kubectl uses OAuth token generated by&lt;/p&gt;</description></item><item><title>Awesome-Selfhosted</title><link>https://dominicusin.github.io/2019/06/16/awesome-selfhosted/</link><pubDate>Sun, 16 Jun 2019 14:04:00 +0000</pubDate><guid>https://dominicusin.github.io/2019/06/16/awesome-selfhosted/</guid><description>&lt;h1 class="relative group"&gt;Awesome-Selfhosted
 &lt;div id="awesome-selfhosted" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#awesome-selfhosted" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;&lt;a href="https://github.com/sindresorhus/awesome" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Awesome"
 src="https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg"
 &gt;&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Selfhosting is the process of locally hosting and managing applications instead of renting from SaaS providers.&lt;/p&gt;</description></item><item><title>SFTP</title><link>https://dominicusin.github.io/2019/05/17/sftp/</link><pubDate>Fri, 17 May 2019 21:50:00 +0000</pubDate><guid>https://dominicusin.github.io/2019/05/17/sftp/</guid><description>&lt;p&gt;This Guide will allow you to mount your Feral slots remote file system as a local file system through SFTP.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Recommended Method:&lt;/strong&gt; Install Dokan Libraries and then use win-sshfs.&lt;/p&gt;</description></item><item><title>Linux Networking commands</title><link>https://dominicusin.github.io/2019/01/31/linux-networking-commands/</link><pubDate>Thu, 31 Jan 2019 15:41:00 +0000</pubDate><guid>https://dominicusin.github.io/2019/01/31/linux-networking-commands/</guid><description>&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://linux.die.net/man/8/arpwatch" target="_blank" rel="noreferrer"&gt;arpwatch&lt;/a&gt; – Ethernet Activity Monitor.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/tgraf/bmon" target="_blank" rel="noreferrer"&gt;bmon&lt;/a&gt; – bandwidth monitor and rate estimator.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.gropp.org/?id=projects&amp;amp;sub=bwm-ng" target="_blank" rel="noreferrer"&gt;bwm-ng&lt;/a&gt; – live network bandwidth monitor.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://curl.haxx.se/" target="_blank" rel="noreferrer"&gt;curl&lt;/a&gt; – transferring data with URLs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://unix4lyfe.org/darkstat/" target="_blank" rel="noreferrer"&gt;darkstat&lt;/a&gt; – captures network traffic, usage statistics.&lt;/p&gt;</description></item><item><title>Awesome Machine Learning for Cyber Security</title><link>https://dominicusin.github.io/2018/11/09/awesome-machine-learning-for-cyber-security/</link><pubDate>Fri, 09 Nov 2018 03:42:00 +0000</pubDate><guid>https://dominicusin.github.io/2018/11/09/awesome-machine-learning-for-cyber-security/</guid><description>&lt;h1 class="relative group"&gt;Awesome Machine Learning for Cyber Security &lt;a href="https://github.com/sindresorhus/awesome" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Awesom"
 src="https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg"
 &gt;&lt;/figure&gt;
&lt;/a&gt;
 &lt;div id="awesome-machine-learning-for-cyber-security-awesom" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#awesome-machine-learning-for-cyber-security-awesom" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;&lt;a href="https://github.com/jivoi/awesome-ml-for-cybersecurity" target="_blank" rel="noreferrer"&gt;&lt;img src="https://github.com/jivoi/awesome-ml-for-cybersecurity/raw/master/cyber-ml-logo.png" align="right" width="100"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A curated list of amazingly awesome tools and resources related to the use of machine learning for cyber security.&lt;/p&gt;</description></item><item><title>My favorite movies</title><link>https://dominicusin.github.io/2018/11/08/my-favorite-movies/</link><pubDate>Thu, 08 Nov 2018 23:34:00 +0000</pubDate><guid>https://dominicusin.github.io/2018/11/08/my-favorite-movies/</guid><description>&lt;h1 class="relative group"&gt;&lt;strong&gt;My favorite movies&lt;/strong&gt;
 &lt;div id="my-favorite-movies" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#my-favorite-movies" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.imdb.com/title/tt1901040/" target="_blank" rel="noreferrer"&gt;Wrong 2012&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.imdb.com/title/tt2481554/" target="_blank" rel="noreferrer"&gt;Murder of a Cat 2014&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.imdb.com/title/tt1567437/" target="_blank" rel="noreferrer"&gt;The Voices 2014&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Google Interview Questions</title><link>https://dominicusin.github.io/2018/02/25/google-interview-questions/</link><pubDate>Sun, 25 Feb 2018 18:25:00 +0000</pubDate><guid>https://dominicusin.github.io/2018/02/25/google-interview-questions/</guid><description>&lt;p&gt;##Google Interview Questions: Product Marketing Manager&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Why do you want to join Google?
&amp;ndash; Because I want to create tools for others to learn, for free. I didn&amp;rsquo;t have a lot of money when growing up so I didn&amp;rsquo;t get access to the same books, computers and resources that others had which caused money, I want to help ensure that others can learn on the same playing field regardless of their families wealth status or location.&lt;/p&gt;</description></item><item><title>it-podcast</title><link>https://dominicusin.github.io/2018/02/03/russia-it-podcast/</link><pubDate>Sat, 03 Feb 2018 12:50:00 +0000</pubDate><guid>https://dominicusin.github.io/2018/02/03/russia-it-podcast/</guid><description>&lt;h1 class="relative group"&gt;russia-it-podcast
 &lt;div id="russia-it-podcast" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#russia-it-podcast" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;Список русскоязычных подкастов на тему информационных технологий.&lt;/p&gt;
&lt;p&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt=""
 src="https://pbs.twimg.com/media/BxeayTeIQAAgf5M.png:large"
 &gt;&lt;/figure&gt;
&lt;/p&gt;

&lt;h4 class="relative group"&gt;DevZen (&lt;a href="https://twitter.com/search?q=%23DevZen" target="_blank" rel="noreferrer"&gt;#DevZen&lt;/a&gt;) &lt;a href="http://devzen.ru/" target="_blank" rel="noreferrer"&gt;site&lt;/a&gt;, &lt;a href="http://vk.cc/2YIFnf" target="_blank" rel="noreferrer"&gt;itunes&lt;/a&gt;
 &lt;div id="devzen-devzen-site-itunes" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#devzen-devzen-site-itunes" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;p&gt;DevZen Podcast (ранее EaxCast) — единственный подкаст на русском языке о программировании, администрировании и вообще IT, который (1) выходит каждую неделю, (2) специализируется на сильно технических темах, не &amp;ldquo;мобилках&amp;rdquo;, (3) и при этом не является узконаправленным, например, посвященным одному языку программирования или стеку технологий. За первый год своего существования у подкаста появилось более 3000 постоянных слушателей.&lt;/p&gt;</description></item><item><title>forth</title><link>https://dominicusin.github.io/2017/11/15/forth/</link><pubDate>Wed, 15 Nov 2017 13:38:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/11/15/forth/</guid><description>&lt;h2 class="relative group"&gt;Forths in Assembly
 &lt;div id="forths-in-assembly" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#forths-in-assembly" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th style="text-align: center"&gt;:star:&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Name / Link&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Lang&lt;/th&gt;
					&lt;th style="text-align: left"&gt;CPU&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Description&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;:sparkles:&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/search?q=amforth&amp;amp;type=Repositories&amp;amp;s=updated" target="_blank" rel="noreferrer"&gt;AmForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;AVR, MSP430&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;em&gt;(13 repositories)&lt;/em&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;126&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/organix/pijFORTHos" target="_blank" rel="noreferrer"&gt;pijFORTHos&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ARM&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Bare-metal FORTH operating system for Raspberry Pi&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;53&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/jamesbowman/swapforth" target="_blank" rel="noreferrer"&gt;Swapforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;J1, FT900, x64&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Cross-platform 32-bit ANS Forth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;44&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/chengchangwu/jonesforth" target="_blank" rel="noreferrer"&gt;jonesforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;x86&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ANS FORTH version of jonesforth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;32&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/TG9541/stm8ef" target="_blank" rel="noreferrer"&gt;STM8EF&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;STM8S&lt;/td&gt;
					&lt;td style="text-align: left"&gt;eForth with extensions for $0.20 µCs&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;30&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/hellige/dcpu" target="_blank" rel="noreferrer"&gt;DCPU&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;DCPU-16&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth for Notch&amp;rsquo;s DCPU-16&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;29&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/ekoeppen/CoreForth" target="_blank" rel="noreferrer"&gt;CoreForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ARM&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth for the Cortex-M3&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;23&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/M2IHP13-admin/JonesForth-arm" target="_blank" rel="noreferrer"&gt;JonesForth-arm&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ARM&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ARM port of JonesForth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;22&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/jkotlinski/durexforth" target="_blank" rel="noreferrer"&gt;DurexForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;6502&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Modern C64 Forth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;13&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/nfz/asforth" target="_blank" rel="noreferrer"&gt;asforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;AVR&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Subroutine threaded Forth for Atmega328&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;9&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/chitselb/pettil" target="_blank" rel="noreferrer"&gt;PETTIL&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;6502&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth for the Commodore PET 2001&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;8&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/oh2aun/flashforth" target="_blank" rel="noreferrer"&gt;FlashForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;PIC, AVR&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth system for the Microchip PIC 18, 24, 30, 33 and the Atmel Atmega&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;8&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/jean-michel/FAST-FORTH" target="_blank" rel="noreferrer"&gt;FastForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;MSP430&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth for all MSP430 FRAM devices, with SD card FAT16/32 and much more&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;7&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/gnooth/feline" target="_blank" rel="noreferrer"&gt;feline&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;x64&lt;/td&gt;
					&lt;td style="text-align: left"&gt;64-bit native code Forth 200x&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;6&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/vygr/OSX-Forth" target="_blank" rel="noreferrer"&gt;OSX-Forth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;x86&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth for OSX&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/samawati/j1eforth" target="_blank" rel="noreferrer"&gt;j1eforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;J1&lt;/td&gt;
					&lt;td style="text-align: left"&gt;eForth for the j1&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/ehaliewicz/megaforth" target="_blank" rel="noreferrer"&gt;megaforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;68000&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth designed for the Sega Megadrive&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;2&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/jjonethal/mecrisp-stellaris" target="_blank" rel="noreferrer"&gt;MecrispStellaris&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ARM Cortex&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Mecrisp Stellaris Forth for ARM Cortex Architectures&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;1&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/mikalus/CF430FR" target="_blank" rel="noreferrer"&gt;CF430R&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;MSP430&lt;/td&gt;
					&lt;td style="text-align: left"&gt;CamelForth for MSP430&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;1&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="http://mecrisp.sourceforge.net" target="_blank" rel="noreferrer"&gt;Mecrisp&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;MSP430&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Mecrisp Forth for MSP430&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;1&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/nealcrook/hForth" target="_blank" rel="noreferrer"&gt;hForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Assembly&lt;/td&gt;
					&lt;td style="text-align: left"&gt;8086, Z80, ARM&lt;/td&gt;
					&lt;td style="text-align: left"&gt;hForth for i8086, Z80 and ARM&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;

&lt;h2 class="relative group"&gt;Forths in Forth
 &lt;div id="forths-in-forth" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#forths-in-forth" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th style="text-align: center"&gt;:star:&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Name / Link&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Lang&lt;/th&gt;
					&lt;th style="text-align: left"&gt;CPU&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Description&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;49&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/larsbrinkhoff/lbForth" target="_blank" rel="noreferrer"&gt;lbForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;x86&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Self-hosting metacompiled Forth, bootstrapping from a few lines of C&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;8&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/samueltardieu/picforth" target="_blank" rel="noreferrer"&gt;PicForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;PIC16&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth cross-compiler for PIC16Fxxx&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;8&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/CharleyShattuck/myforth-arduino" target="_blank" rel="noreferrer"&gt;myforth-arduino&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;AVR&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Simple, non-standard, tethered Forth for the Arduino&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;7&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/oco2000/m3forth" target="_blank" rel="noreferrer"&gt;m3forth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;ARM&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Cross-compiler for Cortex-M3&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;6&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/ForthHub/cmFORTH" target="_blank" rel="noreferrer"&gt;cmFORTH&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;NC4016&lt;/td&gt;
					&lt;td&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;5&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/ForthHub/FIG-Forth" target="_blank" rel="noreferrer"&gt;FIG-Forth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;6502&lt;/td&gt;
					&lt;td&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;2&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/6809/sbc09" target="_blank" rel="noreferrer"&gt;sbc09 Forth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;6809&lt;/td&gt;
					&lt;td&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;2&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/nealcrook/multicomp6809/tree/master/camelforth" target="_blank" rel="noreferrer"&gt;CamelForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth&lt;/td&gt;
					&lt;td style="text-align: left"&gt;6809&lt;/td&gt;
					&lt;td&gt;&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;

&lt;h2 class="relative group"&gt;Forths in JavaScript and other scripted languages
 &lt;div id="forths-in-javascript-and-other-scripted-languages" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#forths-in-javascript-and-other-scripted-languages" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th style="text-align: center"&gt;:star:&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Name / Link&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Lang&lt;/th&gt;
					&lt;th style="text-align: left"&gt;CPU&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Description&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;61&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/skilldrick/easyforth" target="_blank" rel="noreferrer"&gt;Easy Forth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;JavaScript&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Small ebook for learning Forth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;4&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/hcchengithub/project-k" target="_blank" rel="noreferrer"&gt;project-k&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;JavaScript&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth kernel in JavaScript&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/doy/sonnet" target="_blank" rel="noreferrer"&gt;Sonnet&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Lua&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;forth-like language interpreter, written in lua&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/Omnifarious/forthlike" target="_blank" rel="noreferrer"&gt;forthlike&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Python&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;A very simple Forth-like language implemented in Python&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;2&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/hcchengithub/jeforth.3we" target="_blank" rel="noreferrer"&gt;jeforth.3we&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;JavaScript&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;jeforth 3 words engine&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;9&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/wolfwejgaard/tclforth" target="_blank" rel="noreferrer"&gt;TclForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Tcl/Tk&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Multi-OS Forth using Tcl as its native language&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;15&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/eatonphil/jsforth" target="_blank" rel="noreferrer"&gt;jsforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Javascript&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;A simple Forth-like language with a web-based REPL&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;

&lt;h2 class="relative group"&gt;Forths in Other Languages
 &lt;div id="forths-in-other-languages" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#forths-in-other-languages" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th style="text-align: center"&gt;:star:&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Name / Link&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Lang&lt;/th&gt;
					&lt;th style="text-align: left"&gt;CPU&lt;/th&gt;
					&lt;th style="text-align: left"&gt;Description&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;41&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/philburk/pforth" target="_blank" rel="noreferrer"&gt;pForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;C&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Portable Forth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;20&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/forthy42/gforth" target="_blank" rel="noreferrer"&gt;Gforth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;C&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Gforth mirror&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;13&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/zwizwa/staapl" target="_blank" rel="noreferrer"&gt;staapl&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Racket&lt;/td&gt;
					&lt;td style="text-align: left"&gt;PIC18&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Racket-based Forth / Macro Assembler on steroids for PIC18F&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/tcoram/uforth" target="_blank" rel="noreferrer"&gt;uForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;C&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Very portable (embeddable) switch threaded Forth&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/chengchangwu/rtforth" target="_blank" rel="noreferrer"&gt;rtForth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Rust&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Forth implemented in Rust for realtime application&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style="text-align: center"&gt;3&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;a href="https://github.com/tiluser/Creole-Forth" target="_blank" rel="noreferrer"&gt;Creole Forth&lt;/a&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Pascal&lt;/td&gt;
					&lt;td style="text-align: left"&gt;&lt;/td&gt;
					&lt;td style="text-align: left"&gt;Scripting language in the form of a Delphi/Lazarus component&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;</description></item><item><title>dpiblock</title><link>https://dominicusin.github.io/2017/11/10/dpiblock/</link><pubDate>Fri, 10 Nov 2017 16:58:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/11/10/dpiblock/</guid><description>&lt;div class="text text_html js-mediator-article" id="post_text"&gt;Провайдеры Российской Федерации, в большинстве своем, применяют системы глубокого анализа трафика (DPI, Deep Packet Inspection) для блокировки сайтов, внесенных в реестр запрещенных. Не существует единого стандарта на DPI, есть большое количество реализации от разных поставщиков DPI-решений, отличающихся по типу подключения и типу работы.&lt;br&gt;
&lt;br&gt;
Существует два распространенных типа подключения DPI: пассивный и активный.&lt;br&gt;
&lt;br&gt;
&lt;h2&gt;Пассивный DPI&lt;/h2&gt;Пассивный DPI — DPI, подключенный в провайдерскую сеть параллельно (не в разрез) либо через пассивный оптический сплиттер, либо с использованием зеркалирования исходящего от пользователей трафика. Такое подключение не замедляет скорость работы сети провайдера в случае недостаточной производительности DPI, из-за чего применяется у крупных провайдеров. DPI с таким типом подключения технически может только выявлять попытку запроса запрещенного контента, но не пресекать ее. Чтобы обойти это ограничение и заблокировать доступ на запрещенный сайт, DPI отправляет пользователю, запрашивающему заблокированный URL, специально сформированный HTTP-пакет с перенаправлением на страницу-заглушку провайдера, словно такой ответ прислал сам запрашиваемый ресурс (подделывается IP-адрес отправителя и TCP sequence). Из-за того, что DPI физически расположен ближе к пользователю, чем запрашиваемый сайт, подделанный ответ доходит до устройства пользователя быстрее, чем настоящий ответ от сайта.&lt;a name="habracut"&gt;&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;h3&gt;Выявляем и блокируем пакеты пассивного DPI&lt;/h3&gt;Поддельные пакеты, формируемые DPI, легко обнаружить анализатором трафика, например, Wireshark.&lt;br&gt;
Пробуем зайти на заблокированный сайт:&lt;br&gt;
&lt;img src="https://habrastorage.org/getpro/habr/post_images/140/ae8/4e2/140ae84e2bc2c6965f2e896ef2cc5bb6.png" alt="Wireshark"&gt;&lt;br&gt;
&lt;br&gt;
Мы видим, что сначала приходит пакет от DPI, с HTTP-перенаправлением кодом 302, а затем настоящий ответ от сайта. Ответ от сайта расценивается как ретрансмиссия и отбрасывается операционной системой. Браузер переходит по ссылке, указанной в ответе DPI, и мы видим страницу блокировки.&lt;br&gt;
&lt;br&gt;
Рассмотрим пакет от DPI подробнее:&lt;br&gt;
&lt;img src="https://habrastorage.org/getpro/habr/post_images/a59/be3/5db/a59be35dbd7c16dd386db5079d6beaea.png" alt="image"&gt;&lt;br&gt;
&lt;br&gt;
&lt;pre&gt;&lt;code&gt;HTTP/1.1 302 Found
Connection: close
Location: http://warning.rt.ru/?id=17&amp;amp;st=0&amp;amp;dt=195.82.146.214&amp;amp;rs=http%3A%2F%2Frutracker.org%2F&lt;/code&gt;&lt;/pre&gt;&lt;br&gt;
В ответе DPI не устанавливается флаг «Don't Fragment», и в поле Identification указано 1. Серверы в интернете обычно устанавливают бит «Don't Fragment», и пакеты без этого бита встречаются нечасто. Мы можем использовать это в качестве отличительной особенности пакетов от DPI, вместе с тем фактом, что такие пакеты всегда содержат HTTP-перенаправление кодом 302, и написать правило iptables, блокирующее их:&lt;br&gt;
&lt;pre&gt;&lt;code&gt;# iptables -A FORWARD -p tcp --sport 80 -m u32 --u32 "0x4=0x10000 &amp;amp;&amp;amp; 0x60=0x7761726e &amp;amp;&amp;amp; 0x64=0x696e672e &amp;amp;&amp;amp; 0x68=0x72742e72" -m comment --comment "Rostelecom HTTP" -j DROP&lt;/code&gt;&lt;/pre&gt;&lt;br&gt;
Что это такое? Модуль u32 iptables позволяет выполнять битовые операции и операции сравнения над 4-байтовыми данными в пакете. По смещению 0x4 хранится 2-байтное поле Indentification, сразу за ним идут 1-байтные поля Flags и Fragment Offset.&lt;br&gt;
Начиная со смещения 0x60 расположен домен перенаправления (HTTP-заголовок Location).&lt;br&gt;
Если Identification = 1, Flags = 0, Fragment Offset = 0, 0x60 = «warn», 0x64 = «ing.», 0x68 = «rt.ru», то отбрасываем пакет, и получаем настоящий ответ от сайта.&lt;br&gt;
&lt;br&gt;
В случае с HTTPS-сайтами, DPI присылает TCP Reset-пакет, тоже с Identification = 1 и Flags = 0.&lt;br&gt;
&lt;br&gt;
&lt;h2&gt;Активный DPI&lt;/h2&gt;Активный DPI — DPI, подключенный в сеть провайдера привычным образом, как и любое другое сетевое устройство. Провайдер настраивает маршрутизацию так, чтобы DPI получал трафик от пользователей к заблокированным IP-адресам или доменам, а DPI уже принимает решение о пропуске или блокировке трафика. Активный DPI может проверять как исходящий, так и входящий трафик, однако, если провайдер применяет DPI только для блокирования сайтов из реестра, чаще всего его настраивают на проверку только исходящего трафика.&lt;br&gt;
&lt;br&gt;
Системы DPI разработаны таким образом, чтобы обрабатывать трафик с максимально возможной скоростью, исследуя только самые популярные и игнорируя нетипичные запросы, даже если они полностью соответствуют стандарту.&lt;br&gt;
&lt;br&gt;
&lt;h3&gt;Изучаем стандарт HTTP&lt;/h3&gt;Типичные HTTP-запросы в упрощенном виде выглядят следующим образом:&lt;br&gt;
&lt;pre&gt;&lt;code&gt;GET / HTTP/1.1
Host: habrahabr.ru
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:49.0) Gecko/20100101 Firefox/50.0
Accept-Encoding: gzip, deflate, br
Connection: keep-alive&lt;/code&gt;&lt;/pre&gt;&lt;br&gt;
Запрос начинается с HTTP-метода, затем следует один пробел, после него указывается путь, затем еще один пробел, и заканчивается строка протоколом и переносом строки CRLF.&lt;br&gt;
Заголовки начинаются с большой буквы, после двоеточия ставится символ пробела.&lt;br&gt;
&lt;br&gt;
Давайте заглянем в последнюю версию стандарта HTTP/1.1 от 2014 года. Согласно RFC 7230, HTTP-заголовки не зависят от регистра символов, а после двоеточия может стоять произвольное количество пробелов (или не быть их вовсе).&lt;br&gt;
&lt;pre&gt;&lt;code&gt; Each header field consists of a case-insensitive field name followed
 by a colon (":"), optional leading whitespace, the field value, and
 optional trailing whitespace.
&lt;pre&gt;&lt;code&gt; header-field = field-name &amp;quot;:&amp;quot; OWS field-value OWS

 field-name = token
 field-value = *( field-content / obs-fold )
 field-content = field-vchar [ 1*( SP / HTAB ) field-vchar ]
 field-vchar = VCHAR / obs-text

 obs-fold = CRLF 1*( SP / HTAB )
 ; obsolete line folding&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;br&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;OWS — опциональный один или несколько символов пробела или табуляции, SP — одинарный символ пробела, HTAB — табуляция, CRLF — перенос строки и возврат каретки (\r\n).&lt;br&gt;
&lt;br&gt;
Это значит, что запрос ниже полностью соответствует стандарту, его должны принять многие веб-серверы, придерживающиеся стандарта:&lt;br&gt;&lt;/p&gt;</description></item><item><title>Some interesting links</title><link>https://dominicusin.github.io/2017/11/08/links/</link><pubDate>Wed, 08 Nov 2017 10:26:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/11/08/links/</guid><description>&lt;ol&gt;
&lt;li&gt;&lt;a href="https://blahcat.github.io/" target="_blank" rel="noreferrer"&gt;https://blahcat.github.io/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://dotfiles.github.io" target="_blank" rel="noreferrer"&gt;GitHub ❤ ~/&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bernerdschaefer/dotfiles/blob/bs-nixos/nixos/configuration.nix" target="_blank" rel="noreferrer"&gt;dwm + apple trackpad&lt;/a&gt; (&lt;a href="https://github.com/bernerdschaefer/dotfiles/blob/bs-nixos/profile.nix" target="_blank" rel="noreferrer"&gt;profile.nix&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/i-e-b/6320077" target="_blank" rel="noreferrer"&gt;xmonad&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bjornfor/nixos-config/blob/master/configuration.nix" target="_blank" rel="noreferrer"&gt;gnome3 + select variation for 2 different machines (laptop vs desktop)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Common searches
 &lt;div id="common-searches" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#common-searches" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;

&lt;h4 class="relative group"&gt;Setup
 &lt;div id="setup" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#setup" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=xmonad&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;xmonad repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=xmonad" target="_blank" rel="noreferrer"&gt;xmonad gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=xmonad" target="_blank" rel="noreferrer"&gt;xmonad #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=xmonad&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;xmonad issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=gnome3&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;gnome3 repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=gnome3" target="_blank" rel="noreferrer"&gt;gnome3 gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=gnome3" target="_blank" rel="noreferrer"&gt;gnome3 #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=gnome3&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;gnome3 issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=lightdm&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;lightdm repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=lightdm" target="_blank" rel="noreferrer"&gt;lightdm gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=lightdm" target="_blank" rel="noreferrer"&gt;lightdm #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=lightdm&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;lightdm issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=gdm&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;gdm repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=gdm" target="_blank" rel="noreferrer"&gt;gdm gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=gdm" target="_blank" rel="noreferrer"&gt;gdm #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=gdm&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;gdm issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=macbook&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;macbook repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=macbook" target="_blank" rel="noreferrer"&gt;macbook gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=macbook" target="_blank" rel="noreferrer"&gt;macbook #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=macbook&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;macbook issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=lxde&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;lxde repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=lxde" target="_blank" rel="noreferrer"&gt;lxde gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=lxde" target="_blank" rel="noreferrer"&gt;lxde #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=lxde&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;lxde issues&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Editors
 &lt;div id="editors" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#editors" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=yi&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;yi repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=yi" target="_blank" rel="noreferrer"&gt;yi gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=yi" target="_blank" rel="noreferrer"&gt;yi #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=yi&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;yi issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=vim&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;vim repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=vim" target="_blank" rel="noreferrer"&gt;vim gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=vim" target="_blank" rel="noreferrer"&gt;vim #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=vim&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;vim issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=emacs&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;emacs repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=emacs" target="_blank" rel="noreferrer"&gt;emacs gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=emacs" target="_blank" rel="noreferrer"&gt;emacs #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=emacs&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;emacs issues&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 class="relative group"&gt;Browsers
 &lt;div id="browsers" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#browsers" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=chromium&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;chromium repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=chromium" target="_blank" rel="noreferrer"&gt;chromium gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=chromium" target="_blank" rel="noreferrer"&gt;chromium #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=chromium&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;chromium issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=chrome&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;chrome repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=chrome" target="_blank" rel="noreferrer"&gt;chrome gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=chrome" target="_blank" rel="noreferrer"&gt;chrome #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=chrome&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;chrome issues&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=firefox&amp;amp;type=Code&amp;amp;utf8=%e2%9c%93" target="_blank" rel="noreferrer"&gt;firefox repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=nix&amp;amp;q=firefox" target="_blank" rel="noreferrer"&gt;firefox gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=firefox" target="_blank" rel="noreferrer"&gt;firefox #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=firefox&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;firefox issues&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h1 class="relative group"&gt;Haskell
 &lt;div id="haskell" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#haskell" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/search?l=Nix&amp;amp;q=hoogle" target="_blank" rel="noreferrer"&gt;hoogle repos&lt;/a&gt; / &lt;a href="https://gist.github.com/search?l=Nix&amp;amp;q=hoogle" target="_blank" rel="noreferrer"&gt;hoogle gists&lt;/a&gt; / &lt;a href="https://botbot.me/freenode/nixos/search/?q=hoogle" target="_blank" rel="noreferrer"&gt;hoogle #nixos&lt;/a&gt; / &lt;a href="https://github.com/NixOS/nixpkgs/search?q=hoogle&amp;amp;type=Issues" target="_blank" rel="noreferrer"&gt;hoogle issues&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h1 class="relative group"&gt;More reading
 &lt;div id="more-reading" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#more-reading" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jhedev/awesome-nix" target="_blank" rel="noreferrer"&gt;Awesome Nix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nixos.org/wiki/Cheatsheet" target="_blank" rel="noreferrer"&gt;Nix Cheatsheet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://robots.thoughtbot.com/install-linux-on-a-macbook-air#where-to-go-from-here" target="_blank" rel="noreferrer"&gt;Where to go from here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nixos.org/wiki/Install/remove_software" target="_blank" rel="noreferrer"&gt;Install/remove software&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Prepare my Windows workstation</title><link>https://dominicusin.github.io/2017/11/05/winworkstation/</link><pubDate>Sun, 05 Nov 2017 23:27:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/11/05/winworkstation/</guid><description>&lt;h1 class="relative group"&gt;Prepare my Windows workstation
 &lt;div id="prepare-my-windows-workstation" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#prepare-my-windows-workstation" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;

&lt;h2 class="relative group"&gt;Identification
 &lt;div id="identification" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#identification" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Name: HP Z210 Convertible Minitower Base Model Workstation&lt;/li&gt;
&lt;li&gt;Model #: XM856AV&lt;/li&gt;
&lt;li&gt;Serial #: CZC13941PV&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Windows 10 &amp;ldquo;Light&amp;rdquo;
 &lt;div id="windows-10-light" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#windows-10-light" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://www.microsoft.com/en-us/software-download/windows10" target="_blank" rel="noreferrer"&gt;Download Windows 10 ISO tool from Microsoft&lt;/a&gt;&lt;/p&gt;</description></item><item><title>nedaigne</title><link>https://dominicusin.github.io/2017/08/31/nedaigne/</link><pubDate>Thu, 31 Aug 2017 14:04:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/08/31/nedaigne/</guid><description>&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/77283/" target="_blank" rel="noreferrer"&gt;Тот самый Мюнхгаузен&lt;/a&gt; (1979)10&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/77282/" target="_blank" rel="noreferrer"&gt;Обыкновенное чудо&lt;/a&gt; (1978)10&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/432763/" target="_blank" rel="noreferrer"&gt;Концерт&lt;/a&gt; (2009)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/77249/" target="_blank" rel="noreferrer"&gt;Благочестивая Марта&lt;/a&gt; (1980)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/46225/" target="_blank" rel="noreferrer"&gt;Бриллиантовая рука&lt;/a&gt; (1968)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/42819/" target="_blank" rel="noreferrer"&gt;Осторожно, бабушка!&lt;/a&gt; (1961)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/42664/" target="_blank" rel="noreferrer"&gt;Иван Васильевич меняет профессию&lt;/a&gt; (1973)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/46592/" target="_blank" rel="noreferrer"&gt;Медведь&lt;/a&gt; (1938)9&lt;/p&gt;</description></item><item><title>imhonet is dead</title><link>https://dominicusin.github.io/2017/08/10/imhonet/</link><pubDate>Thu, 10 Aug 2017 00:03:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/08/10/imhonet/</guid><description>&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/2702/" target="_blank" rel="noreferrer"&gt;Враг мой&lt;/a&gt;(1985)10&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/60285/" target="_blank" rel="noreferrer"&gt;Боги наверное сошли с ума&lt;/a&gt;(1980)10&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/376448/" target="_blank" rel="noreferrer"&gt;Футурама: В дикую зеленую даль&lt;/a&gt;(2009)10&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/1827/" target="_blank" rel="noreferrer"&gt;Другие ипостаси&lt;/a&gt;(1980)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/447/" target="_blank" rel="noreferrer"&gt;Звездные войны: Эпизод 6 - Возвращение Джедая&lt;/a&gt;(1983)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/682669/" target="_blank" rel="noreferrer"&gt;Малавита&lt;/a&gt;(2013)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.kinopoisk.ru/film/679924/" target="_blank" rel="noreferrer"&gt;Патруль времени&lt;/a&gt;(2013)9&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/251733/" target="_blank" rel="noreferrer"&gt;Аватар&lt;/a&gt;(2009)9&lt;/p&gt;</description></item><item><title>Migrate a code repository from SourceForge (SVN) to Github (GIT)</title><link>https://dominicusin.github.io/2017/07/28/svn2git/</link><pubDate>Fri, 28 Jul 2017 17:29:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/07/28/svn2git/</guid><description>&lt;h1 class="relative group"&gt;Migrate a code repository from SourceForge (SVN) to Github (GIT)
 &lt;div id="migrate-a-code-repository-from-sourceforge-svn-to-github-git" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#migrate-a-code-repository-from-sourceforge-svn-to-github-git" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;To do a migration you will need a system that allows you to install Ruby, Ruby Gems and Git. We are running the entire process on a CentOS 6 box (YMMV).&lt;/p&gt;</description></item><item><title>Free Programming Books</title><link>https://dominicusin.github.io/2017/06/15/free-programming-books/</link><pubDate>Thu, 15 Jun 2017 16:49:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/06/15/free-programming-books/</guid><description>&lt;p&gt;###Index&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#meta-lists" &gt;Списки книг&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#language-agnostic" &gt;Language Agnostic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#bash" &gt;Bash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#coffeescript" &gt;CoffeeScript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#git" &gt;Git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#javascript" &gt;JavaScript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#latex" &gt;LaTeX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#lisp" &gt;Lisp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#metapost" &gt;MetaPost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#node.js" &gt;Node.js&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#nosql" &gt;NoSQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#perl" &gt;Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#r" &gt;R&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#ruby" &gt;Ruby&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#rspec" &gt;RSpec&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#ruby-on-rails" &gt;Ruby on Rails&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#scilab" &gt;Scilab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#sql" &gt;SQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dominicusin.github.io/2017/06/15/free-programming-books/#parallel" &gt;Параллельные технологии&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;###Language Agnostic&lt;/p&gt;</description></item><item><title>OnionShare</title><link>https://dominicusin.github.io/2017/06/07/onionshare/</link><pubDate>Wed, 07 Jun 2017 17:02:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/06/07/onionshare/</guid><description>&lt;h1 class="relative group"&gt;OnionShare
 &lt;div id="onionshare" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#onionshare" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;&lt;a href="https://travis-ci.org/micahflee/onionshare" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Build Status"
 src="https://travis-ci.org/micahflee/onionshare.png"
 &gt;&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;OnionShare lets you securely and anonymously share files of any size. It works by starting a web server, making it accessible as a Tor onion service, and generating an unguessable URL to access and download the files. It doesn&amp;rsquo;t require setting up a server on the internet somewhere or using a third party file-sharing service. You host the file on your own computer and use a Tor onion service to make it temporarily accessible over the internet. The other user just needs to use Tor Browser to download the file from you.&lt;/p&gt;</description></item><item><title>Linux System Administrator(DevOp) Interview Questions</title><link>https://dominicusin.github.io/2017/05/28/interview/</link><pubDate>Sun, 28 May 2017 22:03:00 +0000</pubDate><guid>https://dominicusin.github.io/2017/05/28/interview/</guid><description>&lt;h1 class="relative group"&gt;Linux System Administrator/DevOp Interview Questions
 &lt;div id="linux-system-administratordevop-interview-questions" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#linux-system-administratordevop-interview-questions" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;A collection of linux sysadmin/devop interview questions. Feel free to contribute via pull requests, issues or email messages.&lt;/p&gt;</description></item><item><title>Curriculum Vitae</title><link>https://dominicusin.github.io/2016/12/01/rieziumie/</link><pubDate>Thu, 01 Dec 2016 08:32:00 +0000</pubDate><guid>https://dominicusin.github.io/2016/12/01/rieziumie/</guid><description>&lt;h1 class="relative group"&gt;Domini
 &lt;div id="domini" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#domini" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;

&lt;h2 class="relative group"&gt;SKILLS
 &lt;div id="skills" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#skills" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;System administrator, technical support engineer: Unix FreeBSD Linux Solaris Open Source Software&lt;/p&gt;</description></item><item><title>List of favourite movies</title><link>https://dominicusin.github.io/2016/11/22/second/</link><pubDate>Tue, 22 Nov 2016 02:25:00 +0000</pubDate><guid>https://dominicusin.github.io/2016/11/22/second/</guid><description>&lt;h1 class="relative group"&gt;&lt;strong&gt;комедии&lt;/strong&gt;
 &lt;div id="комедии" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#%d0%ba%d0%be%d0%bc%d0%b5%d0%b4%d0%b8%d0%b8" aria-label="Якорь"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/820220/" target="_blank" rel="noreferrer"&gt; !!Cюрприз / De Surprise &lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/55057/" target="_blank" rel="noreferrer"&gt;La totale! &lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="http://www.kinopoisk.ru/film/60285/" target="_blank" rel="noreferrer"&gt;боги сошли с ума &lt;/a&gt;&lt;a href="http://www.kinopoisk.ru/film/182416/" target="_blank" rel="noreferrer"&gt;http://www.kinopoisk.ru/film/182416/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>First post</title><link>https://dominicusin.github.io/2015/11/19/first/</link><pubDate>Thu, 19 Nov 2015 01:41:00 +0000</pubDate><guid>https://dominicusin.github.io/2015/11/19/first/</guid><description>&lt;p&gt;Domini&amp;rsquo;s Simple Blog&lt;/p&gt;
&lt;p&gt;Hello everyone, I&amp;rsquo;m dominicusin l&amp;rsquo;esprit de mort Which way did the extinguished fire go? Honi soit qui mal y pens herzlich willkommen bei सच्चिदानंद Activity: ♡ umbra mortis ♧ Temet Nosce ♢ Hic locus est, ubi mors gaudet succurrere vitae ♤ Separabis terram ab igne, subtile a spisso, suaviter mango cum inqenio Interests: commedia dell&amp;rsquo;arte, triathlon, burning hearts with a soldering iron on a cake, guilloche The favorite music: Wu-Tang Clan&lt;/p&gt;</description></item><item><title>404</title><link>https://dominicusin.github.io/404/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://dominicusin.github.io/404/</guid><description/></item><item><title>About</title><link>https://dominicusin.github.io/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://dominicusin.github.io/about/</guid><description>&lt;div class="about-container"&gt;
 &lt;div class="about-hero"&gt;
 &lt;div class="about-avatar"&gt;
 &lt;img src="https://dominicusin.github.io/assets/images/avatar.jpg" alt="Dominicus In" class="avatar-image" /&gt;
 &lt;div class="avatar-placeholder"&gt;
 &lt;span class="avatar-initials"&gt;DI&lt;/span&gt;
 &lt;/div&gt;
 &lt;/div&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;div class=&amp;quot;about-header-content&amp;quot;&amp;gt;
 &amp;lt;h1 class=&amp;quot;about-title&amp;quot;&amp;gt;Dominicus In&amp;lt;/h1&amp;gt;
 &amp;lt;p class=&amp;quot;about-subtitle&amp;quot;&amp;gt;Industrial &amp;amp; Systems Engineer&amp;lt;/p&amp;gt;
 &amp;lt;p class=&amp;quot;about-description&amp;quot;&amp;gt;
 Passionate about optimizing complex systems, data-driven decision making, and building scalable engineering solutions. 
 Specializing in industrial automation, process optimization, and systems integration.
 &amp;lt;/p&amp;gt;
 
 &amp;lt;div class=&amp;quot;about-social&amp;quot;&amp;gt;
 &amp;lt;a href=&amp;quot;https://github.com/dominicusin&amp;quot; class=&amp;quot;social-link&amp;quot; target=&amp;quot;_blank&amp;quot; rel=&amp;quot;noopener&amp;quot;&amp;gt;
 &amp;lt;span class=&amp;quot;social-icon&amp;quot;&amp;gt;📦&amp;lt;/span&amp;gt;
 &amp;lt;span class=&amp;quot;social-text&amp;quot;&amp;gt;GitHub&amp;lt;/span&amp;gt;
 &amp;lt;/a&amp;gt;
 &amp;lt;a href=&amp;quot;https://linkedin.com/in/dominicusin&amp;quot; class=&amp;quot;social-link&amp;quot; target=&amp;quot;_blank&amp;quot; rel=&amp;quot;noopener&amp;quot;&amp;gt;
 &amp;lt;span class=&amp;quot;social-icon&amp;quot;&amp;gt;💼&amp;lt;/span&amp;gt;
 &amp;lt;span class=&amp;quot;social-text&amp;quot;&amp;gt;LinkedIn&amp;lt;/span&amp;gt;
 &amp;lt;/a&amp;gt;
 &amp;lt;a href=&amp;quot;https://twitter.com/dominicusin&amp;quot; class=&amp;quot;social-link&amp;quot; target=&amp;quot;_blank&amp;quot; rel=&amp;quot;noopener&amp;quot;&amp;gt;
 &amp;lt;span class=&amp;quot;social-icon&amp;quot;&amp;gt;🐦&amp;lt;/span&amp;gt;
 &amp;lt;span class=&amp;quot;social-text&amp;quot;&amp;gt;Twitter&amp;lt;/span&amp;gt;
 &amp;lt;/a&amp;gt;
 &amp;lt;a href=&amp;quot;mailto:contact@dominicu_sin.io&amp;quot; class=&amp;quot;social-link&amp;quot;&amp;gt;
 &amp;lt;span class=&amp;quot;social-icon&amp;quot;&amp;gt;📧&amp;lt;/span&amp;gt;
 &amp;lt;span class=&amp;quot;social-text&amp;quot;&amp;gt;Email&amp;lt;/span&amp;gt;
 &amp;lt;/a&amp;gt;
 &amp;lt;/div&amp;gt;
&amp;lt;/div&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
 &lt;/div&gt;
 &lt;div class="about-content"&gt;
 &lt;section class="about-section"&gt;
 &lt;h2 class="section-title"&gt;Professional Background&lt;/h2&gt;
 &lt;div class="experience-timeline"&gt;
 &lt;div class="timeline-item"&gt;
 &lt;div class="timeline-date"&gt;2022 - Present&lt;/div&gt;
 &lt;div class="timeline-content"&gt;
 &lt;h3&gt;Senior Systems Engineer&lt;/h3&gt;
 &lt;p&gt;Leading complex industrial automation projects and implementing cutting-edge optimization strategies for manufacturing processes.&lt;/p&gt;</description></item></channel></rss>