CVE Database

CVE-2025-11555CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument date_start results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

CVE-2018-17181CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

CVE-2019-12206CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.

CVE-2019-12207CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.

CVE-2019-0725CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

CVE-2019-12208CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c.

CVE-2025-11551CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file src/students/Database.java. This manipulation of the argument roll/name/gpa causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2019-10910CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVE-2019-10913CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-79

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.

CVE-2025-11549CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVE-2018-17179CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.

CVE-2019-0153CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-0172CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.

CVE-2019-5953CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

CVE-2019-11887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.

CVE-2019-12158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension.

CVE-2019-12160CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

GoHTTP through 2017-07-25 has a sendHeader use-after-free.

CVE-2018-6605CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

CVE-2019-12241CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.

CVE-2019-12240CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.

CVE-2025-11522CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, when Facebook login is enabled. CVE-2025-62064 is likely a duplicate of this CVE.

CVE-2019-7765CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7762CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7763CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7764CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-12898CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.

CVE-2019-7766CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7767CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7768CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7772CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7779CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7781CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7782CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7783CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7784CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7788CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7791CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-12277CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.

CVE-2019-7792CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7804CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-12899CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.

CVE-2019-12046CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

LemonLDAP::NG -2.0.3 has Incorrect Access Control.

CVE-2025-7526CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

CVE-2019-7805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7807CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7808CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-11634KEVCRITICALin_the_wild
CVSS 9.8
EPSS 31.16%
Priority 70

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

CVE-2019-12900CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

CVE-2025-11529CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 3a1cffd2aea63d884025949cfbcfd274d06216a4. A patch should be applied to remediate this issue.

← PreviousPage 304 / 7034Next →