CVE Database

CVE-2019-11536CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires network connectivity to the device and exploits the webserver interface, typically through a browser.

CVE-2019-7832CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7833CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7834CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7835CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2017-5863CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

CVE-2018-7842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-290

A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.

CVE-2018-7846CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.

CVE-2018-6604CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request.

CVE-2018-7847CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.

CVE-2018-11215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.

CVE-2019-6808CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.

CVE-2019-11873CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length, client hello length, total extensions length, PSK extension length, total identity length, and identity length contain their maximum value which is 2^16. The identity data field of the PSK extension of the packet contains the attack data, to be stored in the undefined memory (RAM) of the server. The size of the data is about 65 kB. Possibly the attacker can perform a remote code execution attack.

CVE-2019-12042CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.

CVE-2019-12297CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080.

CVE-2017-17060CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-275

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.

CVE-2017-5210CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.

CVE-2017-5212CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.

CVE-2019-12272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

CVE-2019-7130CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution.

CVE-2019-12300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

CVE-2016-8899CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.

CVE-2019-12301CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed in 5.6.44-85.0-2.

CVE-2019-7104CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7106CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7107CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

CVE-2019-7088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7098CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7099CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7101CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7102CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7103CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7112CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2016-8901CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.

CVE-2017-11365CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

CVE-2019-12288CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.

CVE-2019-12289CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files within the internal firmware or even steal account information by executing a command.

CVE-2019-7117CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7118CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7119CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7124CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-7128CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2016-8897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.

CVE-2025-11513CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/supplier_update.php. This manipulation of the argument supp_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2025-11509CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was detected in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/product_add.php. Performing manipulation of the argument prod_name results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

← PreviousPage 305 / 7034Next →