CVE Database

CVE-2025-11423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

CVE-2018-15506CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running BubbleUPnP, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack the cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

CVE-2018-17393CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.

CVE-2018-17398CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.

CVE-2018-16613CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.

CVE-2018-16618CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.

CVE-2018-17148CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

CVE-2018-17374CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.

CVE-2018-17381CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

CVE-2018-17386CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

CVE-2019-2006CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-362

In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-116665972

CVE-2019-2007CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-120789744

CVE-2025-11422CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability has been found in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unknown function of the file /admin/login.php. Such manipulation of the argument Username leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11420CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was detected in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/edit_order_details.php. The manipulation of the argument order_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

CVE-2018-15890CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.

CVE-2025-11418CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2019-8459CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-428

Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

CVE-2019-12920CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.

CVE-2016-7404CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

CVE-2018-15747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system within a "python" "files" "content" JSON file.

CVE-2018-15868CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.

CVE-2019-11011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Akamai CloudTest before 58.30 allows remote code execution.

CVE-2019-12928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is meant to be used by trusted users. If one is able to access this interface via a tcp socket open to the internet, then it is an insecure configuration issue

CVE-2019-12929CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is meant to be used by trusted users. If one is able to access this interface via a tcp socket open to the internet, then it is an insecure configuration issue

CVE-2019-12939CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.

CVE-2019-12960CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.

CVE-2019-12951CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.

CVE-2019-12966CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.

CVE-2019-6167CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

CVE-2019-6168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

CVE-2019-9039CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. The _all_docs endpoint is not required for Couchbase Mobile replication and external access to this REST endpoint has been blocked to mitigate this issue. This issue has been fixed in versions 2.5.0 and 2.1.3.

CVE-2025-11416CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/invoices.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVE-2025-11415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/customer-list.php. Such manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVE-2018-15556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.

CVE-2025-11408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2018-20810CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-326

Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

CVE-2018-15555CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-662

On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.

CVE-2018-15520CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Various Lexmark devices have a Buffer Overflow (issue 2 of 2).

CVE-2018-15519CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Various Lexmark devices have a Buffer Overflow (issue 1 of 2).

CVE-2018-14885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.

CVE-2018-20813CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.

CVE-2019-10989CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. Note: A different vulnerability than CVE-2019-10991.

CVE-2019-10991CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.

CVE-2019-10993CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code.

CVE-2019-13067CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

CVE-2025-11407CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVE-2019-11821CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.

CVE-2019-11829CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.

CVE-2019-13082CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.

CVE-2019-13086CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

← PreviousPage 310 / 7034Next →