CVE Database

CVE-2019-13107CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c

CVE-2019-5497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.

CVE-2019-4336CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.

CVE-2019-13131CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

CVE-2025-11405CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was identified in SourceCodester Hotel and Lodge Management System 1.0. This vulnerability affects unknown code of the file /del_tax.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

CVE-2019-7667CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this issue to download the database file and disclose login information, which can allow the attacker to bypass authentication and have full access to the system.

CVE-2019-7668CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

Prima Systems FlexAir devices have Default Credentials.

CVE-2025-11403CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknown functionality of the file /del_booking.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

CVE-2025-52021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization.

CVE-2019-10979CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

CVE-2019-7271CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

Nortek Linear eMerge 50P/5000P devices have Default Credentials.

CVE-2025-11401CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /pages/save_curr.php. This manipulation of the argument currcode causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVE-2025-11400CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /del_room.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

CVE-2025-11397CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipulation of the argument email results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVE-2019-4087CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and execute arbitrary code on the system with instance id privileges or cause the server or storage agent to crash. IBM X-Force ID: 157510.

CVE-2017-8408CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the GET parameters passed in this request (to test if SMB credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramfs-root archive which contains the filesystem set up on the device that contains all the binaries. The binary "cgibox" is the one that has the vulnerable function "sub_7EAFC" that receives the values sent by the GET request. If we open this binary in IDA-pro we will notice that this follows a ARM little endian format. The function sub_7EAFC in IDA pro is identified to be receiving the values sent in the GET request and the value set in GET parameter "user" is extracted in function sub_7E49C which is then passed to the vulnerable system API call.

CVE-2019-12594CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

DOSBox 0.74-2 has Incorrect Access Control.

CVE-2019-7263CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-18

Linear eMerge E3-Series devices have a Version Control Failure.

CVE-2019-7264CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.

CVE-2025-11396CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

CVE-2019-7266CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-565

Linear eMerge 50P/5000P devices allow Authentication Bypass.

CVE-2019-7267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Linear eMerge 50P/5000P devices allow Cookie Path Traversal.

CVE-2025-0603CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0.

CVE-2019-7260CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

CVE-2019-7261CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Linear eMerge E3-Series devices have Hard-coded Credentials.

CVE-2017-8404CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramfs-root archive which contains the filesystem set up on the device that contains all the binaries. The library "libmailutils.so" is the one that has the vulnerable function "sub_1FC4" that receives the values sent by the POST request. If we open this binary in IDA-pro we will notice that this follows an ARM little endian format. The function sub_1FC4 in IDA pro is identified to be receiving the values sent in the POST request and the value set in POST parameter "receiver1" is extracted in function "sub_15AC" which is then passed to the vulnerable system API call. The vulnerable library function is accessed in "cgibox" binary at address 0x0008F598 which calls the "mailLoginTest" function in "libmailutils.so" binary as shown below which results in the vulnerable POST parameter being passed to the library which results in the command injection issue.

CVE-2018-11420CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a different vulnerability than CVE-2018-11423.

CVE-2019-7252CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

Linear eMerge E3-Series devices have Default Credentials.

CVE-2019-7253CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Linear eMerge E3-Series devices allow Directory Traversal.

CVE-2025-11354CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Executing manipulation of the argument image can lead to unrestricted upload. The attack may be performed from remote. The exploit has been published and may be used.

CVE-2025-11350CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. The affected element is an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CVE-2025-11349CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

CVE-2025-11348CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2018-11421CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-319

Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. The protocol is vulnerable to remote unauthenticated disclosure of sensitive information, including the administrator's password. Under certain conditions, it's also possible to retrieve additional information, such as content of HTTP requests to the device, or the previously used password, due to memory leakages.

CVE-2017-8410CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary performs a memcpy operation at address 0x00011E34 with the value sent in the "Authorization: Basic" RTSP header and stores it on the stack. The number of bytes to be copied are calculated based on the length of the string sent in the RTSP header by the client. As a result, memcpy copies more data then it can hold on stack and this results in corrupting the registers for the caller function sub_F6CC which results in memory corruption. The severity of this attack is enlarged by the fact that the same value is then copied on the stack in the function 0x00011378 and this allows to overflow the buffer allocated and thus control the PC register which will result in arbitrary code execution on the device.

CVE-2017-8415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string "admin" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.

CVE-2019-13177CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.

CVE-2018-11426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web interface to use all its functions except for password change.

CVE-2018-11422CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-319

Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. Any commands (including device reboot, configuration download or upload, or firmware upgrade) are accepted and executed by the device without authentication.

CVE-2018-11425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424.

CVE-2017-18346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.

CVE-2017-6900CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-255

An issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python script used for authentication. When calling wrongpass, the variables $VAL0 and $VAL1 should be enclosed in quotes to prevent the potential for Bash command injection. Further to this, VAL0 and VAL1 should be sanitised to ensure they do not contain malicious characters. Passing it the username of '-' will cause it to time out and log the user in because of poor error handling. This will log the attacker in as an administrator where the telnet / ssh services can be enabled, and the credentials for local users can be reset. Also, login.cgi accepts the username as a GET parameter, so login can be achieved by browsing to the /cgi-bin/login.cgi?username=-%20a URI.

CVE-2025-11347CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Student Page. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been made public and could be used.

CVE-2019-13207CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.

CVE-2025-11346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 is able to mitigate this issue. It is advisable to upgrade the affected component.

CVE-2015-3907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.

CVE-2019-10100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.

CVE-2019-7165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.

CVE-2019-10104CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

CVE-2019-12850CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.

← PreviousPage 311 / 7034Next →