CVE Database

CVE-2019-15111CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.

CVE-2019-7965CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8003CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8006CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8015CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8023CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8026CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8028CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8029CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8030CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8031CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8036CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8047CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2016-10909CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.

CVE-2019-8060CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8061CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8098CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-8100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2014-10379CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The duplicate-post plugin before 2.6 for WordPress has SQL injection.

CVE-2015-9333CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The cforms2 plugin before 14.6.10 for WordPress has SQL injection.

CVE-2019-1938CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.

CVE-2019-1974CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to gain full administrative access to the affected device.

CVE-2019-10687CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.

CVE-2019-6177CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Lenovo Vantage or Lenovo Diagnostics in April 2018.

CVE-2016-10921CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.

CVE-2017-18570CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

CVE-2017-18571CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.

CVE-2017-18573CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.

CVE-2018-20979CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.

CVE-2019-15318CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

CVE-2014-10383CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.

CVE-2014-10384CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.

CVE-2016-10922CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

CVE-2019-11030CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.

CVE-2019-11031CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.

CVE-2014-10387CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

CVE-2014-10389CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

CVE-2013-7483CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

CVE-2015-9334CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The email-newsletter plugin through 20.15 for WordPress has SQL injection.

CVE-2018-20987CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.

CVE-2019-15504CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).

CVE-2019-15505CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).

CVE-2019-10746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVE-2019-10747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-400

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

CVE-2019-10750CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-400

deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.

CVE-2019-15535CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.

← PreviousPage 318 / 7034Next →