CVE Database

CVE-2019-15536CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.

CVE-2019-15537CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.

CVE-2019-1580CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.

CVE-2019-1581CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.

CVE-2019-6698CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.

CVE-2019-15566CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.

CVE-2019-6695CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.

CVE-2019-15534CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.

CVE-2019-15567CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.

CVE-2019-15563CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.

CVE-2019-15564CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.

CVE-2019-15521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.

CVE-2019-15524CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI.

CVE-2019-15556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.

CVE-2019-15561CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.

CVE-2019-15562CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm

CVE-2019-15565CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.

CVE-2019-14308CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via crafted requests to the LPD service. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

CVE-2018-20991CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free.

CVE-2018-21000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong order, causing heap memory corruption.

CVE-2019-14300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execution via crafted requests to the web server. Affected firmware versions depend on the printer models. One affected configuration is cpe:2.3:o:ricoh:sp_c250dn_firmware:-:*:*:*:*:*:*:* up to (including) 1.06 running on cpe:2.3:o:ricoh:sp_c250dn:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252dn:-:*:*:*:*:*:*:*. Another affected configuration is cpe:2.3:o:ricoh:sp_c250sf_firmware:-:*:*:*:*:*:*:* up to (including) 1.12 running on cpe:2.3:o:ricoh:sp_c250sf:-:*:*:*:*:*:*:*, cpe:2.3:o:ricoh:sp_c252sf:-:*:*:*:*:*:*:*.

CVE-2019-15551CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.

CVE-2019-15552CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.

CVE-2019-15554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.

CVE-2019-15559CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

DianoxDragon Hawn before 2019-07-10 allows SQL injection.

CVE-2019-15560CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

CVE-2018-20995CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.

CVE-2018-20996CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.

CVE-2018-20997CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.

CVE-2018-20998CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.

CVE-2019-15503CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.

CVE-2019-15533CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.

CVE-2019-15543CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases.

CVE-2019-7968CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7969CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7970CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7972CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7973CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7974CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7975CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7990CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7992CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7993CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7997CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-7998CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-8001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-9569CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors.

CVE-2019-15497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

CVE-2019-15651CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex.

← PreviousPage 319 / 7034Next →