CVE Database

CVE-2019-15657CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.

CVE-2015-9344CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The link-log plugin before 2.1 for WordPress has SQL injection.

CVE-2016-10935CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

CVE-2018-21003CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The buddyforms plugin before 2.2.8 for WordPress has SQL injection.

CVE-2018-21004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.

CVE-2018-21005CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.

CVE-2019-15646CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The rsvpmaker plugin before 6.2 for WordPress has SQL injection.

CVE-2019-14314CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

CVE-2019-13273CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.

CVE-2019-13451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

CVE-2019-13452CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

CVE-2019-13455CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in acknowledge.c.

CVE-2019-13484CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.

CVE-2019-13485CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.

CVE-2019-13486CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.

CVE-2012-6719CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The sharebar plugin before 1.2.2 for WordPress has SQL injection.

CVE-2019-15294CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-532

An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file.

CVE-2019-15783CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.

CVE-2019-9930CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Various Lexmark products have an Integer Overflow.

CVE-2019-9932CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Various Lexmark products have a Buffer Overflow (issue 2 of 3).

CVE-2019-9933CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Various Lexmark products have a Buffer Overflow (issue 3 of 3).

CVE-2018-21007CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.

CVE-2019-14943CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVE-2019-11064CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.

CVE-2019-13405CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

CVE-2019-15780CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

CVE-2019-15784CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.

CVE-2019-15785CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

CVE-2019-15786CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.

CVE-2019-15788CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.

CVE-2019-11500CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

CVE-2019-15717CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.

CVE-2019-15805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-326

CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can exploit this.

CVE-2019-15806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-326

CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi can exploit this.

CVE-2019-5608CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A remote attacker may be able to cause an out-of-bounds read or write that may cause the kernel to attempt to access an unmapped page and subsequently panic.

CVE-2019-15819CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.

CVE-2019-15822CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.

CVE-2019-15823CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.

CVE-2019-15824CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.

CVE-2019-15825CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.

CVE-2019-15826CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.

CVE-2019-13188CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

CVE-2019-13976CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

eGain Chat 15.0.3 allows unrestricted file upload.

CVE-2019-13187CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.

CVE-2019-1976CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to access running configuration information about devices managed by the IND, including administrative credentials.

CVE-2019-15937CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.

CVE-2019-15938CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.

CVE-2018-11569CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.

CVE-2019-14222CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g., OS type, system file locations, Java version, Solr version, etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco's Solr Web Admin Interface.

CVE-2019-15846CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

← PreviousPage 320 / 7034Next →