CVE Database

CVE-2016-10954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

CVE-2016-10942CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

CVE-2010-5333CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution. An SEH-overwrite buffer overflow already existed for the vulnerable software. This CVE is to track an alternate exploitation method, utilizing an EIP-overwrite buffer overflow.

CVE-2018-7081CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute arbitrary code within the underlying operating system with full system privileges. Such an attack could lead to complete system compromise. The ability to transmit traffic to an IP interface on the mobility controller is required to carry out an attack. The attack leverages the PAPI protocol (UDP port 8211). If the mobility controller is only bridging L2 traffic to an uplink and does not have an IP address that is accessible to the attacker, it cannot be attacked.

CVE-2019-13548CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.

CVE-2019-13918CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The vulnerability could allow full access to the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE-2019-16303CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-338

A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.

CVE-2019-16309CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.

CVE-2019-14540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

CVE-2019-16335CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

CVE-2017-18634CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

CVE-2019-13474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands.

CVE-2019-16057KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.75%
Priority 70

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

CVE-2016-10971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.

CVE-2019-0195CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the webapp's AppModule class, the value of this symbol could be used to craft a Java deserialization attack, thus running malicious injected Java code. The vector would be the t:formdata parameter from the Form component.

CVE-2016-10972CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

CVE-2019-16366CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.

CVE-2019-10071CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-203

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the correct signature for their payload. The comparison should be done with a constant time algorithm instead.

CVE-2019-15741CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation

CVE-2019-5481CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVE-2019-5482CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

CVE-2019-15131CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerability could allow an attacker to create directories and save files on Code42 servers, which could potentially lead to code execution.

CVE-2019-16239CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.

CVE-2019-16378CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-290

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.

CVE-2018-7820CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-255

A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.

CVE-2019-6840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed.

CVE-2019-16199CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.

CVE-2016-10995CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.

CVE-2019-14254CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwords and/or grant access to the user account "user" in order to become "Administrator" (for example).

CVE-2019-15301CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.

CVE-2019-9677CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.

CVE-2019-13550CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution or cause a system crash.

CVE-2019-5066CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free condition. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

CVE-2019-5067CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

CVE-2019-13558CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.

CVE-2019-3758CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.

CVE-2019-3689CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVE-2019-15000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from 6.5.0 before 6.5.2 (the fixed version for 6.5.x) allows remote attackers who have permission to access a repository, if public access is enabled for a project or repository then attackers are able to exploit this issue anonymously, to read the contents of arbitrary files on the system and execute commands via injecting additional arguments into git commands.

CVE-2019-15088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.

CVE-2016-11000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

CVE-2019-16642CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.

CVE-2019-16644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.

CVE-2019-16656CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.

CVE-2018-21018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

CVE-2019-16694CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

CVE-2019-16695CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.

CVE-2019-16696CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.

CVE-2019-16722CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.

CVE-2019-3416CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.

CVE-2019-5504CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.

← PreviousPage 322 / 7034Next →