CVE Database

CVE-2019-13957CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.

CVE-2018-10103CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).

CVE-2018-10105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).

CVE-2019-17113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.

CVE-2019-17133CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.

CVE-2019-16891CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

CVE-2019-17184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.

CVE-2019-17192CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-670

The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs

CVE-2019-17197CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.

CVE-2019-17206CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.

CVE-2019-17215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the device.

CVE-2019-17216CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-916

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort.

CVE-2019-15748CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM package that includes a PHP file, which could execute arbitrary PHP code.

CVE-2019-17266CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

CVE-2019-17267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

CVE-2019-17269CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.

CVE-2019-15746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.

CVE-2019-15751CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to the web root of the application.

CVE-2015-9450CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter.

CVE-2015-9451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.

CVE-2015-9452CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.

CVE-2019-12811CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method. This can be leveraged for code execution

CVE-2019-12812CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leveraged for code execution.

CVE-2019-17041CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMsg will reach the value zero and will skip the sanity check that detects invalid log messages. The message will then be considered valid, and the parser will eat up the nonexistent colon delimiter. In doing so, it will decrement lenMsg, a signed integer, whose value was zero and now becomes minus one. The following step in the parser is to shift left the contents of the message. To do this, it will call memmove with the right pointers to the target and destination strings, but the lenMsg will now be interpreted as a huge value, causing a heap overflow.

CVE-2019-17042CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMsg will reach the value zero and will skip the sanity check that detects invalid log messages. The message will then be considered valid, and the parser will eat up the nonexistent colon delimiter. In doing so, it will decrement lenMsg, a signed integer, whose value was zero and now becomes minus one. The following step in the parser is to shift left the contents of the message. To do this, it will call memmove with the right pointers to the target and destination strings, but the lenMsg will now be interpreted as a huge value, causing a heap overflow.

CVE-2018-21025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.

CVE-2019-13336CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE: the vendor's position is that this product reached end of life in 2016.

CVE-2019-10757CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.

CVE-2018-21024CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

CVE-2019-3980CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-346

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

CVE-2019-17373CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.

CVE-2019-15859CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

CVE-2019-17383CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.

CVE-2019-17399CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.

CVE-2019-15020CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-346

A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.

CVE-2019-9535CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-349

A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an attacker to execute arbitrary commands on their victim's computer by providing malicious output to the terminal. It could be exploited using command-line utilities that print attacker-controlled content.

CVE-2019-15019CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector.

CVE-2019-1584CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint.

CVE-2019-17415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331.

CVE-2019-17072CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.

CVE-2019-17429CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.

CVE-2015-9479CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.

CVE-2019-17320CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

CVE-2015-9466CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.

CVE-2015-9467CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.

CVE-2015-9471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

CVE-2019-17455CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

CVE-2019-11526CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

CVE-2019-9531CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide unauthenticated, shell-like access to the device.

CVE-2019-9533CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.

← PreviousPage 324 / 7034Next →