CVE Database

CVE-2011-1933CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Jifty::DBI before 0.68.

CVE-2019-14896CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.

CVE-2019-18184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

CVE-2019-19330CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

CVE-2011-2717CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.

CVE-2019-14895CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.

CVE-2019-14897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.

CVE-2019-14901CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.

CVE-2019-12392CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Anviz access control devices allow remote attackers to issue commands without a password.

CVE-2019-18609CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

CVE-2019-15631CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

CVE-2019-19492CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

CVE-2019-19502CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.

CVE-2019-12503CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.

CVE-2019-19015CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the appliance. By connecting to the database through the proxy (without password authentication), an attacker is able to fully control the appliance database. Through this, several different paths exist to gain further access, or execute code.

CVE-2019-19021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.

CVE-2013-4486CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

CVE-2019-16885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via the cookie comparison.

CVE-2019-19459CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

CVE-2019-5096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.

CVE-2013-2095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection

CVE-2018-0729CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.

CVE-2018-0730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-11930CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-763

An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

CVE-2019-11934CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

CVE-2019-11935CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

CVE-2019-11936CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-626

Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

CVE-2019-11940CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.

CVE-2019-17556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.

CVE-2019-19228CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-312

Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.

CVE-2013-2745CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

CVE-2013-2159CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Monkey HTTP Daemon: broken user name authentication

CVE-2019-19521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

CVE-2019-19589CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-436

The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder.

CVE-2019-19317CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-681

lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.

CVE-2019-14910CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

CVE-2019-19594CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.

CVE-2019-19595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

CVE-2019-7183CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-59

This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7192KEVCRITICALin_the_wild
CVSS 9.8
EPSS 94.30%
Priority 70

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7193KEVCRITICALin_the_wild
CVSS 9.8
EPSS 25.79%
Priority 70

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7194KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.94%
Priority 70

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7195KEVCRITICALin_the_wild
CVSS 9.8
EPSS 94.11%
Priority 70

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-19617CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVE-2019-19333CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

CVE-2019-19334CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

CVE-2019-5544KEVCRITICALin_the_wild
CVSS 9.8
EPSS 92.69%
Priority 70

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

CVE-2018-7282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.

CVE-2019-16670CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.

CVE-2019-16672CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-319

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.

← PreviousPage 331 / 7034Next →