CVE Database

CVE-2018-10388CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

CVE-2019-12567CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.

CVE-2019-12568CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567.

CVE-2019-19948CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

CVE-2019-19950CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

CVE-2019-19951CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

CVE-2019-19952CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

CVE-2019-19977CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.

CVE-2019-16327CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.

CVE-2019-19398CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may lead to malicious code execution.

CVE-2013-3085CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

CVE-2013-3088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

CVE-2019-20041CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVE-2013-4621CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities

CVE-2007-0158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

thttpd 2007 has buffer underflow.

CVE-2013-5027CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Collabtive 1.0 has incorrect access control

CVE-2019-20049CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().

CVE-2019-16535CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.

CVE-2019-10774CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-17621KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.01%
Priority 70

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

CVE-2019-13445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line.

CVE-2019-7478CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.

CVE-2019-3984CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.

CVE-2004-2776CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter.

CVE-2013-7070CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.

CVE-2019-10158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

CVE-2014-0048CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

CVE-2013-3941CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.

CVE-2014-0011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.

CVE-2016-1000027CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVE-2020-5311CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

CVE-2020-5312CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

CVE-2019-20330CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

CVE-2019-19088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

CVE-2019-11994CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. An API is used to execute a command manifest file during upgrade does not correctly prevent directory traversal and so can be used to execute manifest files in arbitrary locations on the node. The API does not require user authentication and is accessible over the management network, resulting in the potential for unauthenticated remote execution of manifest files. For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061901&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

CVE-2014-8337CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

CVE-2020-5499CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.

CVE-2019-19628CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

CVE-2020-5519CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.

CVE-2019-20343CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).

CVE-2016-11017CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

CVE-2020-5510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.

CVE-2019-16272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.

CVE-2019-16273CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a covert ability to capture screen data from the Zoom Client on Windows by executing commands on the Android OS.

CVE-2013-5122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access

CVE-2019-10776CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.

CVE-2020-5307CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.

CVE-2019-14906CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.

CVE-2020-5841CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.

CVE-2019-17146CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction request header, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8458.

← PreviousPage 335 / 7034Next →