CVE Database

CVE-2019-19392CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.

CVE-2020-7229CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.

CVE-2015-2784CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.

CVE-2016-11018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

CVE-2011-4943CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)

CVE-2018-16272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

CVE-2019-10780CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.

CVE-2019-10781CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.

CVE-2020-6959CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.

CVE-2020-6960CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.

CVE-2020-7109CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

CVE-2011-3614CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

CVE-2011-3621CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled.

CVE-2012-4919CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-829

Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

CVE-2019-19836CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.

CVE-2019-19843CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.

CVE-2019-19840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.

CVE-2019-19841CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.

CVE-2019-19842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.

CVE-2012-2087CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

CVE-2019-19838CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.

CVE-2019-19839CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.

CVE-2019-16153CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.

CVE-2019-16517CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-346

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.

CVE-2015-5334CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

CVE-2019-19897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM context of the target system by using the Execute Command Line function.

CVE-2020-7941CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.

CVE-2018-6579CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.

CVE-2019-17570CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

CVE-2020-7245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-640

Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one must register with a username identical to the victim's username, but with white space inserted before and/or after the username. This will register the account with the same username as the victim. After initiating a password reset for the new account, CTFd will reset the victim's account password due to the username collision.

CVE-2012-6451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability

CVE-2014-1924CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not require authentication, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

CVE-2014-1925CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged by remote attackers using CVE-2014-1924.

CVE-2015-4042CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.

CVE-2014-4172CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

CVE-2019-1353CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.

CVE-2020-7981CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.

CVE-2020-8000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

CVE-2020-7995CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

CVE-2020-7999CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.

CVE-2019-20427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of validation for specific fields of packets sent by a client. Interaction between req_capsule_get_size and tgt_brw_write leads to a tgt_shortio2pages integer signedness error.

CVE-2013-3492CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

XnView 2.03 has a stack-based buffer overflow vulnerability

CVE-2013-3493CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

XnView 2.03 has an integer overflow vulnerability

CVE-2015-0244CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVE-2013-4441CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2019-17096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.

CVE-2019-19825CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.

CVE-2019-17095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the condition, an unauthenticated attacker should impersonate a infrastructure server to trigger this vulnerability.

CVE-2014-8563CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.

CVE-2020-8087CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must use a Parameter Pollution approach against goform/formSetDiagnosticToolsFmPing by providing the vlu_diagnostic_tools__ping_address parameter twice: once with a shell metacharacter and a command name, and once with a command argument.

← PreviousPage 337 / 7034Next →