Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2019-10542 Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity,... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10541 Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10534 Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapd... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10533 Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-13478 The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10531 Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10528 Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon In... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10522 While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdrag... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10505 Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Cons... | 9.8 | CRITICAL | β | 0 |
| CVE-2011-4628 TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request. | 9.8 | CRITICAL | β | 0 |
| CVE-2010-2446 Rbot Reaction plugin allows command execution | 9.8 | CRITICAL | β | 0 |
| CVE-2020-12889 MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-12918 Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0... | 9.8 | CRITICAL | β | 0 |
| CVE-2016-4401 Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-13224 A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted ... | 9.8 | CRITICAL | β | 0 |
| CVE-2007-0899 There is a possible heap overflow in libclamav/fsg.c before 0.100.0. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18784 SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2006-0061 xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8158 An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that get... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8149 Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8144 A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8136 An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction impl... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-1373 A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8135 A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be de... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8121 An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Boot... | 9.8 | CRITICAL | β | 0 |
| CVE-2011-1460 WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks. | 9.8 | CRITICAL | β | 0 |
| CVE-2006-0062 xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-1134 Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18780 An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. Thes... | 9.8 | CRITICAL | β | 0 |
| CVE-2005-2354 Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-17211 An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory for the CoAP messag... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-17212 Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP in... | 9.8 | CRITICAL | β | 0 |
| CVE-2015-8980 The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. | 9.8 | CRITICAL | β | 0 |
| CVE-2013-4409 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18663 A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2260 Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2259 Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | 9.8 | CRITICAL | β | 0 |
| CVE-2019-13132 In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/au... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-13550 In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow r... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18662 An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugi... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-12803 In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upl... | 9.8 | CRITICAL | β | 0 |
| CVE-2013-1666 Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-3923 Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2739 MiniDLNA has heap-based buffer overflow | 9.8 | CRITICAL | β | 0 |
| CVE-2005-3056 TWiki allows arbitrary shell command execution via the Include function | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2738 minidlna has SQL Injection that may allow retrieval of arbitrary files | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18226 Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-12838 SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-12874 Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-13551 Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can le... | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.