Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2019-8662 This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application dese... | 9.8 | CRITICAL | β | 0 |
| CVE-2015-3166 The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows ... | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2091 SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-6959 The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to ... | 9.8 | CRITICAL | β | 0 |
| CVE-2012-4919 Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability | 9.8 | CRITICAL | β | 0 |
| CVE-2013-2093 Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18858 CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10765 iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-6960 The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to ... | 9.8 | CRITICAL | β | 0 |
| CVE-2010-4660 Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. | 9.8 | CRITICAL | β | 0 |
| CVE-2016-9652 Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75. | 9.8 | CRITICAL | β | 0 |
| CVE-2016-5194 Unspecified vulnerabilities in Google Chrome before 54.0.2840.59. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-1028 The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-14014 Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Nicoba... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-7109 The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-3350 masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-3614 An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-3621 A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8750 Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Multiple issues in libxslt. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-0610 A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted request... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-0609 A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted request... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-6675 BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass.... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8248 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 9.8 | CRITICAL | β | 0 |
| CVE-2019-14013 While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read into the table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connec... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8247 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 9.8 | CRITICAL | β | 0 |
| CVE-2019-15932 Intesync Solismed 3.3sp has Incorrect Access Control. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-19836 AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename. | 9.8 | CRITICAL | β | 0 |
| CVE-2015-9323 The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-19843 Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and ... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-0403 SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-2715 An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-10694 The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overloo... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-14842 Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test for chunk offsets smaller than the beginning of the ... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-4481 IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-4483 IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-15933 Intesync Solismed 3.3sp has SQL Injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2011-1930 In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could ... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-3663 Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the sys... | 9.8 | CRITICAL | β | 0 |
| CVE-2011-3203 A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-5505 Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-19844 Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of ... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-5029 An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18184 Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-8440 controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-19840 A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-18240 In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-15936 Intesync Solismed 3.3sp allows Insecure File Upload. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-19841 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac att... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-3431 All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end sy... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-8293 Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.