Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2019-18344 Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18387 Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit pa... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-11935 Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5,... | 9.8 | CRITICAL | — | 0 |
| CVE-2011-4121 The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use th... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-11933 A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of... | 9.8 | CRITICAL | — | 0 |
| CVE-2013-2745 An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0 | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19228 Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19576 class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8237 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and ear... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8236 Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user. | 9.8 | CRITICAL | — | 0 |
| CVE-2018-8879 Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by pro... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-11936 Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-20343 The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executa... | 9.8 | CRITICAL | — | 0 |
| CVE-2016-11017 The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a f... | 9.8 | CRITICAL | — | 0 |
| CVE-2011-3350 masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18337 A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communicati... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-11940 In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18284 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18370 An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can co... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18623 Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with acces... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8613 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8662 This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application dese... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-12489 An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a com... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-15911 An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive... | 9.8 | CRITICAL | — | 0 |
| CVE-2011-1028 The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-15913 An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive informat... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19750 minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product. | 9.8 | CRITICAL | — | 0 |
| CVE-2012-3460 cumin: At installation postgresql database user created without password | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8293 Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. | 9.8 | CRITICAL | — | 0 |
| CVE-2016-5194 Unspecified vulnerabilities in Google Chrome before 54.0.2840.59. | 9.8 | CRITICAL | — | 0 |
| CVE-2016-9652 Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75. | 9.8 | CRITICAL | — | 0 |
| CVE-2010-4660 Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-10765 iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18835 Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected ... | 9.8 | CRITICAL | — | 0 |
| CVE-2008-7291 gri before 2.12.18 generates temporary files in an insecure way. | 9.8 | CRITICAL | — | 0 |
| CVE-2013-7171 Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root p... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-17571 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gad... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18858 CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18323 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could cause a Denial-of-Service condition and potentially... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19747 NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any val... | 9.8 | CRITICAL | — | 0 |
| CVE-2014-3700 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2268 Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-5509 ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote atta... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8248 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2271 Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Indus... | 9.8 | CRITICAL | — | 0 |
| CVE-2013-2093 Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8247 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 9.8 | CRITICAL | — | 0 |
| CVE-2019-6675 BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass.... | 9.8 | CRITICAL | — | 0 |
| CVE-2013-2091 SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18289 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potential... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.