Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2019-18349 HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-5509 ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote atta... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19594 reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-14910 A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication ... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-8879 Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by pro... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19317 lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other i... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2303 SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2017-18605 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-14896 A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possi... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19230 An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2289 Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industria... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2271 Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Indus... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2268 Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2011-1939 SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. | 9.8 | CRITICAL | — | 0 |
| CVE-2011-1933 SQL injection vulnerability in Jifty::DBI before 0.68. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-4621 IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use thi... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-16340 Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-10627 Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-17392 Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled. | 9.8 | CRITICAL | — | 0 |
| CVE-2012-3460 cumin: At installation postgresql database user created without password | 9.8 | CRITICAL | — | 0 |
| CVE-2013-7171 Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root p... | 9.8 | CRITICAL | — | 0 |
| CVE-2014-3700 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data | 9.8 | CRITICAL | — | 0 |
| CVE-2015-3166 The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows ... | 9.8 | CRITICAL | — | 0 |
| CVE-2013-2091 SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2013-2093 Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18858 CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-10765 iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. | 9.8 | CRITICAL | — | 0 |
| CVE-2010-4660 Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. | 9.8 | CRITICAL | — | 0 |
| CVE-2016-9652 Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75. | 9.8 | CRITICAL | — | 0 |
| CVE-2016-5194 Unspecified vulnerabilities in Google Chrome before 54.0.2840.59. | 9.8 | CRITICAL | — | 0 |
| CVE-2011-1028 The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-11171 Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service vi... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-12526 An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fai... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8248 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8247 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | 9.8 | CRITICAL | — | 0 |
| CVE-2011-1930 In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-3663 Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the sys... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-5029 An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19595 reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-13116 The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18952 SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-18240 In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19589 The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19307 An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT p... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19521 libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login... | 9.8 | CRITICAL | — | 0 |
| CVE-2013-3367 Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-8236 Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user. | 9.8 | CRITICAL | — | 0 |
| CVE-2010-4533 offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-16119 SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-2205 In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privilege... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.