Latest CVE Feed
-
9.8
CRITICALCVE-2019-9827
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.... Read more
Affected Products : hawtio- EPSS Score: %4.59
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9823
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: ... Read more
Affected Products : intellij_idea- EPSS Score: %0.00
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9873
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019... Read more
Affected Products : intellij_idea- EPSS Score: %0.00
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-0496
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.... Read more
Affected Products : network_backup- EPSS Score: %2.56
- Published: Feb. 21, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-10195
A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/goform_get_cmd_process of the component SMS Check. The manipulation o... Read more
- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
9.8
CRITICALCVE-2019-9791
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacemen... Read more
- EPSS Score: %39.30
- Published: Apr. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19646
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.... Read more
- EPSS Score: %8.50
- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0289
A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unknown code of the file stock_entry_submit.php. The manipulation of the argument itemype leads to sql injection. The attack can be initia... Read more
Affected Products : food_management_system- EPSS Score: %0.19
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9631
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.... Read more
- EPSS Score: %2.22
- Published: Mar. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9552
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.... Read more
Affected Products : eloan- EPSS Score: %0.82
- Published: Mar. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9566
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.... Read more
Affected Products : flarumchina- EPSS Score: %0.26
- Published: Mar. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11117
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructur... Read more
Affected Products : ipq6018_firmware ipq8064_firmware ipq8074_firmware qca9980_firmware ipq4019_firmware qca9531_firmware qca4531_firmware ipq4019 ipq6018 ipq8064 +4 more products- EPSS Score: %3.59
- Published: Sep. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9365
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: A... Read more
Affected Products : android- EPSS Score: %1.44
- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10163
A vulnerability was found in SourceCodester Sentiment Based Movie Rating System 1.0. It has been classified as critical. Affected is an unknown function of the file /msrps/movie_details.php. The manipulation of the argument id leads to sql injection. It i... Read more
Affected Products : sentiment_based_movie_rating_system- Published: Oct. 20, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2019-9215
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.... Read more
- EPSS Score: %0.95
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9201
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.... Read more
- EPSS Score: %2.01
- Published: Feb. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9217
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.... Read more
Affected Products : gitlab- EPSS Score: %0.14
- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9204
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.... Read more
Affected Products : incident_manager- EPSS Score: %13.41
- Published: Mar. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9163
The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.... Read more
Affected Products : command_client- EPSS Score: %2.62
- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.... Read more
Affected Products : elfinder- EPSS Score: %90.11
- Published: Feb. 26, 2019
- Modified: Nov. 21, 2024