Latest CVE Feed
-
9.3
HIGHCVE-2015-1007
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior... Read more
- EPSS Score: %0.54
- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1010260
Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerabilit... Read more
Affected Products : ktlint- EPSS Score: %0.22
- Published: Apr. 02, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2018-3974
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overwrite an executable that is launched as a system service on boot by default to exploit this vulnerability a... Read more
Affected Products : galaxy- EPSS Score: %0.11
- Published: Apr. 02, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2018-4049
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerab... Read more
Affected Products : galaxy- EPSS Score: %0.08
- Published: Apr. 02, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-10673
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the atta... Read more
Affected Products : ultimate_member- EPSS Score: %0.43
- Published: Apr. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-17023
The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the soft... Read more
- EPSS Score: %0.08
- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2018-4008
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vuln... Read more
Affected Products : shimo_vpn- EPSS Score: %0.11
- Published: Apr. 15, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2027
In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Androi... Read more
Affected Products : android- EPSS Score: %0.34
- Published: Apr. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.... Read more
- EPSS Score: %1.89
- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2019-10309
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbit... Read more
Affected Products : self-organizing_swarm_modules- EPSS Score: %0.07
- Published: Apr. 30, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-11687
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable ... Read more
Affected Products : dicom_standard- EPSS Score: %13.44
- Published: May. 02, 2019
- Modified: Jul. 24, 2025
-
9.3
HIGHCVE-2018-4062
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user... Read more
- EPSS Score: %0.31
- Published: May. 06, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1773
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
Affected Products : webex_meetings_server webex_meetings_online webex_business_suite webex_business_suite_lockdown- EPSS Score: %0.27
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-12569
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerabi... Read more
Affected Products : viber- EPSS Score: %3.22
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-3567
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said m... Read more
Affected Products : osquery- EPSS Score: %0.43
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-8328
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not ... Read more
Affected Products : almond_2015_firmware almond\+firmware almond_firmware almond almond_2015 almond\+- EPSS Score: %0.25
- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1990
In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat... Read more
Affected Products : android- EPSS Score: %1.67
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2016
In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Pro... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-16118
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.... Read more
- EPSS Score: %0.43
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2019-1848
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports neces... Read more
- EPSS Score: %0.37
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024