Latest CVE Feed
-
9.8
CRITICALCVE-2019-4203
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from the host OS and potentially carry out SSRF attacks. IBM X-Force ID: 159124.... Read more
Affected Products : api_connect- EPSS Score: %0.48
- Published: Apr. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9642
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest ac... Read more
Affected Products : pydio- EPSS Score: %2.02
- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-3725
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could expl... Read more
- EPSS Score: %5.45
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8385
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to lis... Read more
- EPSS Score: %10.68
- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21426
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 an... Read more
Affected Products : magento- EPSS Score: %0.40
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12599
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.... Read more
Affected Products : suitecrm- EPSS Score: %0.42
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20354
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remo... Read more
Affected Products : mongoose- EPSS Score: %2.68
- Published: Jun. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20356
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code ... Read more
Affected Products : mongoose- EPSS Score: %2.68
- Published: Jun. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12798
An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size.... Read more
Affected Products : mujs- EPSS Score: %0.43
- Published: Jun. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-3954
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafted IOCTL 81024 RPC call.... Read more
- EPSS Score: %5.95
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18758
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.... Read more
Affected Products : open_faculty_evaluation_system- EPSS Score: %0.31
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17841
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.... Read more
Affected Products : flippa_marketplace_clone- EPSS Score: %0.31
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17842
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.... Read more
Affected Products : hotel_booking_engine- EPSS Score: %0.31
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11232
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.... Read more
Affected Products : biyan- EPSS Score: %0.71
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17386
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.... Read more
Affected Products : micro_deal_factory- EPSS Score: %0.31
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12890
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.... Read more
Affected Products : redwoodhq- EPSS Score: %52.92
- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8459
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead ... Read more
- EPSS Score: %0.50
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15747
The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system within a "python" "files" "content" JSON file.... Read more
Affected Products : glot-www- EPSS Score: %2.65
- Published: Jun. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11011
Akamai CloudTest before 58.30 allows remote code execution.... Read more
Affected Products : cloudtest- EPSS Score: %3.73
- Published: Jun. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12960
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.... Read more
Affected Products : livezilla- EPSS Score: %0.37
- Published: Jun. 25, 2019
- Modified: Nov. 21, 2024