Latest CVE Feed
-
9.8
CRITICALCVE-2018-20998
An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.... Read more
Affected Products : arrayfire- EPSS Score: %0.43
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9569
Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors.... Read more
- EPSS Score: %6.94
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11652
A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as ap... Read more
- EPSS Score: %0.52
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21005
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.... Read more
Affected Products : bbpress_move_topics- EPSS Score: %0.99
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15659
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.... Read more
- EPSS Score: %0.55
- Published: Aug. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15780
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.... Read more
- EPSS Score: %1.10
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15824
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.... Read more
Affected Products : wps_hide_login- EPSS Score: %1.02
- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13976
eGain Chat 15.0.3 allows unrestricted file upload.... Read more
Affected Products : chat- EPSS Score: %0.43
- Published: Sep. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14222
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present ... Read more
Affected Products : alfresco- EPSS Score: %2.14
- Published: Sep. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16125
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.... Read more
Affected Products : jobberbase- EPSS Score: %0.62
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16143
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes.... Read more
- EPSS Score: %0.20
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21013
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.... Read more
Affected Products : swape- EPSS Score: %0.80
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15102
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is a... Read more
Affected Products : sahi_pro- EPSS Score: %4.54
- Published: Sep. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10665
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some... Read more
Affected Products : librenms- EPSS Score: %0.00
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16190
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.... Read more
Affected Products : dir-895l_firmware dir-885l_firmware dir-868l_firmware dir-868l dir-885l dir-895l- EPSS Score: %0.90
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16184
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.... Read more
Affected Products : limesurvey- EPSS Score: %0.69
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12405
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate... Read more
Affected Products : traffic_control- EPSS Score: %1.17
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18605
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.... Read more
Affected Products : gravitate_qa_tracker- EPSS Score: %1.26
- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15896
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (adminis... Read more
Affected Products : lifterlms- EPSS Score: %3.72
- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11495
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small search space for potential random seeds that could then be used to brute force... Read more
Affected Products : couchbase_server- EPSS Score: %0.59
- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024