Latest CVE Feed
-
9.8
CRITICAL- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12419
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equa... Read more
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-2476
syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot.... Read more
Affected Products : syscp- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2007-6745
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.... Read more
- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12719
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.... Read more
Affected Products : sunveillance_monitoring_system_\&_data_recorder- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18952
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.... Read more
Affected Products : xfilesharing- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14345
TemaTres 3.0 allows remote unprivileged users to create an administrator account... Read more
Affected Products : tematres- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-1000006
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.... Read more
Affected Products : hhvm- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2091
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.... Read more
Affected Products : dolibarr_erp\/crm- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3700
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data... Read more
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16340
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.... Read more
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11325
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.... Read more
Affected Products : symfony- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-6310
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.... Read more
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19250
OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.... Read more
Affected Products : opentrade- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19492
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.... Read more
Affected Products : freeswitch- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12394
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.... Read more
Affected Products : management_system- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19021
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.... Read more
Affected Products : webtitan- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024