Latest CVE Feed
-
9.8
CRITICALCVE-2019-16340
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.... Read more
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11325
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.... Read more
Affected Products : symfony- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-6310
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.... Read more
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19250
OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.... Read more
Affected Products : opentrade- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19492
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.... Read more
Affected Products : freeswitch- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12394
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.... Read more
Affected Products : management_system- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19021
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.... Read more
Affected Products : webtitan- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19459
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to e... Read more
Affected Products : proaccess_space- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5083
An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft ImageGear 19.3.0 library. A specially crafted TIFF file can cause an out of bounds write, resulting in a remote code execution. An attac... Read more
Affected Products : imagegear- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11940
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Pr... Read more
Affected Products : proxygen- Published: Dec. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19589
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn... Read more
Affected Products : pdf_embedder- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14910
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.... Read more
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19594
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.... Read more
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7282
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.... Read more
Affected Products : printmonitor- Published: Dec. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16670
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.... Read more
Affected Products : ie-sw-pl09m-5gc-4gt_firmware ie-sw-pl09mt-5gc-4gt_firmware ie-sw-pl18m-2gc-16tx_firmware ie-sw-pl18mt-2gc-16tx_firmware ie-sw-pl18m-2gc14tx2sc_firmware ie-sw-pl18mt-2gc14tx2sc_firmware ie-sw-pl18m-2gc14tx2st_firmware ie-sw-pl18mt-2gc14tx2st_firmware ie-sw-pl18m-2gc14tx2scs_firmware ie-sw-pl18mt-2gc14tx2scs_firmware +70 more products- Published: Dec. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19637
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.... Read more
Affected Products : libsixel- Published: Dec. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8135
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remo... Read more
Affected Products : magento- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5085
An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a p... Read more
Affected Products : leadtools- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15932
Intesync Solismed 3.3sp has Incorrect Access Control.... Read more
Affected Products : solismed- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024