Latest CVE Feed
-
9.8
CRITICALCVE-2019-4651
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170... Read more
Affected Products : jazz_reporting_service- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15913
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home ... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16114
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which a... Read more
Affected Products : atutor- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25049
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).... Read more
Affected Products : android- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25111
An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.... Read more
Affected Products : contiki-os- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16194
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.... Read more
Affected Products : centreon- Published: Sep. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25253
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by the TableName, ColumnName, Name, UserId, or Password pa... Read more
Affected Products : onbase- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5454
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.... Read more
Affected Products : nextcloud- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-16724
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.... Read more
Affected Products : file_sharing_wizard- Published: Sep. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17132
vBulletin through 5.5.4 mishandles custom avatars.... Read more
Affected Products : vbulletin- Published: Oct. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17398
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.... Read more
Affected Products : dark_horse_comics- Published: Oct. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17552
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.... Read more
Affected Products : icms- Published: Oct. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6553
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward Open service request is passed to a fixed size buffer, allowing an attacker ... Read more
Affected Products : rslinx- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18623
Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with access rights matching the user who created the dashboard.... Read more
Affected Products : energycap- Published: Nov. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27488
Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to us... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27739
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in ... Read more
Affected Products : webcit- Published: Oct. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18858
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.... Read more
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6203
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.... Read more
- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.... Read more
- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28269
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : field- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024