| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2776 | Cri | 0.64 | 9.8 | 0.04 | Dec 31, 2019 | go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter. | ||
| CVE-2019-3984 | Cri | 0.64 | 9.8 | 0.04 | Dec 31, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. | ||
| CVE-2019-7162 | Cri | 0.59 | 9.1 | 0.04 | Dec 31, 2019 | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation. | ||
| CVE-2019-7478 | Cri | 0.64 | 9.8 | 0.01 | Dec 31, 2019 | A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1. | ||
| CVE-2019-13445 | Cri | 0.64 | 9.8 | 0.02 | Dec 30, 2019 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line. | ||
| CVE-2019-19735 | Cri | 0.59 | 9.1 | 0.01 | Dec 30, 2019 | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing. | ||
| CVE-2019-17621 | Cri | 0.86 | 9.8 | 0.90 | KEV | Dec 30, 2019 | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. | |
| CVE-2019-10774 | Cri | 0.57 | 9.8 | 0.05 | Dec 30, 2019 | php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-16535 | Cri | 0.64 | 9.8 | 0.02 | Dec 30, 2019 | In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol. | ||
| CVE-2014-5289 | Cri | 0.68 | 9.8 | 0.12 | Dec 27, 2019 | Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request. | ||
| CVE-2019-20049 | Cri | 0.65 | 9.8 | 0.13 | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the… | ||
| CVE-2013-5027 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2019 | Collabtive 1.0 has incorrect access control | ||
| CVE-2007-0158 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2019 | thttpd 2007 has buffer underflow. | ||
| CVE-2013-4982 | Cri | 0.68 | 9.8 | 0.13 | Dec 27, 2019 | AVTECH AVN801 DVR has a security bypass via the administration login captcha | ||
| CVE-2013-4976 | Cri | 0.70 | 9.8 | 0.36 | Dec 27, 2019 | Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials | ||
| CVE-2013-4743 | Cri | 0.67 | 9.8 | 0.08 | Dec 27, 2019 | Static HTTP Server 1.0 has a Local Overflow | ||
| CVE-2013-4621 | Cri | 0.64 | 9.8 | 0.02 | Dec 27, 2019 | Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities | ||
| CVE-2019-19781 | Cri | 0.93 | 9.8 | 1.00 | KEV | Dec 27, 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. | |
| CVE-2019-20041 | Cri | 0.64 | 9.8 | 0.05 | Dec 27, 2019 | wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring. | ||
| CVE-2013-3088 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2019 | Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging". | ||
| CVE-2013-3085 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2019 | An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2. | ||
| CVE-2019-19398 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2019 | M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may… | ||
| CVE-2019-16327 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2019 | D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product. | ||
| CVE-2019-19977 | Cri | 0.64 | 9.8 | 0.03 | Dec 26, 2019 | libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. | ||
| CVE-2019-10758 | Cri | 0.76 | 9.9 | 0.85 | KEV | Dec 24, 2019 | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment. | |
| CVE-2019-19953 | Cri | 0.59 | 9.1 | 0.03 | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c. | ||
| CVE-2019-19952 | Cri | 0.64 | 9.8 | 0.02 | Dec 24, 2019 | In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage. | ||
| CVE-2019-19951 | Cri | 0.64 | 9.8 | 0.03 | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. | ||
| CVE-2019-19950 | Cri | 0.64 | 9.8 | 0.03 | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. | ||
| CVE-2019-19949 | Cri | 0.59 | 9.1 | 0.03 | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare. | ||
| CVE-2019-19948 | Cri | 0.64 | 9.8 | 0.04 | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. | ||
| CVE-2019-12568 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567. | ||
| CVE-2019-12567 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568. | ||
| CVE-2018-10389 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2019 | Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. | ||
| CVE-2018-10388 | Cri | 0.64 | 9.8 | 0.04 | Dec 23, 2019 | Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. | ||
| CVE-2018-10387 | Cri | 0.64 | 9.8 | 0.03 | Dec 23, 2019 | Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161. | ||
| CVE-2019-8293 | Cri | 0.57 | 9.8 | 0.03 | Dec 23, 2019 | Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. | ||
| CVE-2019-7489 | Cri | 0.64 | 9.8 | 0.05 | Dec 23, 2019 | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier. | ||
| CVE-2019-7488 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2019 | Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier. | ||
| CVE-2019-3431 | Cri | 0.64 | 9.8 | 0.00 | Dec 23, 2019 | All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access. | ||
| CVE-2019-18234 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2019 | Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2019-19919 | Cri | 0.57 | 9.8 | 0.07 | Dec 20, 2019 | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads. | ||
| CVE-2019-19747 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2019 | NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that… | ||
| CVE-2019-17571 | Cri | 0.62 | 9.8 | 0.69 | Dec 20, 2019 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects… | ||
| CVE-2019-15913 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2019 | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with… | ||
| CVE-2019-15911 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart… | ||
| CVE-2019-17440 | Cri | 0.65 | 10.0 | 0.02 | Dec 20, 2019 | Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to… | ||
| CVE-2012-6094 | Cri | 0.57 | 9.8 | 0.02 | Dec 20, 2019 | cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system | ||
| CVE-2019-19915 | Cri | 0.59 | 9.0 | 0.01 | Dec 19, 2019 | The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and… | ||
| CVE-2019-17527 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2019 | dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter. |
- risk 0.64cvss 9.8epss 0.04
go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter.
- risk 0.64cvss 9.8epss 0.04
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
- risk 0.59cvss 9.1epss 0.04
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line.
- risk 0.59cvss 9.1epss 0.01
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.
- risk 0.86cvss 9.8epss 0.90
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
- risk 0.57cvss 9.8epss 0.05
php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.02
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
- risk 0.68cvss 9.8epss 0.12
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.
- risk 0.65cvss 9.8epss 0.13
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the…
- risk 0.57cvss 9.8epss 0.01
Collabtive 1.0 has incorrect access control
- risk 0.64cvss 9.8epss 0.01
thttpd 2007 has buffer underflow.
- risk 0.68cvss 9.8epss 0.13
AVTECH AVN801 DVR has a security bypass via the administration login captcha
- risk 0.70cvss 9.8epss 0.36
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
- risk 0.67cvss 9.8epss 0.08
Static HTTP Server 1.0 has a Local Overflow
- risk 0.64cvss 9.8epss 0.02
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
- risk 0.93cvss 9.8epss 1.00
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
- risk 0.64cvss 9.8epss 0.05
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
- risk 0.64cvss 9.8epss 0.02
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
- risk 0.64cvss 9.8epss 0.02
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
- risk 0.64cvss 9.8epss 0.01
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may…
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.
- risk 0.64cvss 9.8epss 0.03
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
- risk 0.76cvss 9.9epss 0.85
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
- risk 0.59cvss 9.1epss 0.03
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
- risk 0.64cvss 9.8epss 0.02
In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
- risk 0.64cvss 9.8epss 0.03
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
- risk 0.64cvss 9.8epss 0.03
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
- risk 0.59cvss 9.1epss 0.03
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
- risk 0.64cvss 9.8epss 0.04
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
- risk 0.64cvss 9.8epss 0.02
Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567.
- risk 0.64cvss 9.8epss 0.02
Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.
- risk 0.64cvss 9.8epss 0.02
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
- risk 0.64cvss 9.8epss 0.04
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
- risk 0.64cvss 9.8epss 0.03
Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161.
- risk 0.57cvss 9.8epss 0.03
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
- risk 0.64cvss 9.8epss 0.05
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
- risk 0.64cvss 9.8epss 0.02
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
- risk 0.64cvss 9.8epss 0.00
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
- risk 0.64cvss 9.8epss 0.02
Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.
- risk 0.57cvss 9.8epss 0.07
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
- risk 0.64cvss 9.8epss 0.01
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that…
- risk 0.62cvss 9.8epss 0.69
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart…
- risk 0.65cvss 10.0epss 0.02
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to…
- risk 0.57cvss 9.8epss 0.02
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
- risk 0.59cvss 9.0epss 0.01
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and…
- risk 0.64cvss 9.8epss 0.01
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.