| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-2091 | Cri | 0.57 | 9.8 | 0.03 | Nov 20, 2019 | SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php. | ||
| CVE-2019-18858 | Cri | 0.64 | 9.8 | 0.02 | Nov 20, 2019 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | ||
| CVE-2019-5541 | Cri | 0.59 | 9.1 | 0.01 | Nov 20, 2019 | VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to… | ||
| CVE-2019-10765 | Cri | 0.57 | 9.8 | 0.02 | Nov 20, 2019 | iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. | ||
| CVE-2010-4660 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2019 | Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. | ||
| CVE-2016-9652 | Cri | 0.64 | 9.8 | 0.02 | Nov 20, 2019 | Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75. | ||
| CVE-2016-5194 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2019 | Unspecified vulnerabilities in Google Chrome before 54.0.2840.59. | ||
| CVE-2011-1028 | Cri | 0.57 | 9.8 | 0.02 | Nov 20, 2019 | The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | ||
| CVE-2011-3350 | Cri | 0.64 | 9.8 | 0.02 | Nov 19, 2019 | masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. | ||
| CVE-2019-10766 | Cri | 0.57 | 9.8 | 0.01 | Nov 19, 2019 | Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization. | ||
| CVE-2011-2921 | Cri | 0.73 | 9.8 | 0.83 | Nov 19, 2019 | ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges. | ||
| CVE-2012-0824 | Cri | 0.64 | 9.8 | 0.02 | Nov 19, 2019 | gnusound 0.7.5 has format string issue | ||
| CVE-2016-1000006 | Cri | 0.57 | 9.8 | 0.02 | Nov 19, 2019 | hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions. | ||
| CVE-2019-12409 | Cri | 0.65 | 9.8 | 0.21 | Nov 18, 2019 | The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring… | ||
| CVE-2019-12271 | Cri | 0.64 | 9.8 | 0.02 | Nov 18, 2019 | Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side. | ||
| CVE-2018-20687 | Cri | 0.64 | 9.8 | 0.03 | Nov 18, 2019 | An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML… | ||
| CVE-2011-5331 | Cri | 0.64 | 9.8 | 0.03 | Nov 18, 2019 | Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval. | ||
| CVE-2011-5330 | Cri | 0.64 | 9.8 | 0.02 | Nov 18, 2019 | Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls. | ||
| CVE-2019-19113 | Cri | 0.64 | 9.8 | 0.02 | Nov 18, 2019 | main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection. | ||
| CVE-2019-17058 | Cri | 0.59 | 9.1 | 0.02 | Nov 18, 2019 | Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by an Administrator who uploads a crafted upload.dat file. | ||
| CVE-2019-19012 | Cri | 0.65 | 9.8 | 0.11 | Nov 17, 2019 | An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a… | ||
| CVE-2019-19010 | Cri | 0.57 | 9.8 | 0.02 | Nov 16, 2019 | Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands. | ||
| CVE-2019-13582 | Cri | 0.64 | 9.8 | 0.02 | Nov 15, 2019 | An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution. | ||
| CVE-2019-13581 | Cri | 0.64 | 9.8 | 0.03 | Nov 15, 2019 | An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service… | ||
| CVE-2011-0703 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2019 | In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session. | ||
| CVE-2013-7088 | Cri | 0.57 | 9.8 | 0.03 | Nov 15, 2019 | ClamAV before 0.97.7 has buffer overflow in the libclamav component | ||
| CVE-2013-7087 | Cri | 0.57 | 9.8 | 0.03 | Nov 15, 2019 | ClamAV before 0.97.7 has WWPack corrupt heap memory | ||
| CVE-2019-14345 | Cri | 0.64 | 9.8 | 0.02 | Nov 15, 2019 | TemaTres 3.0 allows remote unprivileged users to create an administrator account | ||
| CVE-2019-18985 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 lacks brute force protection for the 2FA token. | ||
| CVE-2019-18981 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification. | ||
| CVE-2019-18928 | Cri | 0.57 | 9.8 | 0.02 | Nov 15, 2019 | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection. | ||
| CVE-2019-15803 | Cri | 0.59 | 9.1 | 0.01 | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by… | ||
| CVE-2019-15800 | Cri | 0.64 | 9.8 | 0.04 | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could… | ||
| CVE-2019-14678 | Cri | 0.65 | 10.0 | 0.03 | Nov 14, 2019 | SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This… | ||
| CVE-2013-4108 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2019 | Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors. | ||
| CVE-2019-18939 | Cri | 0.67 | 9.8 | 0.41 | Nov 14, 2019 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST… | ||
| CVE-2019-18938 | Cri | 0.66 | 9.8 | 0.34 | Nov 14, 2019 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution. | ||
| CVE-2019-18937 | Cri | 0.66 | 9.8 | 0.34 | Nov 14, 2019 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request. | ||
| CVE-2013-3072 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2019 | An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration… | ||
| CVE-2013-3073 | Cri | 0.64 | 9.8 | 0.04 | Nov 14, 2019 | A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34. | ||
| CVE-2019-11171 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2019 | Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access. | ||
| CVE-2019-11168 | Cri | 0.59 | 9.1 | 0.01 | Nov 14, 2019 | Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access. | ||
| CVE-2019-8248 | Cri | 0.64 | 9.8 | 0.04 | Nov 14, 2019 | Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | ||
| CVE-2019-8247 | Cri | 0.64 | 9.8 | 0.04 | Nov 14, 2019 | Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution . | ||
| CVE-2019-8246 | Cri | 0.64 | 9.8 | 0.05 | Nov 14, 2019 | Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | ||
| CVE-2011-1930 | Cri | 0.68 | 9.8 | 0.21 | Nov 14, 2019 | In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP… | ||
| CVE-2019-3663 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2019 | Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further… | ||
| CVE-2019-5029 | Cri | 0.71 | 9.8 | 0.57 | Nov 13, 2019 | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches… | ||
| CVE-2019-18952 | Cri | 0.67 | 9.8 | 0.45 | Nov 13, 2019 | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP. | ||
| CVE-2019-18240 | Cri | 0.65 | 9.8 | 0.14 | Nov 13, 2019 | In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code. |
- risk 0.57cvss 9.8epss 0.03
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
- risk 0.64cvss 9.8epss 0.02
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
- risk 0.59cvss 9.1epss 0.01
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to…
- risk 0.57cvss 9.8epss 0.02
iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.
- risk 0.64cvss 9.8epss 0.01
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
- risk 0.64cvss 9.8epss 0.02
Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.
- risk 0.64cvss 9.8epss 0.01
Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
- risk 0.57cvss 9.8epss 0.02
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
- risk 0.64cvss 9.8epss 0.02
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
- risk 0.57cvss 9.8epss 0.01
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
- risk 0.73cvss 9.8epss 0.83
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
- risk 0.64cvss 9.8epss 0.02
gnusound 0.7.5 has format string issue
- risk 0.57cvss 9.8epss 0.02
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
- risk 0.65cvss 9.8epss 0.21
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring…
- risk 0.64cvss 9.8epss 0.02
Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.
- risk 0.64cvss 9.8epss 0.03
An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML…
- risk 0.64cvss 9.8epss 0.03
Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.
- risk 0.64cvss 9.8epss 0.02
Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
- risk 0.64cvss 9.8epss 0.02
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
- risk 0.59cvss 9.1epss 0.02
Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by an Administrator who uploads a crafted upload.dat file.
- risk 0.65cvss 9.8epss 0.11
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a…
- risk 0.57cvss 9.8epss 0.02
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service…
- risk 0.64cvss 9.8epss 0.01
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.
- risk 0.57cvss 9.8epss 0.03
ClamAV before 0.97.7 has buffer overflow in the libclamav component
- risk 0.57cvss 9.8epss 0.03
ClamAV before 0.97.7 has WWPack corrupt heap memory
- risk 0.64cvss 9.8epss 0.02
TemaTres 3.0 allows remote unprivileged users to create an administrator account
- risk 0.57cvss 9.8epss 0.01
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
- risk 0.57cvss 9.8epss 0.01
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
- risk 0.57cvss 9.8epss 0.02
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by…
- risk 0.64cvss 9.8epss 0.04
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could…
- risk 0.65cvss 10.0epss 0.03
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This…
- risk 0.64cvss 9.8epss 0.02
Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.
- risk 0.67cvss 9.8epss 0.41
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST…
- risk 0.66cvss 9.8epss 0.34
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.
- risk 0.66cvss 9.8epss 0.34
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request.
- risk 0.64cvss 9.8epss 0.02
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration…
- risk 0.64cvss 9.8epss 0.04
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
- risk 0.64cvss 9.8epss 0.02
Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.
- risk 0.59cvss 9.1epss 0.01
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.
- risk 0.64cvss 9.8epss 0.04
Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
- risk 0.64cvss 9.8epss 0.04
Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .
- risk 0.64cvss 9.8epss 0.05
Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
- risk 0.68cvss 9.8epss 0.21
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP…
- risk 0.64cvss 9.8epss 0.01
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further…
- risk 0.71cvss 9.8epss 0.57
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches…
- risk 0.67cvss 9.8epss 0.45
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
- risk 0.65cvss 9.8epss 0.14
In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.