| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-2283 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2019-2258 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in… | ||
| CVE-2019-2249 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9205,… | ||
| CVE-2019-10565 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2019-10542 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2019-10541 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,… | ||
| CVE-2019-10534 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,… | ||
| CVE-2019-10533 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,… | ||
| CVE-2019-10531 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439 | ||
| CVE-2019-10528 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables… | ||
| CVE-2019-10522 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607,… | ||
| CVE-2019-10505 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2011-4628 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request. | ||
| CVE-2010-2446 | Cri | 0.64 | 9.8 | 0.03 | Nov 6, 2019 | Rbot Reaction plugin allows command execution | ||
| CVE-2019-12918 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir]. | ||
| CVE-2016-4401 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials. | ||
| CVE-2007-0899 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | There is a possible heap overflow in libclamav/fsg.c before 0.100.0. | ||
| CVE-2019-18784 | Cri | 0.57 | 9.8 | 0.01 | Nov 6, 2019 | SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. | ||
| CVE-2006-4243 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code. | ||
| CVE-2006-3100 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | termpkg 3.3 suffers from buffer overflow. | ||
| CVE-2006-0062 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window. | ||
| CVE-2006-0061 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session. | ||
| CVE-2019-8158 | Cri | 0.57 | 9.8 | 0.01 | Nov 6, 2019 | An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted… | ||
| CVE-2019-8149 | Cri | 0.57 | 9.8 | 0.02 | Nov 6, 2019 | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication. | ||
| CVE-2019-8144 | Cri | 0.57 | 9.8 | 0.02 | Nov 6, 2019 | A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods. | ||
| CVE-2019-8136 | Cri | 0.57 | 9.8 | 0.01 | Nov 6, 2019 | An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component. | ||
| CVE-2019-8135 | Cri | 0.57 | 9.8 | 0.02 | Nov 6, 2019 | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution. | ||
| CVE-2019-8121 | Cri | 0.57 | 9.8 | 0.01 | Nov 5, 2019 | An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities. | ||
| CVE-2011-1460 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2019 | WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks. | ||
| CVE-2011-1134 | Cri | 0.64 | 9.8 | 0.03 | Nov 5, 2019 | Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager. | ||
| CVE-2019-18780 | Cri | 0.64 | 9.8 | 0.06 | Nov 5, 2019 | An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance… | ||
| CVE-2005-2354 | Cri | 0.64 | 9.8 | 0.02 | Nov 5, 2019 | Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues. | ||
| CVE-2019-17211 | Cri | 0.64 | 9.8 | 0.03 | Nov 5, 2019 | An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory for the CoAP message from the sn_coap_hdr_s data structure. Both returned_byte_count and… | ||
| CVE-2019-17212 | Cri | 0.64 | 9.8 | 0.03 | Nov 5, 2019 | Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the… | ||
| CVE-2015-8980 | Cri | 0.64 | 9.8 | 0.07 | Nov 4, 2019 | The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. | ||
| CVE-2013-4409 | Cri | 0.57 | 9.8 | 0.04 | Nov 4, 2019 | An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. | ||
| CVE-2019-18663 | Cri | 0.64 | 9.8 | 0.01 | Nov 4, 2019 | A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter. | ||
| CVE-2013-2260 | Cri | 0.64 | 9.8 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | ||
| CVE-2013-2259 | Cri | 0.64 | 9.8 | 0.04 | Nov 4, 2019 | Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | ||
| CVE-2013-4103 | Cri | 0.67 | 9.8 | 0.07 | Nov 4, 2019 | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | ||
| CVE-2013-4102 | Cri | 0.59 | 9.1 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness | ||
| CVE-2019-18662 | Cri | 0.64 | 9.8 | 0.02 | Nov 2, 2019 | An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query.… | ||
| CVE-2013-1666 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2019 | Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. | ||
| CVE-2011-3923 | Cri | 0.74 | 9.8 | 0.89 | Nov 1, 2019 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | ||
| CVE-2013-2739 | Cri | 0.67 | 9.8 | 0.05 | Nov 1, 2019 | MiniDLNA has heap-based buffer overflow | ||
| CVE-2005-3056 | Cri | 0.64 | 9.8 | 0.03 | Nov 1, 2019 | TWiki allows arbitrary shell command execution via the Include function | ||
| CVE-2013-2738 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2019 | minidlna has SQL Injection that may allow retrieval of arbitrary files | ||
| CVE-2019-18226 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2019 | Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products. | ||
| CVE-2019-13551 | Cri | 0.64 | 9.8 | 0.05 | Oct 31, 2019 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an… | ||
| CVE-2019-13547 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication. |
- risk 0.64cvss 9.8epss 0.01
Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.64cvss 9.8epss 0.01
Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in…
- risk 0.64cvss 9.8epss 0.01
Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9205,…
- risk 0.64cvss 9.8epss 0.01
Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.64cvss 9.8epss 0.01
Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.64cvss 9.8epss 0.01
Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…
- risk 0.64cvss 9.8epss 0.01
Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…
- risk 0.64cvss 9.8epss 0.01
Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…
- risk 0.64cvss 9.8epss 0.01
Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439
- risk 0.64cvss 9.8epss 0.01
Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables…
- risk 0.64cvss 9.8epss 0.01
While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607,…
- risk 0.64cvss 9.8epss 0.01
Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.64cvss 9.8epss 0.02
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.
- risk 0.64cvss 9.8epss 0.03
Rbot Reaction plugin allows command execution
- risk 0.64cvss 9.8epss 0.01
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].
- risk 0.64cvss 9.8epss 0.01
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
- risk 0.64cvss 9.8epss 0.02
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
- risk 0.57cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
- risk 0.64cvss 9.8epss 0.02
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.
- risk 0.64cvss 9.8epss 0.02
termpkg 3.3 suffers from buffer overflow.
- risk 0.64cvss 9.8epss 0.01
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
- risk 0.64cvss 9.8epss 0.02
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
- risk 0.57cvss 9.8epss 0.01
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted…
- risk 0.57cvss 9.8epss 0.02
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.
- risk 0.57cvss 9.8epss 0.02
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.
- risk 0.57cvss 9.8epss 0.01
An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.
- risk 0.57cvss 9.8epss 0.02
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.
- risk 0.57cvss 9.8epss 0.01
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.
- risk 0.64cvss 9.8epss 0.01
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
- risk 0.64cvss 9.8epss 0.03
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
- risk 0.64cvss 9.8epss 0.06
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance…
- risk 0.64cvss 9.8epss 0.02
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.
- risk 0.64cvss 9.8epss 0.03
An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory for the CoAP message from the sn_coap_hdr_s data structure. Both returned_byte_count and…
- risk 0.64cvss 9.8epss 0.03
Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the…
- risk 0.64cvss 9.8epss 0.07
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
- risk 0.57cvss 9.8epss 0.04
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.
- risk 0.64cvss 9.8epss 0.02
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
- risk 0.64cvss 9.8epss 0.04
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
- risk 0.67cvss 9.8epss 0.07
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
- risk 0.59cvss 9.1epss 0.02
Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query.…
- risk 0.64cvss 9.8epss 0.02
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
- risk 0.74cvss 9.8epss 0.89
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
- risk 0.67cvss 9.8epss 0.05
MiniDLNA has heap-based buffer overflow
- risk 0.64cvss 9.8epss 0.03
TWiki allows arbitrary shell command execution via the Include function
- risk 0.64cvss 9.8epss 0.02
minidlna has SQL Injection that may allow retrieval of arbitrary files
- risk 0.64cvss 9.8epss 0.01
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.
- risk 0.64cvss 9.8epss 0.05
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an…
- risk 0.64cvss 9.8epss 0.03
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.