| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13508 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2019 | FreeTDS through 1.1.11 has a Buffer Overflow. | ||
| CVE-2018-4031 | Cri | 0.65 | 10.0 | 0.03 | Oct 31, 2019 | An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua… | ||
| CVE-2012-6125 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2019 | Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. | ||
| CVE-2010-2783 | Cri | 0.59 | 9.1 | 0.02 | Oct 31, 2019 | IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. | ||
| CVE-2010-2548 | Cri | 0.59 | 9.1 | 0.02 | Oct 31, 2019 | IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. | ||
| CVE-2019-5151 | Cri | 0.65 | 10.0 | 0.02 | Oct 31, 2019 | An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to… | ||
| CVE-2019-5049 | Cri | 0.65 | 10.0 | 0.02 | Oct 31, 2019 | An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this… | ||
| CVE-2013-1910 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. | ||
| CVE-2019-18465 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2019 | In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL… | ||
| CVE-2019-18464 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2019 | In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the… | ||
| CVE-2009-5043 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2019 | burn allows file names to escape via mishandled quotation marks | ||
| CVE-2009-5042 | Cri | 0.59 | 9.1 | 0.01 | Oct 31, 2019 | python-docutils allows insecure usage of temporary files | ||
| CVE-2009-5041 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2019 | overkill has buffer overflow via long player names that can corrupt data on the server machine | ||
| CVE-2019-18364 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. | ||
| CVE-2019-18425 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table… | ||
| CVE-2010-0748 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2019 | Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. | ||
| CVE-2019-18633 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2019 | European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected. | ||
| CVE-2019-18632 | Cri | 0.57 | 9.8 | 0.01 | Oct 30, 2019 | European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate. | ||
| CVE-2019-10762 | Cri | 0.57 | 9.8 | 0.01 | Oct 30, 2019 | columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping. | ||
| CVE-2018-21029 | Cri | 0.64 | 9.8 | 0.03 | Oct 30, 2019 | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability… | ||
| CVE-2012-0694 | Cri | 0.72 | 9.8 | 0.67 | Oct 29, 2019 | SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. | ||
| CVE-2019-8287 | Cri | 0.65 | 9.8 | 0.19 | Oct 29, 2019 | TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity. | ||
| CVE-2019-18624 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2019 | Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553,… | ||
| CVE-2019-18604 | Cri | 0.57 | 9.8 | 0.02 | Oct 29, 2019 | In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled. | ||
| CVE-2019-15683 | Cri | 0.65 | 9.8 | 0.19 | Oct 29, 2019 | TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via… | ||
| CVE-2019-15679 | Cri | 0.65 | 9.8 | 0.12 | Oct 29, 2019 | TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity. | ||
| CVE-2019-15678 | Cri | 0.65 | 9.8 | 0.12 | Oct 29, 2019 | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity. | ||
| CVE-2019-10749 | Cri | 0.57 | 9.8 | 0.01 | Oct 29, 2019 | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect. | ||
| CVE-2019-10748 | Cri | 0.57 | 9.8 | 0.01 | Oct 29, 2019 | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects. | ||
| CVE-2019-10211 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2019 | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. | ||
| CVE-2012-1187 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2019 | Bitlbee does not drop extra group privileges correctly in unix.c | ||
| CVE-2010-3375 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2019 | qtparted has insecure library loading which may allow arbitrary code execution | ||
| CVE-2009-3887 | Cri | 0.64 | 9.8 | 0.03 | Oct 29, 2019 | ytnef has directory traversal | ||
| CVE-2019-18189 | Cri | 0.64 | 9.8 | 0.05 | Oct 28, 2019 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not… | ||
| CVE-2019-17181 | Cri | 0.71 | 9.8 | 0.49 | Oct 28, 2019 | A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system. | ||
| CVE-2019-14450 | Cri | 0.65 | 9.8 | 0.10 | Oct 28, 2019 | A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external… | ||
| CVE-2019-16897 | — | Cri | 0.64 | 9.8 | 0.02 | Oct 28, 2019 | In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in… | |
| CVE-2010-4239 | Cri | 0.65 | 9.8 | 0.13 | Oct 28, 2019 | Tiki Wiki CMS Groupware 5.2 has Local File Inclusion | ||
| CVE-2009-4899 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2019 | pixelpost 1.7.1 has SQL injection | ||
| CVE-2002-2444 | Cri | 0.57 | 9.8 | 0.02 | Oct 28, 2019 | Snoopy before 2.0.0 has a security hole in exec cURL | ||
| CVE-2019-14931 | Cri | 0.71 | 9.8 | 0.58 | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user… | ||
| CVE-2019-14930 | Cri | 0.64 | 9.8 | 0.02 | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the… | ||
| CVE-2019-14929 | Cri | 0.64 | 9.8 | 0.02 | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak… | ||
| CVE-2019-14926 | Cri | 0.64 | 9.8 | 0.02 | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial… | ||
| CVE-2019-16662 | Cri | 0.75 | 9.8 | 0.98 | Oct 28, 2019 | An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution. | ||
| CVE-2017-14742 | Cri | 0.64 | 9.8 | 0.03 | Oct 25, 2019 | Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely. | ||
| CVE-2019-5129 | Cri | 0.67 | 9.8 | 0.39 | Oct 25, 2019 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The… | ||
| CVE-2019-5128 | Cri | 0.66 | 9.8 | 0.30 | Oct 25, 2019 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The… | ||
| CVE-2019-5127 | Cri | 0.67 | 9.8 | 0.45 | Oct 25, 2019 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The… | ||
| CVE-2019-5114 | Cri | 0.64 | 9.9 | 0.01 | Oct 25, 2019 | An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,… |
- risk 0.64cvss 9.8epss 0.02
FreeTDS through 1.1.11 has a Buffer Overflow.
- risk 0.65cvss 10.0epss 0.03
An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua…
- risk 0.64cvss 9.8epss 0.02
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
- risk 0.59cvss 9.1epss 0.02
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
- risk 0.59cvss 9.1epss 0.02
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
- risk 0.65cvss 10.0epss 0.02
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to…
- risk 0.65cvss 10.0epss 0.02
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this…
- risk 0.64cvss 9.8epss 0.03
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
- risk 0.64cvss 9.8epss 0.01
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL…
- risk 0.64cvss 9.8epss 0.02
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the…
- risk 0.64cvss 9.8epss 0.01
burn allows file names to escape via mishandled quotation marks
- risk 0.59cvss 9.1epss 0.01
python-docutils allows insecure usage of temporary files
- risk 0.64cvss 9.8epss 0.01
overkill has buffer overflow via long player names that can corrupt data on the server machine
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table…
- risk 0.64cvss 9.8epss 0.02
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
- risk 0.64cvss 9.8epss 0.01
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.
- risk 0.57cvss 9.8epss 0.01
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.
- risk 0.57cvss 9.8epss 0.01
columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.
- risk 0.64cvss 9.8epss 0.03
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability…
- risk 0.72cvss 9.8epss 0.67
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
- risk 0.65cvss 9.8epss 0.19
TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.
- risk 0.64cvss 9.8epss 0.01
Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553,…
- risk 0.57cvss 9.8epss 0.02
In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.
- risk 0.65cvss 9.8epss 0.19
TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via…
- risk 0.65cvss 9.8epss 0.12
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.
- risk 0.65cvss 9.8epss 0.12
TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.
- risk 0.57cvss 9.8epss 0.01
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.
- risk 0.57cvss 9.8epss 0.01
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
- risk 0.64cvss 9.8epss 0.02
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
- risk 0.64cvss 9.8epss 0.02
Bitlbee does not drop extra group privileges correctly in unix.c
- risk 0.64cvss 9.8epss 0.02
qtparted has insecure library loading which may allow arbitrary code execution
- risk 0.64cvss 9.8epss 0.03
ytnef has directory traversal
- risk 0.64cvss 9.8epss 0.05
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not…
- risk 0.71cvss 9.8epss 0.49
A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system.
- risk 0.65cvss 9.8epss 0.10
A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external…
- risk 0.64cvss 9.8epss 0.02
In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in…
- risk 0.65cvss 9.8epss 0.13
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
- risk 0.64cvss 9.8epss 0.01
pixelpost 1.7.1 has SQL injection
- risk 0.57cvss 9.8epss 0.02
Snoopy before 2.0.0 has a security hole in exec cURL
- risk 0.71cvss 9.8epss 0.58
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial…
- risk 0.75cvss 9.8epss 0.98
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.
- risk 0.64cvss 9.8epss 0.03
Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.
- risk 0.67cvss 9.8epss 0.39
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…
- risk 0.66cvss 9.8epss 0.30
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…
- risk 0.67cvss 9.8epss 0.45
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…
- risk 0.64cvss 9.9epss 0.01
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,…