87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,201–1,250 of 1,734 in KEV · page 25 of 35

IDTitleSummary
CVE-2019-7192QNAP Photo Station Improper Access Control Vulnerability
KEVQNAP
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
CVE-2019-6693Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
KEVCVSS 6.5Fortinet
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup f…
CVE-2019-6340Drupal Core Remote Code Execution Vulnerability
KEVDrupal
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2019-6223Apple iOS and macOS Group Facetime Vulnerability
KEVApple
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly …
CVE-2019-5825Google Chromium V8 Out-of-Bounds Write Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML…
CVE-2019-5786Google Chrome Blink Use-After-Free Vulnerability
KEVGoogle
Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML …
CVE-2019-5591Fortinet FortiOS Default Configuration Vulnerability
KEVCVSS 6.5Fortinet
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive informatio…
CVE-2019-5544VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
KEVVMware
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to …
CVE-2019-5418Rails Ruby on Rails Path Traversal Vulnerability
KEVRails
Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can ca…
CVE-2019-4716IBM Planning Analytics Remote Code Execution Vulnerability
KEVIBM
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYS…
CVE-2019-3929Crestron Multiple Products Command Injection Vulnerability
KEVCrestron
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnera…
CVE-2019-3568WhatsApp VOIP Stack Buffer Overflow Vulnerability
KEVMeta Platforms
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
CVE-2019-3398Atlassian Confluence Server and Data Center Path Traversal Vulnerability
KEVAtlassian
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote a…
CVE-2019-3396Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
KEVAtlassian
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and rem…
CVE-2019-3010Oracle Solaris Privilege Escalation Vulnerability
KEVOracle
Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2019-2725Oracle WebLogic Server, Injection
KEVCVSS 9.8Oracle
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CVE-2019-2616Oracle BI Publisher Unauthorized Access Vulnerability
KEVOracle
Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attribut…
CVE-2019-2215Android Kernel Use-After-Free Vulnerability
KEVAndroid
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerabi…
CVE-2019-20500D-Link DWL-2600AP Access Point Command Injection Vulnerability
KEVD-Link
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using s…
CVE-2019-20085TVT NVMS-1000 Directory Traversal Vulnerability
KEVTVT
TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
CVE-2019-19781Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
KEVCVSS 9.8Citrix
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker…
CVE-2019-19356Netis WF2419 Devices Remote Code Execution Vulnerability
KEVNetis
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management…
CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability
KEVCVSS 9.8Sangoma
Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access servi…
CVE-2019-18988TeamViewer Desktop Bypass Remote Login Vulnerability
KEVTeamViewer
TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker wer…
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
KEVProgress
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the ser…
CVE-2019-18426WhatsApp Cross-Site Scripting Vulnerability
KEVMeta Platforms
A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2019-18187Trend Micro OfficeScan Directory Traversal Vulnerability
KEVTrend Micro
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading …
CVE-2019-17621D-Link DIR-859 Router Command Execution Vulnerability
KEVD-Link
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to…
CVE-2019-17558Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
KEVApache
The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-17026Mozilla Firefox And Thunderbird Type Confusion Vulnerability
KEVMozilla
Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elem…
CVE-2019-16928Exim Out-of-bounds Write Vulnerability
KEVExim
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
CVE-2019-16920D-Link Multiple Routers Command Injection Vulnerability
KEVD-Link
Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
CVE-2019-16759vBulletin PHP Module Remote Code Execution Vulnerability
KEVvBulletin
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/ren…
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
KEVCisco
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download t…
CVE-2019-1652Cisco Small Business Routers Improper Input Validation Vulnerability
KEVCisco
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote…
CVE-2019-16278Nostromo nhttpd Directory Traversal Vulnerability
KEVNostromo
Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
CVE-2019-16256SIMalliance Toolbox Browser Command Injection Vulnerability
KEVSIMalliance
SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute …
CVE-2019-16057D-Link DNS-320 Remote Code Execution Vulnerability
KEVD-Link
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
CVE-2019-15949Nagios XI Remote Code Execution Vulnerability
KEVNagios
Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as roo…
CVE-2019-1579Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
KEVCVSS 8.1Palo Alto Networks
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
CVE-2019-15752Docker Desktop Community Edition Privilege Escalation Vulnerability
KEVDocker
Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred…
CVE-2019-15271Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
KEVCisco
A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attack…
CVE-2019-15107Webmin Command Injection Vulnerability
KEVCVSS 9.8Webmin
An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.
CVE-2019-1458Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
CVE-2019-1429Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
CVE-2019-1405Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
CVE-2019-1388Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
CVE-2019-1385Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system…
CVE-2019-13720Google Chrome WebAudio Use-After-Free Vulnerability
KEVGoogle
Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-1367Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows fo…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.