87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,251–1,300 of 1,734 in KEV · page 26 of 35

IDTitleSummary
CVE-2019-13608Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
KEVCitrix
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sens…
CVE-2019-13272Linux Kernel Improper Privilege Management Vulnerability
KEVLinux
Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
CVE-2019-1322Microsoft Windows Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability …
CVE-2019-1315Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vul…
CVE-2019-12991Citrix SD-WAN and NetScaler Command Injection Vulnerability
KEVCitrix
Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
CVE-2019-12989Citrix SD-WAN and NetScaler SQL Injection Vulnerability
KEVCitrix
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
CVE-2019-1297Microsoft Excel Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
CVE-2019-1253Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
CVE-2019-1215Microsoft Windows Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Succ…
CVE-2019-1214Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.
CVE-2019-11708Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
KEVMozilla
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-11707Mozilla Firefox and Thunderbird Type Confusion Vulnerability
KEVMozilla
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing…
CVE-2019-11634Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
KEVCVSS 9.8Citrix
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enfo…
CVE-2019-11581Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
KEVAtlassian
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
CVE-2019-11580Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability
KEVAtlassian
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in…
CVE-2019-11539Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
KEVIvanti
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
CVE-2019-11510Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
KEVIvanti
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send …
CVE-2019-1132Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2019-1130Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
CVE-2019-1129Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could…
CVE-2019-11043PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
KEVPHP
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of …
CVE-2019-11001Reolink Multiple IP Cameras OS Command Injection Vulnerability
KEVReolink
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an a…
CVE-2019-10758MongoDB mongo-express Remote Code Execution Vulnerability
KEVMongoDB
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
CVE-2019-1069Microsoft Task Scheduler Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
CVE-2019-1068Microsoft SQL Server Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engi…
CVE-2019-1064Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could…
CVE-2019-10149Exim Mail Transfer Agent (MTA) Improper Input Validation
KEVExim
Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2019-10068Kentico Xperience Deserialization of Untrusted Data Vulnerability
KEVKentico
Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.
CVE-2019-1003030Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
KEVJenkins
Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2019-1003029Jenkins Script Security Plugin Sandbox Bypass Vulnerability
KEVJenkins
Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
CVE-2019-0903Microsoft GDI Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who success…
CVE-2019-0880Microsoft Windows Privilege Escalation Vulnerability
KEVMicrosoft
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could e…
CVE-2019-0863Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mo…
CVE-2019-0859Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2019-0841Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could…
CVE-2019-0808Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allow…
CVE-2019-0803Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploita…
CVE-2019-0797Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation al…
CVE-2019-0752Microsoft Internet Explorer Type Confusion Vulnerability
KEVCVSS 7.5Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
CVE-2019-0708Microsoft Remote Desktop Services Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect…
CVE-2019-0703Microsoft Windows SMB Information Disclosure Vulnerability
KEVMicrosoft
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from…
CVE-2019-0676Microsoft Internet Explorer Information Disclosure Vulnerability
KEVMicrosoft
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnera…
CVE-2019-0604Microsoft SharePoint Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code …
CVE-2019-0543Microsoft Windows Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability …
CVE-2019-0541Microsoft MSHTML Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
CVE-2019-0344SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
KEVSAP
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension t…
CVE-2019-0211Apache HTTP Server Privilege Escalation Vulnerability
KEVApache
Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-proces…
CVE-2019-0193Apache Solr DataImportHandler Code Injection Vulnerability
KEVApache
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CVE-2018-9276Paessler PRTG Network Monitor OS Command Injection Vulnerability
KEVPaessler
Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the…
CVE-2018-8653Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execut…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.