Search Results (323571 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15860 1 Glyphandcog 1 Xpdfreader 2024-11-21 N/A
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
CVE-2019-15859 1 Socomec 2 Diris A-40, Diris A-40 Firmware 2024-11-21 9.8 Critical
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.
CVE-2019-15858 1 Webcraftic 1 Woody Ad Snippets 2024-11-21 8.8 High
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
CVE-2019-15855 1 Maarch 1 Maarch Rm 2024-11-21 9.1 Critical
An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the default installation procedure was followed. This results in a permanent Denial of Service.
CVE-2019-15854 1 Maarch 1 Maarch Rm 2024-11-21 8.8 High
An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration privileges via a crafted PUT request to an unauthorized resource.
CVE-2019-15850 1 Eq-3 2 Homematic Ccu3, Homematic Ccu3 Firmware 2024-11-21 8.8 High
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.
CVE-2019-15849 1 Eq-3 2 Homematic Ccu3, Homematic Ccu3 Firmware 2024-11-21 7.3 High
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could create SSH logins after a valid session and easily compromise the system.
CVE-2019-15848 1 Jetbrains 1 Teamcity 2024-11-21 N/A
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
CVE-2019-15847 3 Gnu, Opensuse, Redhat 4 Gcc, Leap, Enterprise Linux and 1 more 2024-11-21 7.5 High
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.
CVE-2019-15846 2 Debian, Exim 2 Debian Linux, Exim 2024-11-21 N/A
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
CVE-2019-15845 3 Canonical, Redhat, Ruby-lang 6 Ubuntu Linux, Enterprise Linux, Rhel E4s and 3 more 2024-11-21 6.5 Medium
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
CVE-2019-15843 1 Mi 1 Xiaomi Millet Firmware 2024-11-21 7.4 High
A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle attack may lead to partial data leakage or malicious file writing.
CVE-2019-15842 1 Easy Pdf Restaurant Menu Upload Project 1 Easy Pdf Restaurant Menu Upload 2024-11-21 N/A
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
CVE-2019-15841 1 Facebook 1 Facebook For Woocommerce 2024-11-21 N/A
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
CVE-2019-15840 1 Facebook 1 Facebook For Woocommerce 2024-11-21 N/A
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
CVE-2019-15838 1 Kunalnagar 1 Custom 404 Pro 2024-11-21 N/A
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
CVE-2019-15837 1 Bitwise-it 1 Webp Express 2024-11-21 N/A
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15836 1 Bootstrapped 1 Wp Ultimate Recipe 2024-11-21 N/A
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
CVE-2019-15835 1 Wp Better Permalinks Project 1 Wp Better Permalinks 2024-11-21 N/A
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
CVE-2019-15834 1 Webp Converter For Media Project 1 Webp Converter For Media 2024-11-21 N/A
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.