Search Results (323568 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-17387 4 Apple, Aviatrix, Linux and 1 more 4 Macos, Vpn Client, Linux Kernel and 1 more 2024-11-21 7.8 High
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
CVE-2019-17386 1 Eleopard 1 Animate It\! 2024-11-21 8.8 High
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
CVE-2019-17385 1 Eleopard 1 Animate It\! 2024-11-21 6.1 Medium
The animate-it plugin before 2.3.5 for WordPress has XSS.
CVE-2019-17384 1 Eleopard 1 Animate It\! 2024-11-21 6.1 Medium
The animate-it plugin before 2.3.4 for WordPress has XSS.
CVE-2019-17383 1 Netaddr Project 1 Netaddr 2024-11-21 9.8 Critical
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
CVE-2019-17382 1 Zabbix 1 Zabbix 2024-11-21 9.1 Critical
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
CVE-2019-17380 1 Cpanel 1 Cpanel 2024-11-21 6.1 Medium
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
CVE-2019-17379 1 Cpanel 1 Cpanel 2024-11-21 6.1 Medium
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
CVE-2019-17378 1 Cpanel 1 Cpanel 2024-11-21 6.1 Medium
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
CVE-2019-17377 1 Cpanel 1 Cpanel 2024-11-21 6.1 Medium
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
CVE-2019-17376 1 Cpanel 1 Cpanel 2024-11-21 6.1 Medium
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
CVE-2019-17375 1 Cpanel 1 Cpanel 2024-11-21 8.8 High
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
CVE-2019-17373 1 Netgear 20 Dgn2200, Dgn2200 Firmware, Dgn2200m and 17 more 2024-11-21 9.8 Critical
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
CVE-2019-17372 1 Netgear 66 Ac1450, Ac1450 Firmware, D8500 and 63 more 2024-11-21 8.1 High
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
CVE-2019-17371 1 Gif2png Project 1 Gif2png 2024-11-21 6.5 Medium
gif2png 2.5.13 has a memory leak in the writefile function.
CVE-2019-17370 1 Otcms 1 Otcms 2024-11-21 7.2 High
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.
CVE-2019-17369 1 Otcms 1 Otcms 2024-11-21 6.5 Medium
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
CVE-2019-17368 1 S-cms 1 S-cms 2024-11-21 6.1 Medium
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
CVE-2019-17367 1 Openwrt 1 Openwrt 2024-11-21 8.8 High
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.
CVE-2019-17366 1 Citrix 1 Application Delivery Management 2024-11-21 8.8 High
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.