Search Results (323689 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-17613 1 Qibosoft 1 Qibosoft 2024-11-21 9.8 Critical
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.
CVE-2019-17612 1 74cms 1 74cms 2024-11-21 7.2 High
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2019-17611 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
CVE-2019-17610 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
CVE-2019-17609 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.
CVE-2019-17608 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php dbname parameter.
CVE-2019-17607 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php servername parameter.
CVE-2019-17606 1 Hexo-admin Project 1 Hexo-admin 2024-11-21 6.1 Medium
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
CVE-2019-17605 1 Eyecomms 1 Eyecms 2024-11-21 8.8 High
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.
CVE-2019-17604 1 Eyecomms 1 Eyecms 2024-11-21 4.3 Medium
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV, phone number, and all other personal information) by changing the value of the candidate id (the id parameter).
CVE-2019-17603 1 Asus 1 Aura Sync 2024-11-21 7.8 High
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
CVE-2019-17602 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 9.8 Critical
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
CVE-2019-17601 1 Minishare Project 1 Minishare 2024-11-21 9.8 Critical
In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19862 and CVE-2018-19861. NOTE: this product is discontinued.
CVE-2019-17600 1 Intelbras 2 Iwr 1000n, Iwr 1000n Firmware 2024-11-21 9.8 Critical
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
CVE-2019-17599 1 Expresstech 1 Quiz And Survey Master 2024-11-21 6.1 Medium
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
CVE-2019-17598 1 Lightbend 1 Play Framework 2024-11-21 7.5 High
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.
CVE-2019-17596 6 Arista, Debian, Fedoraproject and 3 more 13 Cloudvision Portal, Eos, Mos and 10 more 2024-11-21 7.5 High
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
CVE-2019-17595 3 Gnu, Opensuse, Redhat 3 Ncurses, Leap, Enterprise Linux 2024-11-21 5.4 Medium
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17594 3 Gnu, Opensuse, Redhat 3 Ncurses, Leap, Enterprise Linux 2024-11-21 5.3 Medium
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17593 1 Jizhicms 1 Jizhicms 2024-11-21 8.8 High
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.