Search Results (323620 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-17430 1 Eyoucms 1 Eyoucms 2024-11-21 6.1 Medium
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
CVE-2019-17429 1 Adhouma Cms Project 1 Adhouma Cms 2024-11-21 9.8 Critical
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
CVE-2019-17428 1 Intesync 1 Solismed 2024-11-21 5.9 Medium
An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
CVE-2019-17427 1 Redmine 1 Redmine 2024-11-21 6.1 Medium
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
CVE-2019-17426 1 Mongoosejs 1 Mongoose 2024-11-21 9.1 Critical
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).
CVE-2019-17424 1 Nipper-ng Project 1 Nipper-ng 2024-11-21 7.8 High
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.
CVE-2019-17421 1 Zohocorp 2 Manageengine Firewall Analyzer, Manageengine Opmanager 2024-11-21 7.8 High
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
CVE-2019-17420 2 Oisf, Suricata-ids 2 Libhtp, Suricata 2024-11-21 5.3 Medium
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
CVE-2019-17419 1 Metinfo 1 Metinfo 2024-11-21 7.2 High
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
CVE-2019-17418 1 Metinfo 1 Metinfo 2024-11-21 7.2 High
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
CVE-2019-17417 1 Pbootcms 1 Pbootcms 2024-11-21 4.8 Medium
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
CVE-2019-17415 1 Upredsun 1 File Sharing Wizard 2024-11-21 9.8 Critical
A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331.
CVE-2019-17414 1 Vino Project 1 Vino 2024-11-21 7.5 High
tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.
CVE-2019-17409 1 Open-emr 1 Openemr 2024-11-21 6.1 Medium
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
CVE-2019-17408 1 Zzzcms 1 Zzzphp 2024-11-21 9.8 Critical
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
CVE-2019-17406 1 Nokia 1 Impact 2024-11-21 5.3 Medium
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
CVE-2019-17405 1 Nokia 1 Impact 2024-11-21 6.1 Medium
Nokia IMPACT < 18A: has Reflected self XSS
CVE-2019-17404 1 Nokia 1 Impact 2024-11-21 4.3 Medium
Nokia IMPACT < 18A: allows full path disclosure
CVE-2019-17403 1 Nokia 1 Impact 2024-11-21 8.8 High
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
CVE-2019-17402 4 Canonical, Debian, Exiv2 and 1 more 4 Ubuntu Linux, Debian Linux, Exiv2 and 1 more 2024-11-21 6.5 Medium
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.