CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2020-2051

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2052

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2053

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2054

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2056

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2057

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2058

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2059

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2061

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2062

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2064

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2065

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2068

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2069

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2072

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2073

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2074

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2067

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    8.8
    High

    CVE-2013-7325

    Last Modified: 21 Nov 2024

    An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.

    Published: 3 Dec 2019
    5.3
    Medium

    CVE-2015-7542

    Last Modified: 21 Nov 2024

    A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.

    Published: 3 Dec 2019
    7.8
    High

    CVE-2019-5164

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.

    Published: 3 Dec 2019
    —
    Unknown

    CVE-2016-1000021

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10538. Reason: This candidate is a duplicate of CVE-2016-10538. Notes: All CVE users should reference CVE-2016-10538 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Dec 2019
    7.5
    High

    CVE-2019-5163

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.

    Published: 3 Dec 2019
    9.8
    Critical

    CVE-2019-5096

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.

    Published: 3 Dec 2019
    7.5
    High

    CVE-2019-5097

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST requests and does not require the requested resource to exist on the server.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5110

    Last Modified: 21 Nov 2024

    Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5109

    Last Modified: 21 Nov 2024

    Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5112

    Last Modified: 21 Nov 2024

    Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_status was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5111

    Last Modified: 21 Nov 2024

    Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_cat was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5133

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5132

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear 19.3.0 library. A specially crafted GEM file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5076

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG header-parser of the Accusoft ImageGear 19.3.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the viction to trigger the vulnerability.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-5083

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft ImageGear 19.3.0 library. A specially crafted TIFF file can cause an out of bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 3 Dec 2019
    5.5
    Medium

    CVE-2019-3750

    Last Modified: 21 Nov 2024

    Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.

    Published: 3 Dec 2019
    5.5
    Medium

    CVE-2019-3749

    Last Modified: 21 Nov 2024

    Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.

    Published: 3 Dec 2019
    4.8
    Medium

    CVE-2019-18574

    Last Modified: 21 Nov 2024

    RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.

    Published: 3 Dec 2019
    7.5
    High

    CVE-2019-10013

    Last Modified: 21 Nov 2024

    The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

    Published: 3 Dec 2019
    7.5
    High

    CVE-2019-9689

    Last Modified: 21 Nov 2024

    process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certificate handshake message with zero certificates.

    Published: 3 Dec 2019
    9.8
    Critical

    CVE-2019-16885

    Last Modified: 21 Nov 2024

    In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via the cookie comparison.

    Published: 3 Dec 2019
    5.4
    Medium

    CVE-2019-18992

    Last Modified: 21 Nov 2024

    OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).

    Published: 3 Dec 2019
    5.4
    Medium

    CVE-2019-18993

    Last Modified: 21 Nov 2024

    OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).

    Published: 3 Dec 2019
    7.8
    High

    CVE-2019-19382

    Last Modified: 21 Nov 2024

    Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation.

    Published: 3 Dec 2019
    8.8
    High

    CVE-2019-19383

    Last Modified: 21 Nov 2024

    freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).

    Published: 3 Dec 2019
    5.4
    Medium

    CVE-2019-19457

    Last Modified: 21 Nov 2024

    SALTO ProAccess SPACE 5.4.3.0 allows XSS.

    Published: 3 Dec 2019
    8.6
    High

    CVE-2019-19458

    Last Modified: 21 Nov 2024

    SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.

    Published: 3 Dec 2019
    9.8
    Critical

    CVE-2019-19459

    Last Modified: 21 Nov 2024

    An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

    Published: 3 Dec 2019
    5.5
    Medium

    CVE-2019-19460

    Last Modified: 21 Nov 2024

    An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.

    Published: 3 Dec 2019
    7.8
    High

    CVE-2019-7366

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into opening a malicious FBX file which may exploit a buffer overflow vulnerability causing it to run arbitrary code on the system.

    Published: 3 Dec 2019
    7.8
    High

    CVE-2019-7365

    Last Modified: 21 Nov 2024

    DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.

    Published: 3 Dec 2019
    4.3
    Medium

    CVE-2019-3990

    Last Modified: 21 Nov 2024

    A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

    Published: 3 Dec 2019