CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-10748

    Last Modified: 21 Nov 2024

    Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-3977

    Last Modified: 21 Nov 2024

    RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly reseting all the system's usernames and passwords.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-3979

    Last Modified: 21 Nov 2024

    RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can poison the router's DNS cache via malicious responses with additional and untrue records.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-3978

    Last Modified: 21 Nov 2024

    RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning

    Published: 28 Oct 2019
    8.8
    High

    CVE-2019-3976

    Last Modified: 21 Nov 2024

    RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2012-2945

    Last Modified: 21 Nov 2024

    Hadoop 1.0.3 contains a symlink vulnerability.

    Published: 28 Oct 2019
    7.2
    High

    CVE-2011-2538

    Last Modified: 21 Nov 2024

    Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-18187

    Last Modified: 30 Oct 2025

    Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-18188

    Last Modified: 21 Nov 2024

    Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to the IUSR account, which has restricted permission and is unable to make major system changes. An attempted attack requires user authentication.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-18189

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2017-5678

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-13069. Reason: This candidate is a reservation duplicate of CVE-2017-13069. Notes: All CVE users should reference CVE-2017-13069 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Oct 2019
    7.5
    High

    CVE-2017-15725

    Last Modified: 21 Nov 2024

    An XML External Entity Injection vulnerability exists in Dzone AnswerHub.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-14450

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-17181

    Last Modified: 21 Nov 2024

    A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2012-5577

    Last Modified: 21 Nov 2024

    Python keyring lib before 0.10 created keyring files with world-readable permissions.

    Published: 28 Oct 2019
    6.5
    Medium

    CVE-2019-5536

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

    Published: 28 Oct 2019
    5.9
    Medium

    CVE-2019-5538

    Last Modified: 21 Nov 2024

    Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over SCP. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.

    Published: 28 Oct 2019
    5.9
    Medium

    CVE-2019-5537

    Last Modified: 21 Nov 2024

    Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-16897

    Last Modified: 21 Nov 2024

    In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in the K7AVOptn.dll module to facilitate escalation of privileges via inter-process communication with a service process.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2010-4239

    Last Modified: 21 Nov 2024

    Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

    Published: 28 Oct 2019
    6.1
    Medium

    CVE-2010-4240

    Last Modified: 21 Nov 2024

    Tiki Wiki CMS Groupware 5.2 has XSS

    Published: 28 Oct 2019
    8.8
    High

    CVE-2010-4241

    Last Modified: 21 Nov 2024

    Tiki Wiki CMS Groupware 5.2 has CSRF

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18564

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18565

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18566

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18531

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18544

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18554

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18527

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18528

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18529

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18530

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18532

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18533

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18534

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18535

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18536

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18537

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18538

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18539

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18540

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18541

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18542

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18543

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18545

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18546

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18547

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18548

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18549

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18550

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019