Total
10067 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-0768 | 1 Microsoft | 3 Internet Explorer, Windows 10, Windows Server 2019 | 2024-02-04 | 4.3 MEDIUM | 4.3 MEDIUM |
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761. | |||||
CVE-2018-20981 | 1 Ninjaforms | 1 Ninja Forms | 2024-02-04 | 6.4 MEDIUM | 9.1 CRITICAL |
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. | |||||
CVE-2019-9864 | 1 Amazon Affiliate Store Project | 1 Amazon Affiliate Store | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount. | |||||
CVE-2019-3479 | 1 Hp | 1 Arcsight Logger | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7. | |||||
CVE-2018-15737 | 1 Stopzilla | 1 Antimalware | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x80002043. | |||||
CVE-2017-9376 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2024-02-04 | 5.0 MEDIUM | 6.5 MEDIUM |
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do. | |||||
CVE-2019-1800 | 1 Cisco | 2 Wireless Lan Controller, Wireless Lan Controller Software | 2024-02-04 | 6.1 MEDIUM | 6.5 MEDIUM |
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit the vulnerability by sending malicious IAPP messages to an affected device. A successful exploit could allow the attacker to cause the Cisco WLC Software to reload, resulting in a DoS condition. Software versions prior to 8.2.170.0, 8.5.150.0, and 8.8.100.0 are affected. | |||||
CVE-2016-10855 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 10.0 HIGH | 9.8 CRITICAL |
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). | |||||
CVE-2019-1711 | 1 Cisco | 1 Ios Xr | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of gRPC requests. An attacker could exploit this vulnerability by repeatedly sending unauthenticated gRPC requests to the affected device. A successful exploit could cause the emsd process to crash, resulting in a DoS condition. Resolved in Cisco IOS XR 6.5.1 and later. | |||||
CVE-2016-10807 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). | |||||
CVE-2019-13612 | 1 Altn | 1 Mdaemon Email Server | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a customer deploys a server with sufficient resources to scan large messages. | |||||
CVE-2019-9794 | 2 Microsoft, Mozilla | 4 Windows, Firefox, Firefox Esr and 1 more | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. | |||||
CVE-2018-4446 | 1 Apple | 1 Iphone Os | 2024-02-04 | 4.3 MEDIUM | 3.3 LOW |
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1. | |||||
CVE-2017-16775 | 1 Synology | 1 Sso Server | 2024-02-04 | 5.8 MEDIUM | 6.1 MEDIUM |
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |||||
CVE-2016-10808 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 9.0 HIGH | 8.8 HIGH |
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113). | |||||
CVE-2018-4279 | 1 Apple | 1 Safari | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2. | |||||
CVE-2019-10074 | 1 Apache | 1 Ofbiz | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533 | |||||
CVE-2019-0115 | 1 Intel | 1 Graphics Driver | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial of service via local access. | |||||
CVE-2018-18878 | 1 Columbiaweather | 2 Weather Microserver, Weather Microserver Firmware | 2024-02-04 | 7.8 HIGH | 7.5 HIGH |
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable. | |||||
CVE-2018-6138 | 1 Google | 1 Chrome | 2024-02-04 | 5.8 MEDIUM | 8.1 HIGH |
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. |