Vulnerabilities (CVE)
1,704 pages, showing 401–500, ordered by identifier.
- CVE-2018-14933 — NUUO NVRmini Devices OS Command Injection Vulnerability NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command...
- CVE-2018-15133 — Laravel Deserialization of Untrusted Data Vulnerability Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution....
- CVE-2018-15811 — DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak...
- CVE-2018-15961 — Adobe ColdFusion Unrestricted File Upload Vulnerability Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
- CVE-2018-15982 — Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
- CVE-2018-17463 — Google Chromium V8 Remote Code Execution Vulnerability Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside...
- CVE-2018-17480 — Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code...
- CVE-2018-18325 — DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak...
- CVE-2018-18809 — TIBCO JasperReports Library Directory Traversal Vulnerability TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access...
- CVE-2018-19320 — GIGABYTE Multiple Products Unspecified Vulnerability The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II...
- CVE-2018-19321 — GIGABYTE Multiple Products Privilege Escalation Vulnerability The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC...
- CVE-2018-19322 — GIGABYTE Multiple Products Code Execution Vulnerability The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC...
- CVE-2018-19323 — GIGABYTE Multiple Products Privilege Escalation Vulnerability The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC...
- CVE-2018-19410 — Paessler PRTG Network Monitor Local File Inclusion Vulnerability Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated...
- CVE-2018-19943 — QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
- CVE-2018-19949 — QNAP NAS File Station Command Injection Vulnerability A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
- CVE-2018-19953 — QNAP NAS File Station Cross-Site Scripting Vulnerability A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
- CVE-2018-20062 — ThinkPHP 'noneCms' Remote Code Execution Vulnerability ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use...
- CVE-2018-20250 — WinRAR Absolute Path Traversal Vulnerability WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
- CVE-2018-20753 — Kaseya VSA Remote Code Execution Vulnerability Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
- CVE-2018-2380 — SAP Customer Relationship Management (CRM) Path Traversal Vulnerability SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to...
- CVE-2018-2628 — Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3...
- CVE-2018-4063 — Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially...
- CVE-2018-4344 — Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
- CVE-2018-4878 — Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
- CVE-2018-4939 — Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
- CVE-2018-4990 — Adobe Acrobat and Reader Double Free Vulnerability Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
- CVE-2018-5002 — Adobe Flash Player Stack-based Buffer Overflow Vulnerability Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
- CVE-2018-5430 — TIBCO JasperReports Server Information Disclosure Vulnerability TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the...
- CVE-2018-6065 — Google Chromium V8 Integer Overflow Vulnerability Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially...
- CVE-2018-6530 — D-Link Multiple Routers OS Command Injection Vulnerability Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
- CVE-2018-6789 — Exim Buffer Overflow Vulnerability Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for...
- CVE-2018-6882 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote...
- CVE-2018-6961 — VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful...
- CVE-2018-7445 — MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote...
- CVE-2018-7600 — Drupal Core Remote Code Execution Vulnerability Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack...
- CVE-2018-7602 — Drupal Core Remote Code Execution Vulnerability A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to...
- CVE-2018-7841 — Schneider Electric U.motion Builder SQL Injection Vulnerability A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an...
- CVE-2018-8120 — Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
- CVE-2018-8174 — Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka...
- CVE-2018-8298 — ChakraCore Scripting Engine Type Confusion Vulnerability The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
- CVE-2018-8373 — Microsoft Scripting Engine Memory Corruption Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in...
- CVE-2018-8405 — Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles...
- CVE-2018-8406 — Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles...
- CVE-2018-8414 — Microsoft Windows Shell Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
- CVE-2018-8440 — Microsoft Windows Privilege Escalation Vulnerability An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
- CVE-2018-8453 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
- CVE-2018-8581 — Microsoft Exchange Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited...
- CVE-2018-8589 — Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who...
- CVE-2018-8611 — Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
- CVE-2018-8639 — Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local,...
- CVE-2018-8653 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles...
- CVE-2018-9276 — Paessler PRTG Network Monitor OS Command Injection Vulnerability Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with...
- CVE-2019-0193 — Apache Solr DataImportHandler Code Injection Vulnerability The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
- CVE-2019-0211 — Apache HTTP Server Privilege Escalation Vulnerability Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads...
- CVE-2019-0344 — SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the...
- CVE-2019-0541 — Microsoft MSHTML Remote Code Execution Vulnerability Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution...
- CVE-2019-0543 — Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who...
- CVE-2019-0604 — Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully...
- CVE-2019-0676 — Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An...
- CVE-2019-0703 — Microsoft Windows SMB Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests,...
- CVE-2019-0708 — Microsoft Remote Desktop Services Remote Code Execution Vulnerability Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that...
- CVE-2019-0752 — Microsoft Internet Explorer Type Confusion Vulnerability A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in...
- CVE-2019-0797 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle...
- CVE-2019-0803 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory...
- CVE-2019-0808 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle...
- CVE-2019-0841 — Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who...
- CVE-2019-0859 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation...
- CVE-2019-0863 — Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles...
- CVE-2019-0880 — Microsoft Windows Privilege Escalation Vulnerability A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who...
- CVE-2019-0903 — Microsoft GDI Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles...
- CVE-2019-1003029 — Jenkins Script Security Plugin Sandbox Bypass Vulnerability Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
- CVE-2019-1003030 — Jenkins Matrix Project Plugin Remote Code Execution Vulnerability Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening...
- CVE-2019-10068 — Kentico Xperience Deserialization of Untrusted Data Vulnerability Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code...
- CVE-2019-10149 — Exim Mail Transfer Agent (MTA) Improper Input Validation Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command...
- CVE-2019-1064 — Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who...
- CVE-2019-1068 — Microsoft SQL Server Remote Code Execution Vulnerability Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in...
- CVE-2019-1069 — Microsoft Task Scheduler Privilege Escalation Vulnerability A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
- CVE-2019-10758 — MongoDB mongo-express Remote Code Execution Vulnerability mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the toBSON method.
- CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection...
- CVE-2019-11043 — PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past...
- CVE-2019-1129 — Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who...
- CVE-2019-1130 — Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
- CVE-2019-1132 — Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
- CVE-2019-11510 — Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote...
- CVE-2019-11539 — Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to...
- CVE-2019-11580 — Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall...
- CVE-2019-11581 — Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for...
- CVE-2019-11634 — Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from...
- CVE-2019-11707 — Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript...
- CVE-2019-11708 — Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
- CVE-2019-1214 — Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for...
- CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in...
- CVE-2019-1253 — Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
- CVE-2019-1297 — Microsoft Excel Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
- CVE-2019-12989 — Citrix SD-WAN and NetScaler SQL Injection Vulnerability Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
- CVE-2019-12991 — Citrix SD-WAN and NetScaler Command Injection Vulnerability Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.
- CVE-2019-1315 — Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An...
- CVE-2019-1322 — Microsoft Windows Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who...
- CVE-2019-13272 — Linux Kernel Improper Privilege Management Vulnerability Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.