CVE-2019-17000 to CVE-2019-17999
143 CVEs with public proof-of-concept exploits.
- CVE-2019-170031 PoCScanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
- CVE-2019-170212 PoCsDuring the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses…
- CVE-2019-170241 PoCMozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory…
- CVE-2019-170265 PoCsKEVIncorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted…
- CVE-2019-170411 PoCAn issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX…
- CVE-2019-170451 PoCIlch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab.
- CVE-2019-170461 PoCIlch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.
- CVE-2019-170511 PoCEvernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as…
- CVE-2019-170591 PoCA shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to…
- CVE-2019-170642 PoCsCatalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
- CVE-2019-170731 PoCemlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory…
- CVE-2019-170802 PoCsmintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker,…
- CVE-2019-170912 PoCsfaces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer…
- CVE-2019-171011 PoCCommand execution due to unsanitized input in Netatmo Smart Indoor Security Camera
- CVE-2019-171141 PoCA stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers…
- CVE-2019-171151 PoCMultiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject…
- CVE-2019-171161 PoCA stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers…
- CVE-2019-171181 PoCA CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing…
- CVE-2019-171191 PoCMultiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute…
- CVE-2019-171201 PoCA stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers…
- CVE-2019-171231 PoCThe eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled,…
- CVE-2019-171243 PoCsKramer VIAware 2.5.0719.1034 has Incorrect Access Control.
- CVE-2019-171321 PoCvBulletin through 5.5.4 mishandles custom avatars.
- CVE-2019-171371 PoCThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware…
- CVE-2019-171472 PoCsThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers.…
- CVE-2019-171761 PoCGenesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor,…
- CVE-2019-171801 PoCValve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file…
- CVE-2019-171813 PoCsA remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request…
- CVE-2019-171891 PoCtotemodata 3.0.0_b936 has XSS via a folder name.
- CVE-2019-171991 PoCwww/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored…
- CVE-2019-172073 PoCsA reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin…
- CVE-2019-172131 PoCThe WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.
- CVE-2019-172141 PoCThe WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.
- CVE-2019-172202 PoCsRocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
- CVE-2019-172211 PoCPhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The…
- CVE-2019-172221 PoCAn issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen,…
- CVE-2019-172241 PoCThe web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path…
- CVE-2019-172253 PoCsSubrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
- CVE-2019-172281 PoCincludes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for…
- CVE-2019-172301 PoCincludes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
- CVE-2019-172311 PoCincludes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
- CVE-2019-172321 PoCFunctions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
- CVE-2019-172331 PoCFunctions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
- CVE-2019-172341 PoCincludes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
- CVE-2019-1724016 PoCsbl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged…
- CVE-2019-172632 PoCsIn libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap-based buffer…
- CVE-2019-172641 PoCIn libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-based buffer over-read…
- CVE-2019-172703 PoCsYachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the…
- CVE-2019-172711 PoCvBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
- CVE-2019-173551 PoCIn the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available…
- CVE-2019-173562 PoCsThe Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as…
- CVE-2019-173621 PoCIn LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid…
- CVE-2019-173641 PoCThe processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers…
- CVE-2019-173712 PoCsgif2png 2.5.13 has a memory leak in the writefile function.
- CVE-2019-173721 PoCCertain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The…
- CVE-2019-173823 PoCsAn issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and…
- CVE-2019-173871 PoCAn authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges…
- CVE-2019-173881 PoCWeak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker…
- CVE-2019-173941 PoCIn the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and…
- CVE-2019-173951 PoCIn the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be…
- CVE-2019-173981 PoCIn the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log…
- CVE-2019-174001 PoCThe unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
- CVE-2019-174011 PoClibyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of…
- CVE-2019-174031 PoCNokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
- CVE-2019-174041 PoCNokia IMPACT < 18A: allows full path disclosure
- CVE-2019-174051 PoCNokia IMPACT < 18A: has Reflected self XSS
- CVE-2019-174061 PoCNokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
- CVE-2019-174081 PoCparserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key…
- CVE-2019-174183 PoCsAn issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno…
- CVE-2019-174243 PoCsA stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers…
- CVE-2019-174271 PoCIn Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
- CVE-2019-174281 PoCAn issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data…
- CVE-2019-174441 PoCJFrog Artifactory does not enforce default admin password change
- CVE-2019-174501 PoCfind_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows…
- CVE-2019-174511 PoCAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer…
- CVE-2019-174521 PoCBento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to…
- CVE-2019-174531 PoCBento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to…
- CVE-2019-174541 PoCBento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to…
- CVE-2019-174551 PoCLibntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write…
- CVE-2019-174891 PoCJiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or…
- CVE-2019-174901 PoCapp\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated…
- CVE-2019-174911 PoCJiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or…
- CVE-2019-174931 PoCJiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or…
- CVE-2019-174953 PoCsA Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite…
- CVE-2019-174971 PoCTracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to…
- CVE-2019-175021 PoCHydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Length header.…
- CVE-2019-175033 PoCsAn issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka…
- CVE-2019-175042 PoCsAn issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows…
- CVE-2019-175051 PoCD-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An…
- CVE-2019-175063 PoCsThere are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker…
- CVE-2019-175081 PoCOn D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
- CVE-2019-175091 PoCD-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and…
- CVE-2019-175101 PoCD-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and…
- CVE-2019-175201 PoCThe Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM…
- CVE-2019-175211 PoCAn issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
- CVE-2019-175241 PoCAn XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected…
- CVE-2019-175252 PoCsThe login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct…
- CVE-2019-175261 PoCAn issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet…
- CVE-2019-175351 PoCGila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to…
- CVE-2019-175361 PoCGila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php.…
- CVE-2019-175381 PoCJiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../…
- CVE-2019-175411 PoCImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in…
- CVE-2019-175542 PoCsThe XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external…
- CVE-2019-1755811 PoCsKEVApache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template…
- CVE-2019-175648 PoCsUnsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a…
- CVE-2019-175704 PoCsAn untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka…
- CVE-2019-175712 PoCsIncluded in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely…
- CVE-2019-175721 PoCIn Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like…
- CVE-2019-175731 PoCBy default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is…
- CVE-2019-175741 PoCAn issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the…
- CVE-2019-175761 PoCAn issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via…
- CVE-2019-175771 PoCAn issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via…
- CVE-2019-175781 PoCAn issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via…
- CVE-2019-175921 PoCThe csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a…
- CVE-2019-175941 PoCThere is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before…
- CVE-2019-175951 PoCThere is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before…
- CVE-2019-175961 PoCGo before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There…
- CVE-2019-175991 PoCThe quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact…
- CVE-2019-176001 PoCIntelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
- CVE-2019-176011 PoCIn MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code…
- CVE-2019-176032 PoCsEne.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows…
- CVE-2019-176041 PoCAn Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other…
- CVE-2019-176051 PoCA mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by…
- CVE-2019-176121 PoCAn issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the…
- CVE-2019-176131 PoCqibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature…
- CVE-2019-176215 PoCsKEVThe UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to…
- CVE-2019-176241 PoC"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000…
- CVE-2019-176252 PoCsThere is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The…
- CVE-2019-176332 PoCsFor Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start…
- CVE-2019-176361 PoCIn Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as…
- CVE-2019-176371 PoCIn all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be…
- CVE-2019-176381 PoCIn Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to…
- CVE-2019-176401 PoCIn Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5,…
- CVE-2019-176581 PoCAn unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to…
- CVE-2019-1766215 PoCsThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when…
- CVE-2019-176661 PoCrtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading…
- CVE-2019-176691 PoCWordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation…
- CVE-2019-176701 PoCWordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain…
- CVE-2019-176713 PoCsIn WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
- CVE-2019-176721 PoCWordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
- CVE-2019-176731 PoCWordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
- CVE-2019-176741 PoCWordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
- CVE-2019-176751 PoCWordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to…