CVE-2019-8000 to CVE-2019-8999
130 CVEs with public proof-of-concept exploits.
- CVE-2019-80141 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80161 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80171 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80241 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80381 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80391 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80411 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80421 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80431 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80441 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80451 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80461 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80481 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80491 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80501 PoCAdobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and…
- CVE-2019-80861 PoCAdobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could…
- CVE-2019-81951 PoCAdobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and…
- CVE-2019-81961 PoCAdobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and…
- CVE-2019-81971 PoCAdobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and…
- CVE-2019-83201 PoCA Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files…
- CVE-2019-83314 PoCsIn Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
- CVE-2019-83341 PoCAn issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&viewid=[XSS].
- CVE-2019-83351 PoCAn issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&id=[XSS].
- CVE-2019-83411 PoCAn issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the…
- CVE-2019-83451 PoCThe Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle…
- CVE-2019-83471 PoCBEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the…
- CVE-2019-83492 PoCsMultiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2019-83521 PoCBy default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network…
- CVE-2019-83601 PoCThemerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
- CVE-2019-83621 PoCDedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a…
- CVE-2019-83681 PoCOpenEMR v5.0.1-6 allows XSS.
- CVE-2019-83711 PoCOpenEMR v5.0.1-6 allows code execution.
- CVE-2019-83721 PoCThe LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write…
- CVE-2019-83752 PoCsThe UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent…
- CVE-2019-83762 PoCsAn issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can…
- CVE-2019-83772 PoCsAn issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This…
- CVE-2019-83782 PoCsAn issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in…
- CVE-2019-83792 PoCsAn issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in…
- CVE-2019-83802 PoCsAn issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampMs() located in…
- CVE-2019-83812 PoCsAn issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a…
- CVE-2019-83822 PoCsAn issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in Core/Ap4List.h…
- CVE-2019-83832 PoCsAn issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It…
- CVE-2019-83852 PoCsAn issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion…
- CVE-2019-83872 PoCsMASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
- CVE-2019-83892 PoCsA file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer…
- CVE-2019-83903 PoCsqdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
- CVE-2019-83912 PoCsqdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
- CVE-2019-83921 PoCAn issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to…
- CVE-2019-83942 PoCsKEVZoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page…
- CVE-2019-84001 PoCORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
- CVE-2019-84042 PoCsAn issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image…
- CVE-2019-84101 PoCMaccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords…
- CVE-2019-84211 PoCupload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
- CVE-2019-84221 PoCA SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in…
- CVE-2019-84231 PoCZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
- CVE-2019-84241 PoCZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
- CVE-2019-84251 PoCincludes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
- CVE-2019-84261 PoCskins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the…
- CVE-2019-84271 PoCdaemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
- CVE-2019-84281 PoCZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a…
- CVE-2019-84291 PoCZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
- CVE-2019-84371 PoCnjiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.
- CVE-2019-84423 PoCsThe CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version…
- CVE-2019-84462 PoCsThe /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect…
- CVE-2019-84498 PoCsThe /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an…
- CVE-2019-84518 PoCsThe /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal…
- CVE-2019-84522 PoCsA hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows…
- CVE-2019-84611 PoCCheck Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean…
- CVE-2019-85061 PoCKEVA type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1,…
- CVE-2019-85132 PoCsThis issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary…
- CVE-2019-85141 PoCA logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2.…
- CVE-2019-85181 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2,…
- CVE-2019-85261 PoCKEVA use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be…
- CVE-2019-85401 PoCA memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS…
- CVE-2019-85581 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2,…
- CVE-2019-85611 PoCA logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to…
- CVE-2019-85652 PoCsA race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application…
- CVE-2019-85911 PoCA type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3,…
- CVE-2019-86011 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5,…
- CVE-2019-86054 PoCsKEVA use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3,…
- CVE-2019-86111 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5,…
- CVE-2019-86131 PoCA use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote…
- CVE-2019-86221 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5,…
- CVE-2019-86231 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5,…
- CVE-2019-86241 PoCAn out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to…
- CVE-2019-86413 PoCsAn out-of-bounds read was addressed with improved input validation.
- CVE-2019-86461 PoCAn out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4,…
- CVE-2019-86471 PoCA use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote…
- CVE-2019-86491 PoCA logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is…
- CVE-2019-86561 PoCThis was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave…
- CVE-2019-86601 PoCA memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4,…
- CVE-2019-86611 PoCA use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may…
- CVE-2019-86622 PoCsThis issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker…
- CVE-2019-86631 PoCThis issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to…
- CVE-2019-86711 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6,…
- CVE-2019-86721 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6,…
- CVE-2019-86891 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6,…
- CVE-2019-86901 PoCA logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in…
- CVE-2019-87171 PoCA memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS 13. An…
- CVE-2019-87181 PoCA memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application…
- CVE-2019-87651 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously…
- CVE-2019-87812 PoCsA memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be…
- CVE-2019-87911 PoCAn issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam…
- CVE-2019-87921 PoCAn injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App…
- CVE-2019-88051 PoCA validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement.…
- CVE-2019-88201 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS…
- CVE-2019-88521 PoCA memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update…
- CVE-2019-89033 PoCsindex.js in Total.js Platform before 3.2.3 allows path traversal.
- CVE-2019-89211 PoCAn issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP…
- CVE-2019-89221 PoCA heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in…
- CVE-2019-89232 PoCsXAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
- CVE-2019-89243 PoCsXAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
- CVE-2019-89253 PoCsAn issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the…
- CVE-2019-89263 PoCsAn issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone…
- CVE-2019-89273 PoCsAn issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone…
- CVE-2019-89283 PoCsAn issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp…
- CVE-2019-89293 PoCsAn issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone…
- CVE-2019-89331 PoCIn DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and…
- CVE-2019-89362 PoCsNTP through 4.2.8p12 has a NULL Pointer Dereference.
- CVE-2019-89373 PoCsHotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php,…
- CVE-2019-89382 PoCsVertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.
- CVE-2019-894213 PoCsWordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an…
- CVE-2019-894312 PoCsWordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output…
- CVE-2019-89531 PoCThe HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to…
- CVE-2019-89563 PoCsIn the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when…
- CVE-2019-89782 PoCsAn improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4,…
- CVE-2019-89811 PoCtls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because the need_bytes…
- CVE-2019-89822 PoCscom/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value,…
- CVE-2019-89851 PoCOn Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer…
- CVE-2019-89971 PoCAn XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6…