CVE-2019-9000 to CVE-2019-9999
228 CVEs with public proof-of-concept exploits.
- CVE-2019-90021 PoCAn issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute…
- CVE-2019-90173 PoCsDWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
- CVE-2019-90191 PoCThe British Airways Entertainment System, as installed on Boeing 777-36N(ER) and possibly other aircraft, does not prevent the USB…
- CVE-2019-90211 PoCAn issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer…
- CVE-2019-90261 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow in the function…
- CVE-2019-90271 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow problem in the…
- CVE-2019-90281 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function…
- CVE-2019-90291 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is an out-of-bounds read with a SEGV in the…
- CVE-2019-90301 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in…
- CVE-2019-90311 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a NULL pointer dereference in the function…
- CVE-2019-90321 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is an out-of-bounds write problem causing a SEGV…
- CVE-2019-90331 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for the "Rank…
- CVE-2019-90341 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for a memcpy in…
- CVE-2019-90351 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function…
- CVE-2019-90361 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow in the function…
- CVE-2019-90371 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a buffer over-read in the function…
- CVE-2019-90381 PoCAn issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is an out-of-bounds read problem with a SEGV in…
- CVE-2019-90412 PoCsAn issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict,…
- CVE-2019-90481 PoCAn issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a…
- CVE-2019-90491 PoCAn issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a…
- CVE-2019-90501 PoCAn issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a…
- CVE-2019-90511 PoCAn issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a…
- CVE-2019-90521 PoCAn issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a…
- CVE-2019-905353 PoCsAn issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated…
- CVE-2019-90551 PoCAn issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and…
- CVE-2019-90621 PoCPHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
- CVE-2019-90826 PoCsKEVThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via…
- CVE-2019-90832 PoCsSQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
- CVE-2019-90841 PoCIn Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to…
- CVE-2019-90851 PoCHoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter…
- CVE-2019-90861 PoCHotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
- CVE-2019-90871 PoCHotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
- CVE-2019-91051 PoCThe WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several…
- CVE-2019-91061 PoCThe WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or…
- CVE-2019-91072 PoCsXSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php.
- CVE-2019-91082 PoCsXSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.
- CVE-2019-91092 PoCsXSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php.
- CVE-2019-91102 PoCsXSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
- CVE-2019-91131 PoCMing (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.
- CVE-2019-91141 PoCMing (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.
- CVE-2019-91161 PoCDLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse…
- CVE-2019-91241 PoCAn issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
- CVE-2019-91432 PoCsAn issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be…
- CVE-2019-91442 PoCsAn issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be…
- CVE-2019-91511 PoCAn issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in H5VM.c when called…
- CVE-2019-91532 PoCsImproper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its…
- CVE-2019-91541 PoCImproper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
- CVE-2019-91551 PoCA cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether…
- CVE-2019-91561 PoCGemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
- CVE-2019-91581 PoCGemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
- CVE-2019-91621 PoCIn the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length…
- CVE-2019-91641 PoCCommand injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
- CVE-2019-91651 PoCSQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys…
- CVE-2019-91671 PoCCross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the…
- CVE-2019-91721 PoCAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It…
- CVE-2019-91821 PoCThere is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a…
- CVE-2019-91842 PoCsSQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands…
- CVE-2019-91891 PoCPrima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the…
- CVE-2019-919312 PoCsIn PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group…
- CVE-2019-91947 PoCselFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
- CVE-2019-91992 PoCsPoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be…
- CVE-2019-92002 PoCsA heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered…
- CVE-2019-92022 PoCsNagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
- CVE-2019-92031 PoCAuthorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
- CVE-2019-92041 PoCSQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.
- CVE-2019-92061 PoCPRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued.
- CVE-2019-92091 PoCIn Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in…
- CVE-2019-92101 PoCIn AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an…
- CVE-2019-92111 PoCThere is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP…
- CVE-2019-92136 PoCsIn the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for…
- CVE-2019-92201 PoCAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It…
- CVE-2019-92261 PoCAn issue was discovered in baigo CMS 2.1.1. There is a persistent XSS vulnerability that allows remote attackers to inject arbitrary web…
- CVE-2019-92271 PoCAn issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A…
- CVE-2019-93672 PoCsIn Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with…
- CVE-2019-94652 PoCsIn the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could…
- CVE-2019-94861 PoCSTRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the…
- CVE-2019-94916 PoCsTrend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious…
- CVE-2019-95001 PoCBroadcom brcmfmac driver is vulnerable to a heap buffer overflow
- CVE-2019-95011 PoCBroadcom wl driver is vulnerable to heap buffer overflow
- CVE-2019-95062 PoCsBlutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key length negotiation
- CVE-2019-95111 PoCSome HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a…
- CVE-2019-95351 PoCiTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution
- CVE-2019-95431 PoCAn issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can…
- CVE-2019-95442 PoCsAn issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() located in…
- CVE-2019-95452 PoCsAn issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be…
- CVE-2019-95532 PoCsBolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
- CVE-2019-95542 PoCsIn the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an…
- CVE-2019-95562 PoCsFiberHome an5506-04-f RP2669 devices have XSS.
- CVE-2019-95571 PoCAbility Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim…
- CVE-2019-95581 PoCMailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the…
- CVE-2019-95672 PoCsThe "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
- CVE-2019-95682 PoCsThe "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the…
- CVE-2019-95701 PoCAn issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the…
- CVE-2019-95752 PoCsThe Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
- CVE-2019-95762 PoCsThe Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
- CVE-2019-95801 PoCIn st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null"…
- CVE-2019-95814 PoCsphpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary…
- CVE-2019-95821 PoCeQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2.41.8, 2.41.9,…
- CVE-2019-95831 PoCeQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks.…
- CVE-2019-95841 PoCeQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile…
- CVE-2019-95851 PoCeQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related…
- CVE-2019-95871 PoCThere is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to…
- CVE-2019-95881 PoCThere is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf…
- CVE-2019-95891 PoCThere is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be…
- CVE-2019-95912 PoCsA reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject…
- CVE-2019-95922 PoCsA reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary…
- CVE-2019-95932 PoCsA reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary…
- CVE-2019-95963 PoCsDarktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
- CVE-2019-95973 PoCsDarktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
- CVE-2019-95981 PoCAn issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
- CVE-2019-95993 PoCsThe AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many…
- CVE-2019-96002 PoCsThe Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial…
- CVE-2019-96011 PoCThe ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous…
- CVE-2019-96031 PoCMiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
- CVE-2019-96041 PoCPHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
- CVE-2019-96171 PoCAn issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does…
- CVE-2019-96183 PoCsThe GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
- CVE-2019-96219 PoCsKEVZimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch…
- CVE-2019-96222 PoCseBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by…
- CVE-2019-96232 PoCsFeng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
- CVE-2019-96245 PoCsWebmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges…
- CVE-2019-96251 PoCJBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
- CVE-2019-96261 PoCPHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
- CVE-2019-96321 PoCESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the…
- CVE-2019-96411 PoCAn issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized…
- CVE-2019-96462 PoCsThe Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in…
- CVE-2019-96472 PoCsGila CMS 1.9.1 has XSS.
- CVE-2019-96483 PoCsAn issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE…
- CVE-2019-96493 PoCsAn issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a…
- CVE-2019-96502 PoCsAn XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
- CVE-2019-96531 PoCNUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell…
- CVE-2019-96561 PoCAn issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file…
- CVE-2019-96571 PoCAlarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect…
- CVE-2019-96601 PoCStored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
- CVE-2019-96611 PoCStored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
- CVE-2019-96681 PoCAn issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to…
- CVE-2019-967012 PoCsKEVmailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability,…
- CVE-2019-96731 PoCFreenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
- CVE-2019-96881 PoCsftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.
- CVE-2019-96925 PoCsclass.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file…
- CVE-2019-97011 PoCDLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable…
- CVE-2019-97021 PoCSymantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue…
- CVE-2019-97261 PoCDirectory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of…
- CVE-2019-97291 PoCIn Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating…
- CVE-2019-97302 PoCsIncorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to…
- CVE-2019-97332 PoCsAn issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin…
- CVE-2019-97381 PoCjimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
- CVE-2019-97401 PoCAn issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the…
- CVE-2019-97421 PoCgdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks…
- CVE-2019-97451 PoCCloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates…
- CVE-2019-97572 PoCsAn issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view…
- CVE-2019-97582 PoCsAn issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators…
- CVE-2019-97603 PoCsFTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine…
- CVE-2019-97611 PoCAn XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without…
- CVE-2019-97622 PoCsA SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not…
- CVE-2019-97663 PoCsStack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary…
- CVE-2019-97672 PoCsStack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary…
- CVE-2019-97682 PoCsThinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it…
- CVE-2019-97691 PoCPilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
- CVE-2019-97851 PoCgitnote 3.1.0 allows remote attackers to execute arbitrary code via a crafted Markdown file, as demonstrated by a…
- CVE-2019-97875 PoCsWordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default…
- CVE-2019-97913 PoCsThe type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled…
- CVE-2019-97923 PoCsThe IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This…
- CVE-2019-98071 PoCWhen arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with…
- CVE-2019-98091 PoCIf the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these…
- CVE-2019-98108 PoCsIncorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer…
- CVE-2019-98111 PoCAs part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a…
- CVE-2019-98131 PoCIncorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read…
- CVE-2019-98161 PoCA possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the…
- CVE-2019-98312 PoCsThe AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via many simultaneous…
- CVE-2019-98321 PoCThe AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket…
- CVE-2019-98331 PoCThe Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many simultaneous…
- CVE-2019-98342 PoCsThe Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka…
- CVE-2019-98351 PoCThe receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. This occurs because…
- CVE-2019-98382 PoCsVFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering.
- CVE-2019-98392 PoCsVFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.
- CVE-2019-98411 PoCVesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
- CVE-2019-98421 PoCmadskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL,…
- CVE-2019-98441 PoCsimple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
- CVE-2019-98451 PoCmadskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data:…
- CVE-2019-98481 PoCLibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as…
- CVE-2019-98491 PoCLibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This…
- CVE-2019-98512 PoCsLibreLogo global-event script execution
- CVE-2019-98583 PoCsRemote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that…
- CVE-2019-98614 PoCsDue to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000…
- CVE-2019-98621 PoCAn issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or…
- CVE-2019-98631 PoCDue to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote…
- CVE-2019-98741 PoCKEVDeserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5…
- CVE-2019-98771 PoCThere is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can…
- CVE-2019-98781 PoCThere is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in…
- CVE-2019-98794 PoCsThe WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user…
- CVE-2019-98804 PoCsAn issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an…
- CVE-2019-98814 PoCsThe createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even…
- CVE-2019-98841 PoCeClass platform contains a Broken Access Control vulnerability
- CVE-2019-98851 PoCeClass platform contains a SQL injection vulnerability
- CVE-2019-98911 PoCThe function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution…
- CVE-2019-98971 PoCMultiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
- CVE-2019-99001 PoCWhen parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote…
- CVE-2019-99032 PoCsPDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find()…
- CVE-2019-99042 PoCsAn issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in…
- CVE-2019-99081 PoCThe font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
- CVE-2019-99092 PoCsThe "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
- CVE-2019-99102 PoCsThe kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
- CVE-2019-99112 PoCsThe social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has…
- CVE-2019-99123 PoCsThe wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
- CVE-2019-99132 PoCsThe wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
- CVE-2019-99142 PoCsThe yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
- CVE-2019-99151 PoCGetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
- CVE-2019-99221 PoCAn issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.
- CVE-2019-99262 PoCsAn issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a…
- CVE-2019-99381 PoCThe SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots…
- CVE-2019-99391 PoCThe SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots…
- CVE-2019-99471 PoCAn issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the…
- CVE-2019-99481 PoCurllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection…
- CVE-2019-99492 PoCsWestern Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are…
- CVE-2019-99553 PoCsOn Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900,…
- CVE-2019-99561 PoCIn ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker…
- CVE-2019-99631 PoCXnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
- CVE-2019-99641 PoCXnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
- CVE-2019-99661 PoCXnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
- CVE-2019-99671 PoCXnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
- CVE-2019-99681 PoCXnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
- CVE-2019-99691 PoCXnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
- CVE-2019-99711 PoCPhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo…
- CVE-2019-99721 PoCPhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary…
- CVE-2019-99741 PoCdiag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a…
- CVE-2019-99751 PoCDASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by…
- CVE-2019-997822 PoCsKEVThe social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url…