• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-6289
2021-07-21
N/A
8.8 HIGH
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.
CVE-2019-6288
Ecs2020 Firmware, Edge-core
Ecs2020_firmware, Ecs2020
2021-10-05
N/A
9.8 CRITICAL
Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.
CVE-2019-6287
2022-04-13
N/A
8.1 HIGH
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
CVE-2019-6286
2019-07-23
N/A
6.5 MEDIUM
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.
CVE-2019-6285
2020-08-24
N/A
6.5 MEDIUM
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
CVE-2019-6284
2020-08-24
N/A
6.5 MEDIUM
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
CVE-2019-6283
2020-08-24
N/A
6.5 MEDIUM
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.
CVE-2019-6282
Chinamobileltd, Gpn2.4p21-c-cn, Gpn2.4p21-c-cn Firmware
Gpn2.4p21-c-cn_firmware, Gpn2.4p21-c-cn
2019-10-24
N/A
8.8 HIGH
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
CVE-2019-6279
Chinamobileltd, Gpn2.4p21-c-cn, Gpn2.4p21-c-cn Firmware
Gpn2.4p21-c-cn_firmware, Gpn2.4p21-c-cn
2020-08-24
N/A
8.8 HIGH
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
CVE-2019-6278
2019-01-18
N/A
5.4 MEDIUM
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
« Previous 1 … 5,332 5,333 5,334 5,335 5,336 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE