• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-20005
2020-01-09
N/A
6.5 MEDIUM
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '' character (where the processing of a string was finished).
CVE-2019-20004
Intelbras, Iwr 3000n Firmware
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2020-01-14
N/A
8.8 HIGH
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.
CVE-2019-20003
2020-01-27
N/A
6.1 MEDIUM
Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication.
CVE-2019-20002
2021-07-21
N/A
7.8 HIGH
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
CVE-2019-20001
2021-07-21
N/A
7.8 HIGH
An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.
CVE-2019-20000
2020-01-08
N/A
5.9 MEDIUM
The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.
CVE-2019-2000
2021-07-21
N/A
7.8 HIGH
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025789.
CVE-2019-19999
2020-01-08
N/A
7.2 HIGH
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
CVE-2019-19998
2020-01-07
N/A
7.5 HIGH
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
CVE-2019-19996
Intelbras, Iwr 3000n Firmware
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2021-07-21
N/A
7.5 HIGH
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the ""} string to v1/system/login.
« Previous 1 … 5,748 5,749 5,750 5,751 5,752 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE