• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-19520
2020-08-24
N/A
7.8 HIGH
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
CVE-2019-1952
2021-10-29
N/A
6.7 MEDIUM
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using directory traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to overwrite or read arbitrary files on an affected device.
CVE-2019-19519
2021-07-21
N/A
7.8 HIGH
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
CVE-2019-19518
2020-01-17
N/A
9.8 CRITICAL
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.
CVE-2019-19517
Action Rf 1200 Firmware, Intelbras
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2020-05-07
N/A
8.8 HIGH
Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
CVE-2019-19516
Intelbras, Wrn 150 Firmware
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2019-12-13
N/A
6.5 MEDIUM
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.
CVE-2019-19515
Ayision, Ays-wr01, Ays-wr01 Firmware
Ays-wr01_firmware, Ays-wr01
2020-05-07
N/A
6.1 MEDIUM
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
CVE-2019-19514
Ayision, Ays-wr01, Ays-wr01 Firmware
Ays-wr01_firmware, Ays-wr01
2020-05-07
N/A
5.4 MEDIUM
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
CVE-2019-19513
Bassmidi, Un4seen
Bassmidi
2020-10-27
N/A
9.8 CRITICAL
The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target machine. A failure in exploitation leads to a denial of service.
CVE-2019-1951
2020-10-16
N/A
5.8 MEDIUM
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristics and sending it to a target device. A successful exploit could allow the attacker to bypass the L3 and L4 traffic filters and inject an arbitrary packet in the network.
« Previous 1 … 5,790 5,791 5,792 5,793 5,794 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE