• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-17586
2020-02-06
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019.
CVE-2019-17585
2020-02-06
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019.
CVE-2019-17584
Meinbergglobal, Syncbox/ptpv2, Syncbox/ptpv2 Firmware
Syncbox/ptpv2_firmware, Syncbox/ptpv2
2020-01-29
N/A
7.5 HIGH
The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The private key is also used in an internal interface of another Meinberg Device and can be extracted from a firmware update of this device. An update to fix the vulnerability was published by the vendor.
CVE-2019-17583
Icms, Idreamsoft
Icms
2020-08-24
N/A
7.5 HIGH
idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.
CVE-2019-17582
2021-02-16
N/A
9.8 CRITICAL
A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer states "This use-after-free is triggered prior to the double free reported in CVE-2017-12858."
CVE-2019-17581
2019-10-28
N/A
6.1 MEDIUM
tonyy dormsystem through 1.3 allows DOM XSS.
CVE-2019-17580
2019-10-16
N/A
9.8 CRITICAL
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
CVE-2019-1758
2019-10-09
N/A
4.3 MEDIUM
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to how the 802.1x packets are handled in the process path. An attacker could exploit this vulnerability by attempting to connect to the network on an 802.1x configured port. A successful exploit could allow the attacker to intermittently obtain access to the network.
CVE-2019-17579
2019-10-17
N/A
6.1 MEDIUM
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
CVE-2019-17578
2022-11-17
N/A
5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
« Previous 1 … 5,925 5,926 5,927 5,928 5,929 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE