• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-15937
2020-08-24
N/A
9.8 CRITICAL
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.
CVE-2019-15936
2019-12-13
N/A
9.8 CRITICAL
Intesync Solismed 3.3sp allows Insecure File Upload.
CVE-2019-15935
2019-12-13
N/A
6.1 MEDIUM
Intesync Solismed 3.3sp has XSS.
CVE-2019-15934
2019-12-13
N/A
8.8 HIGH
Intesync Solismed 3.3sp has CSRF.
CVE-2019-15933
2019-12-13
N/A
9.8 CRITICAL
Intesync Solismed 3.3sp has SQL Injection.
CVE-2019-15932
2020-08-24
N/A
9.8 CRITICAL
Intesync Solismed 3.3sp has Incorrect Access Control.
CVE-2019-15931
2019-12-13
N/A
9.8 CRITICAL
Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
CVE-2019-15930
2019-12-13
N/A
4.3 MEDIUM
Intesync Solismed 3.3sp allows Clickjacking.
CVE-2019-1593
Cisco, Nexus 9500
Sd-wan_firmware, Vedge-100, Vedge-1000, Vedge-100b, Vedge-2000, Vedge-5000, Vedge_100m, Vedge_100wm, Hyperflex_hx220c_m5_firmware, Hyperflex_hx220c_m5
2020-10-08
N/A
7.8 HIGH
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev-ops user could escalate their privilege level to admin with a successful exploit of this vulnerability.
CVE-2019-15929
2019-10-30
N/A
9.8 CRITICAL
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
« Previous 1 … 6,066 6,067 6,068 6,069 6,070 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE