• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-14475
Ccu3, Eq-3
Ccu3_firmware, Ccu3, Ccu2_firmware, Ccu2, Homematic_ccu2_firmware, Homematic_ccu2, Homematic_ccu3_firmware, Homematic_ccu3
2020-08-24
N/A
7.5 HIGH
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a new user in the system, or modify/delete internal programs.
CVE-2019-14474
Ccu3, Eq-3
Ccu3_firmware, Ccu3, Ccu2_firmware, Ccu2, Homematic_ccu2_firmware, Homematic_ccu2, Homematic_ccu3_firmware, Homematic_ccu3
2019-08-16
N/A
7.5 HIGH
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid guest/user/admin account can start this attack too.
CVE-2019-14473
Ccu3, Eq-3
Ccu3_firmware, Ccu3, Ccu2_firmware, Ccu2, Homematic_ccu2_firmware, Homematic_ccu2, Homematic_ccu3_firmware, Homematic_ccu3
2020-08-24
N/A
8.8 HIGH
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the service messages, clear the system protocol or modify/delete internal programs, etc. pp.
CVE-2019-14472
2019-08-05
N/A
6.1 MEDIUM
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
CVE-2019-14471
2019-08-02
N/A
6.1 MEDIUM
TestLink 1.9.19 has XSS via the error.php message parameter.
CVE-2019-14470
2019-09-05
N/A
6.1 MEDIUM
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
CVE-2019-1447
2020-08-24
N/A
5.4 MEDIUM
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445.
CVE-2019-14469
2019-08-26
N/A
5.4 MEDIUM
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
CVE-2019-14468
2019-08-07
N/A
7.8 HIGH
GnuCOBOL 2.2 has a buffer overflow in cb_push_op in cobc/field.c via crafted COBOL source code.
CVE-2019-14467
2020-08-24
N/A
7.8 HIGH
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.
« Previous 1 … 6,202 6,203 6,204 6,205 6,206 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE