• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-11401
2019-04-24
N/A
7.2 HIGH
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
CVE-2019-11400
Tew-652bru Firmware, Trendnet
Securview_wireless_internet_camera, Securview_wireless_internet_camera_activex_control, Teg-30102ws, Teg-30102ws_firmware, Tew-632brp, Tew-632brp_firmware, Tew-651br, Tew-651br_firmware, Tew-652br, Tew-652br_firmware
2019-12-23
N/A
9.8 CRITICAL
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. A buffer overflow occurs through the get_set.ccp ccp_act parameter.
CVE-2019-1140
Edge, Microsoft, Windows 10, Windows Server 2016, Windows Server 2019
20007_office_system, 27mhz_wireless_keyboard, 365_apps, 3d_builder, 3d_viewer, Access, Accessibility_insights_for_android, Accessibility_insights_for_web, Access_multilingual_user_interface_pack, Active_directory
2020-08-24
N/A
7.5 HIGH
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
CVE-2019-11399
Tew-652bru Firmware, Trendnet
Securview_wireless_internet_camera, Securview_wireless_internet_camera_activex_control, Teg-30102ws, Teg-30102ws_firmware, Tew-632brp, Tew-632brp_firmware, Tew-651br, Tew-651br_firmware, Tew-652br, Tew-652br_firmware
2019-12-23
N/A
9.8 CRITICAL
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter.
CVE-2019-11398
2019-06-10
N/A
6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.
CVE-2019-11397
2019-05-16
N/A
6.5 MEDIUM
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
CVE-2019-11396
Avira, Free Security Suite, Microsoft, Software Updater, Windows
Free_security_suite, Software_updater, Free_antivirus, Anti-malware_sdk, Antivir, Antivir_mailgate, Antivir_mailgate_suite, Antivir_personal, Antivir_professional, Antivir_security_suite, 20007_office_system, 27mhz_wireless_keyboard, 365_apps, 3d_builder, 3d_viewer, Access, Accessibility_insights_for_android, Accessibility_insights_for_web, Access_multilingual_user_interface_pack, Active_directory
2020-08-24
N/A
7.8 HIGH
An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM privileges. Arbitrary file creation can be achieved by abusing the SwuConfig.json file creation: an unprivileged user can replace these files by pseudo-symbolic links to arbitrary files. When an update occurs, a privileged service creates a file and sets its access rights, offering write access to the Everyone group in any directory.
CVE-2019-11395
2021-07-21
N/A
9.8 CRITICAL
A buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrated by SMTP RCPT TO, POP3 USER, POP3 LIST, POP3 TOP, or POP3 RETR.
CVE-2019-11393
2019-04-30
N/A
9.8 CRITICAL
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
CVE-2019-11392
2019-06-23
N/A
7.5 HIGH
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
« Previous 1 … 6,474 6,475 6,476 6,477 6,478 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE